Amgen reports cloud breach exposing patient and proprietary data
Pharmaceutical giant confirms threat actors accessed corporate information and patient health records stored across multiple third-party cloud environments.
Amgen has disclosed a data breach affecting patient health information and proprietary corporate data held in cloud systems managed by external service providers. The California-based pharmaceutical company, which develops treatments for serious illnesses including cancer and cardiovascular disease, confirmed that threat actors gained unauthorized access to multiple cloud environments.
The breach exposed both patient data and sensitive corporate information. Amgen has not disclosed the number of affected individuals, the identity of the third-party providers involved, or the specific cloud platforms compromised. The company also has not indicated whether ransomware groups have claimed responsibility or if stolen data has appeared on extortion sites.
The incident underscores the persistent risk of supply chain vulnerabilities in healthcare IT infrastructure. Third-party cloud providers have become a common attack surface, allowing adversaries to breach multiple organizations through a single compromise. Amgen joins a growing list of pharmaceutical and healthcare entities that have suffered breaches through vendor relationships.
- 01Patients: health records may be exposed to identity theft or targeted phishing
- 02Amgen: faces regulatory scrutiny, potential HIPAA penalties, and intellectual property loss
- 03Third-party cloud vendors: likely to face contractual and reputational consequences
- 04Pharmaceutical sector: renewed focus on vendor risk management and cloud security controls
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.