Amgen discloses material cybersecurity incident after data exfiltration from third‑party cloud environments

AMGN

·

Amgen disclosed a material cybersecurity incident in a filing with the U.S. Securities and Exchange Commission on Friday, saying unauthorized activity in third-party cloud environments led to the exfiltration of proprietary data and patient protected health information.

The biotechnology company said in the Form 8-K that, as of the filing date, it had “not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs.” Amgen also said it believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations.

The filing, submitted under Item 1.05 of the SEC’s rules for material cybersecurity incidents, was accepted July 31. Amgen listed July 29 as the earliest event reported and said that was the date it determined the incident was material. The company said it identified “unauthorized activity” in July 2026 involving data stored in cloud environments hosted by third-party cloud service providers.

After detecting the activity, Amgen said it activated its cybersecurity response plan, put containment measures in place and brought in independent cybersecurity forensic experts. The company said it later learned that “some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments.”

Amgen said its investigation is continuing and that it is still assessing “whether, and to what extent, patient information, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated.”

The filing leaves several key questions unanswered. Amgen did not identify the third-party cloud providers involved, did not say how many people may have been affected and did not specify which proprietary, intellectual property or research and development data may have been taken.

The company said it is evaluating regulatory and legal notification requirements and will make required notifications, including to impacted patients. It also said it would amend the 8-K if additional information required under Item 1.05 becomes available.

Item 1.05 is part of the SEC’s cybersecurity disclosure rules adopted in 2023. The rules require public companies to file an 8-K within four business days after determining that a cyber incident is material to investors.

Amgen had previously warned investors in periodic filings about cyber risks tied to third-party service providers. The company also disclosed a separate third-party incident in November 2025 that it later said was not material.

Tags: #amgen, #cybersecurity, #biotech, #sec

Stocks: AMGN