STOCK TITAN

Cyber breach at Amgen (Nasdaq: AMGN) exposes proprietary and patient data

(Moderate)
(Neutral)
Form Type
8-K

Rhea-AI Filing Summary

Amgen Inc. reports a material cybersecurity incident involving unauthorized activity in data stored in cloud environments hosted by third-party providers. Some company data, including proprietary information, patient protected health information and other records, has been exfiltrated from those cloud systems.

Amgen activated its cybersecurity response plan, implemented containment measures and engaged independent forensic experts, and the investigation remains ongoing. The company has not identified any impact on its products, manufacturing operations, financial reporting systems or ability to meet patient needs, and currently believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations. Amgen is assessing regulatory and legal notification obligations and plans to notify affected patients where required.

Positive

  • None.

Negative

  • None.

Filing Explained

The July 31 filing records that Amgen determined the incident was material on July 29 and will amend the 8-K as currently unavailable details become known.

Item 1.05 Material Cybersecurity Incidents Business
A cybersecurity incident that the company has determined to be material to investors.
Incident identified July 2026 Timeframe when unauthorized activity in cloud environments was first identified
Materiality determination date July 29, 2026 Date Amgen determined the cybersecurity incident is material
Report signature date July 31, 2026 Date the report was signed by the Executive Vice President and General Counsel
Material Cybersecurity Incidents regulatory
"Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc."
protected health information medical
"including proprietary data, patient protected health information, and other information"
Protected health information is any personal medical or health-related data that can identify an individual—examples include diagnoses, treatment records, test results, insurance details, or an address when tied to health information. It matters to investors because organizations that collect, store or share this data face strict privacy laws, high breach and liability risk, and potential fines or reputational damage, making PHI a valuable but legally sensitive asset.
exfiltrated technical
"data, including proprietary data, patient protected health information, and other information, has been exfiltrated"
cloud environments technical
"unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers"
Cloud environments are networks of remote computers and services accessed over the internet that store data and run applications instead of relying on a company’s own servers or individual machines. They matter to investors because they influence a business’s costs, speed of growth, and risk profile—like renting flexible office space instead of owning a building, cloud use can lower upfront spending and enable rapid expansion but also creates dependence on third-party providers and potential security or outage risks.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates

FAQ

What cybersecurity incident did Amgen (AMGN) disclose?

Amgen disclosed a material cybersecurity incident involving unauthorized activity in data stored in third-party cloud environments. Some data, including proprietary information, patient protected health information and other records, was exfiltrated from those cloud systems.

Has the Amgen (AMGN) cyber incident affected products or operations?

Amgen states it has not identified any impact on its products, manufacturing operations, financial reporting systems, or ability to meet patient needs. The company continues investigating and assessing what information was accessed, acquired or exfiltrated.

Does Amgen (AMGN) expect a material financial impact from the cybersecurity incident?

Amgen believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations. This assessment is based on current information, while the company’s investigation and evaluation of potential impacts continue.

What data was involved in Amgen's (AMGN) cybersecurity incident?

Amgen reports that some of its data, including proprietary data, patient protected health information, and other information, was exfiltrated from cloud environments. The company is still assessing the types and volumes of information potentially affected.

How is Amgen (AMGN) responding to the cybersecurity incident?

Amgen activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts. It is evaluating regulatory and legal notification requirements and will make required notifications, including to impacted patients, based on its findings.

When did Amgen (AMGN) determine the cyber incident was material?

On July 29, 2026, Amgen determined the cybersecurity incident was material, based on the volume of files that appear impacted and the potential sensitivity of information those files may contain, including proprietary and patient-related data.
false000031815400003181542026-07-292026-07-29

 

UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549

 

FORM 8-K

 

CURRENT REPORT

Pursuant to Section 13 or 15(d) of the Securities Exchange Act of 1934

Date of Report (Date of earliest event reported): July 29, 2026

 

 

Amgen Inc.

(Exact name of Registrant as Specified in Its Charter)

 

 

Delaware

001-37702

95-3540776

(State or Other Jurisdiction
of Incorporation)

(Commission File Number)

(IRS Employer
Identification No.)

 

 

 

 

 

One Amgen Center Drive

 

Thousand Oaks, California

 

91320-1799

(Address of Principal Executive Offices)

 

(Zip Code)

 

Registrant’s Telephone Number, Including Area Code: (805) 447-1000

 

 

(Former Name or Former Address, if Changed Since Last Report)

 

Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions:

 

Written communications pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

 

 

Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

 

 

Pre-commencement communications pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

 

 

Pre-commencement communications pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))

Securities registered pursuant to Section 12(b) of the Act:


Title of each class

 

Trading
Symbol(s)

 


Name of each exchange on which registered

Common stock, $0.0001 par value

 

AMGN

 

The Nasdaq Global Select Market

Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (§ 230.405 of this chapter) or Rule 12b-2 of the Securities Exchange Act of 1934 (§ 240.12b-2 of this chapter).

Emerging growth company

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

 


 

Item 1.05 Material Cybersecurity Incidents.

In July 2026, Amgen Inc. (the "Company") identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts.

The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments. To date, the Company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs. The investigation remains ongoing. The Company continues to assess whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated and to evaluate the potential impact of the incident on the Company.

On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material.

The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations.

The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients.

To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available.

 


 

SIGNATURE

Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized.

 

 

 

AMGEN INC.

 

 

 

 

Date:

July 31, 2026

By:

/s/ Jonathan P. Graham

 

 

 

Name: Jonathan P. Graham

 

 

 

Title: Executive Vice President and General Counsel and Secretary
 

 

 


Filing Exhibits & Attachments

1 document