Amgen has been hit with a data breach impacting its third-party operated cloud-based systems – an event which the company says has compromised both company-owned data and private patient health information.
According to an 8-K form Amgen filed with the US Securities and Exchange Commission (SEC), the company uncovered a material incident in which the privacy of some of its cloud-based data, including proprietary and protected patient health information, was compromised – leading the company to activate its cybersecurity response plan and take steps to contain this data leak.
Discover B2B Marketing That Performs
Combine business intelligence and editorial excellence to reach engaged professionals across 36 leading media platforms.
Currently, Amgen does not believe that this breach has had any impact on either its products, manufacturing or financial reporting systems, though the company continues to investigate what the hackers have accessed. In the 8-K form detailing the cyberattack, Amgen noted it was “not reasonably likely” that the event would have a material impact on the company’s financial condition or results.
This cyberattack on Amgen comes as the future of its rare inflammatory blood vessel disease drug, Tavneos (avacopan) – which made the company $459m in 2025 – lies in the balance. US and European regulators are currently mulling over whether to revoke the drug’s approval, as questions around the integrity of clinical data used to back the drug’s initial approval remain.
This, in part, led the New England Journal of Medicine (NEJM) to retract Tavneos’ pivotal paper back in July 2026.
Amgen also recently greenlit a $74m settlement with investors, who claimed that the company failed to disclose a tax bill of $10.7bn that kept its share price “artificially high” between July 2020 and April 2022.
Life science cyberattacks gain in prevalence
This event sees Amgen join the growing list of life sciences companies that have faced data breaches in recent months. The Iran-linked hacktivist group, Handala, initiated one of the most high-profile cases in recent months by launching a cyberattack on Stryker in the early hours of 11 March 2026. This breach compromised the medtech company’s access to some of its information systems and business applications.
Fellow medtech giant Abbott Laboratories and obesity titan Novo Nordisk have also contended with cyberattacks this year.
Currently, Abbott is investigating a breach of a small number of the internal systems within its cancer diagnostics business, while the latter recently declared that hackers had copied information from its internal IT systems – including patient data from clinical trials – in an extortion bid. Later, FulcrumSec claimed responsibility for this breach.
