Amgen Inc. experienced a cyber incident that involved the theft of patient information and proprietary data stored in cloud servers, the company disclosed in a regulatory filing on July 31, making it the latest large healthcare company to suffer a data breach.
The drugmaker is still assessing the damage but said it is not likely to have a material impact on financial results. A representative for Amgen declined to comment beyond the filing.
Amgen detected unauthorized access to data on third-party cloud servers in July. It subsequently learned that some of the data, including patient protected health information, had been exfiltrated from the cloud environment.
“To date, the company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the company’s ability to meet patient needs,” the company said in the filing.
The incident is considered material because of the volume of files affected and the risk that sensitive information was compromised. The investigation is ongoing.
Additional Challenges Facing Amgen
The breach is the latest setback for the Thousand Oaks, California, drugmaker. The company is separately facing safety questions over its drug Tavneos, which is intended to treat a rare autoimmune condition. A major journal has retracted the study used to support Tavneos’ approval, and regulators in the US and Europe want it removed from the market.
Amgen has also been grappling with declining sales of its older medicines as they lose patent protection. Investors are focused on new pipeline products, particularly the weight-loss shot MariTide, with early evidence suggesting it is not as competitive as existing treatments from Eli Lilly & Co. and Novo Nordisk A/S.
A Pattern of Healthcare Cyber Incidents
The Amgen breach is part of a broader trend of cybersecurity incidents affecting the healthcare and medical technology sectors. Earlier this year, a cyberattack disrupted operations at medical-technology company Stryker Corp. Shortly afterward, Intuitive Surgical Inc., which makes surgical tools and systems, disclosed that it had also been the victim of a cybersecurity incident. Last month, Novo Nordisk identified unauthorized access to some IT systems the drugmaker uses for its global business.
Photo by Sean Gallup/Getty Images
Copyright 2026 Bloomberg.