HomeMalware & ThreatsAmgen Informs SEC About Hack Exposing Patient Data and Trade Secrets

Amgen Informs SEC About Hack Exposing Patient Data and Trade Secrets

Published on

spot_img

Drug Maker Amgen Reports Cyber Hack Potentially Compromising Sensitive Data

On August 3, 2026, pharmaceutical giant Amgen informed the U.S. Securities and Exchange Commission (SEC) of a significant data breach that may have resulted in the theft of critical company information. This breach is particularly concerning as it encompasses a wide range of sensitive data, including protected health information (PHI), intellectual property, research and development files, as well as other confidential business documents.

The California-based company, which boasted nearly $37 billion in revenue for fiscal year 2025, finds itself in a troubling trend that has seen various biotechnology, medical technology, and pharmaceutical firms fall victim to cybercriminal exploits targeting sensitive information. In the wake of this breach, Amgen took decisive actions to mitigate the incident, quickly activating a pre-established cybersecurity response plan. The company has since collaborated with external cybersecurity forensic experts to establish the breadth and implications of the unauthorized data access.

In its filing with the SEC, Amgen revealed that they uncovered unauthorized activities linked to their data stored in cloud environments provided by third-party vendors. Although the company did not disclose the specific date of this discovery or the identities of the cloud service providers involved, it emphasized the severity and potential ramifications of the incident. The ongoing evaluation of the compromised data suggested that the quantity and nature of the information breached could be sensitive, causing Amgen to classify the breach as "material."

As of the latest updates, no cybercrime group has emerged to take credit for the data theft on dark web forums. However, early indications suggest that the characteristics of the breach align with recent attacks perpetrated against several other entities in the healthcare sector, notably including Abbott Laboratories’ Exact Sciences and Medtronic. These incidents bear the signature of ShinyHunters, a notorious cybercriminal organization known for executing a range of data breaches that target healthcare and biotech firms.

This particular group has gained notoriety for conducting extensive data exfiltration attacks that have affected several organizations within the healthcare and related sectors. Errol Weiss, the Chief Security Officer of the Health Information Sharing and Analysis Center, has identified ShinyHunters as a leading threat group behind this surge in security incidents.

It’s worth mentioning that ShinyHunters is not the sole threat to biotech and healthcare firms. In June, two separate hacking groups, FulcrumSec and TheUSERS007, claimed responsibility for pilfering sensitive "crown jewel data" from Danish pharmaceutical powerhouse Novo Nordisk, further exemplifying the rampant thefts targeting the industry.

Experts believe that the staggering array of data in possession of these organizations—from patient records to proprietary research and financial documents—makes them particularly attractive targets for cybercriminals. Eric Bordeau, a virtual Chief Information Officer at the managed services and cybersecurity firm Logically, elucidated the various avenues through which criminals can capitalize on stolen data. Whether through the sale of personal information, identity fraud, or blackmail threats to release sensitive data unless a ransom is paid, the motivations behind such breaches are manifold. In some cases, the value does not lie solely in the data itself but also in the pressures it exerts on organizations.

Amgen’s breach, specifically, involves data exfiltration from third-party cloud environments. Addressing this, Bordeau stated, "I don’t look at this as a cloud problem. The cloud is not inherently less secure; it’s where businesses operate today, making it a focal point for attackers." He emphasized that the crux of these breaches often lies with human factors, such as phishing scams or weak passwords, rather than the technology itself.

Despite the serious nature of the incident, Amgen reassured stakeholders that the breach is "not reasonably likely to have a material impact on the company’s financial condition or results of operations." However, the company has not yet responded to requests for additional information regarding the cyber incident.

As the evaluation of the breach continues, Amgen’s actions and the implications of this data compromise serve as a cautionary tale for organizations across all sectors. The ongoing struggle against cyber threats necessitates robust security measures, including employee training and stringent access controls, to safeguard valuable information assets in today’s increasingly complex digital landscape.

Source link

Latest articles

AI Now Accounts for Over Half of Cybercrime in Africa, Reports Interpol

AI-Driven Cybercrime Surges in Africa, Interpol Reports Interpol has issued a stark warning regarding the...

Live Webinar – Security Without Slowing Growth: Transforming Cybersecurity and Compliance into a Competitive Advantage

Navigating Cybersecurity: A Crucial Webinar for High-Growth Startups In an era where the digital landscape...

Qilin Ransomware Emerges as Most Active Threat in H1 2026

Qilin Ransomware Dominates Global Cyber Threat Landscape in Early 2026 In the first half of...

Attackers Designing Malicious AI Instruction Files to Transform Your Agentic Workflows into Covert Criminal Aids

Sophisticated Cyberattack Explored: A New Trend in Agent Instruction File Poisoning Recent investigations by cybersecurity...

More like this

AI Now Accounts for Over Half of Cybercrime in Africa, Reports Interpol

AI-Driven Cybercrime Surges in Africa, Interpol Reports Interpol has issued a stark warning regarding the...

Live Webinar – Security Without Slowing Growth: Transforming Cybersecurity and Compliance into a Competitive Advantage

Navigating Cybersecurity: A Crucial Webinar for High-Growth Startups In an era where the digital landscape...

Qilin Ransomware Emerges as Most Active Threat in H1 2026

Qilin Ransomware Dominates Global Cyber Threat Landscape in Early 2026 In the first half of...