Circuit Wire — a daily news update from the Circuit.

Amgen, one of the world's largest biotechnology companies, told US regulators that attackers stole patient health data and proprietary files from cloud systems run by outside providers. The California-based firm, with a market value near $207.8 billion, disclosed the theft in a Form 8-K filed with the Securities and Exchange Commission on July 31.

Amgen said it detected unauthorized activity in July involving data held in cloud environments hosted by third-party service providers. It activated its cybersecurity response plan, put containment measures in place, and hired independent forensic experts. The investigation found that proprietary data, patient protected health information, and other records had been taken from those environments.

On July 29, the company determined the incident was material after weighing the volume of affected files and the chance they held sensitive information. Amgen said it does not currently believe the breach is reasonably likely to affect its financial condition or results. It reported no disruption to its products, its manufacturing, its financial reporting, or its ability to supply medicines to patients.

Much about the attack remains unconfirmed. Amgen has not said which cloud providers were involved, how the environments were breached, how many people were affected, or whether a known group was responsible. There is no public sign that ransomware was used, and no criminal group has claimed the theft. The company said its investigation is continuing with help from outside cybersecurity experts, and that it is still assessing whether intellectual property, research and development data, or further patient records were taken. It plans to notify affected patients.

The breach lands amid a run of intrusions across the drug and healthcare sector. In May, Pennsylvania-based West Pharmaceutical Services said a ransomware attack disrupted manufacturing and shipping after data was stolen. In August 2025, Indiana drug-research firm Inotiv shut critical systems following an attack later claimed by the Qilin gang. BleepingComputer reported that it asked Amgen whether the intrusion involved a voice-phishing attack on an employee sign-on account, and whether extortionists linked to ShinyHunters had been in contact. The company did not immediately respond.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

Keep Reading