Breach taxonomy
Summary
Amgen identified unauthorized activity involving its data stored in cloud environments hosted by third-party cloud service providers. Proprietary data, patient protected health information, and other information were exfiltrated from those environments; the company continues to assess whether confidential business information, intellectual property, and R&D data were also taken. On July 29, 2026 Amgen determined the incident was material based on the volume and sensitivity of the impacted files. No impact was identified to products, manufacturing operations, financial reporting systems, or the ability to meet patient needs.
Tagging rationale
ThreatUnknown
Filing describes only 'unauthorized activity' and names no actor or actor category → UNKNOWN.
MethodsData ExfilSupply Chain
Filing confirms data 'has been exfiltrated from these cloud environments' with no encryption or ransom described → DATA-EXFIL; the affected data sat in 'cloud environments hosted by third-party cloud service providers', so SUPPLY-CHAIN is added for the third-party hosting exposure.
AssetsPersonal DataIp Trade SecretsConfidential Biz
Filing states 'some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated' and that it is still assessing exposure of 'confidential business information, intellectual property, research and development' → PERSONAL-DATA (patient PHI) primary, plus IP-TRADE-SECRETS and CONFIDENTIAL-BIZ.
EffectsInfo Privacy Loss
Filing discloses exfiltration of patient protected health information and proprietary data while stating there was no impact to products, manufacturing, or financial reporting systems → INFO-PRIVACY-LOSS only.
Business continuityNot Required
Filing states the company 'has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs' — a data-only incident with no operational downtime → Not Required.
Impact
Amgen formally determined the incident material given the volume and sensitivity of exfiltrated files including patient PHI and proprietary R&D data, but disclosed no record count, no ransom, and no operational or financial-condition impact → score 3.
InsuranceNot disclosed
Filing makes no mention of insurance → null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. In July 2026, Amgen Inc. (the "Company") identified unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers. Upon detecting the activity, the Company activated its cybersecurity response plan, implemented containment measures, and engaged independent cybersecurity forensic experts. The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments. To date, the Company has not identified any impact to its products, manufacturing operations, or financial reporting systems, or to the Company's ability to meet patient needs. The investigation remains ongoing. The Company continues to assess whether, and/or the extent to which, patient, confidential business information, intellectual property, research and development, or other information may have been accessed, acquired, or exfiltrated and to evaluate the potential impact of the incident on the Company. On July 29, 2026, in connection with our evaluation of the volume of the files that appear to have been impacted and the potential that the types of information in such files could be sensitive, the Company determined that this incident is material. The Company believes, as of the date of this Current Report on Form 8-K, that the incident is not reasonably likely to have a material impact on the Company's financial condition or results of operations. The Company takes its obligation to safeguard privacy and security of its patients’ data very seriously. The Company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. To the extent any information required by Item 1.05(a) of Form 8-K was not determined or was unavailable at the time of this filing, the Company will amend this Current Report on Form 8-K as such information is determined or becomes available. SIGNATURE Pursuant to the requirements of the Securities Exchange Act of 1934, the registrant has duly caused this report to be signed on its behalf by the undersigned hereunto duly authorized. AMGEN INC. Date: July 31, 2026 By: /s/ Jonathan P. Graham Name: Jonathan P. Graham Title: Executive Vice President and General Counsel and Secretary