{"id":913,"date":"2026-08-05T11:46:07","date_gmt":"2026-08-05T06:16:07","guid":{"rendered":"https:\/\/www.hexnode.com\/threat-watch\/?p=913"},"modified":"2026-08-19T11:49:25","modified_gmt":"2026-08-19T06:19:25","slug":"amgen-data-breach-what-the-disclosure-confirms-and-omits","status":"publish","type":"post","link":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/","title":{"rendered":"Amgen Data Breach: What the Disclosure Confirms and Omits"},"content":{"rendered":"<p>The Amgen data breach involved unauthorized access to data stored across third-party cloud environments, the company confirmed in a material <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-cyber-security-and-why-is-it-important\/\">cybersecurity<\/a> disclosure. In a Form 8-K filed with the SEC, Amgen confirmed that proprietary data, patient PHI, and other information were exfiltrated from those environments.<\/p>\n<p>What stands out isn&#8217;t the categories of data involved; it&#8217;s how much Amgen has left unconfirmed. It hasn&#8217;t named the cloud providers affected, confirmed an access method, disclosed a victim count, or attributed the activity to a known <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-threat-actor-in-cyber-security\/\">threat actor<\/a>. That gap between confirmed exfiltration and unconfirmed mechanics is where security teams evaluating their own third-party cloud exposure should focus.<\/p>\n<p>The incident is also a reminder that regulated data doesn&#8217;t need to sit inside a company&#8217;s own infrastructure to become a liability. When that data lives in externally hosted environments, a compromise&#8217;s impact extends well beyond the vendor relationship itself.<\/p>\n<p><center>    \t\t<!-- button style scb20be917a3efc78059cf9961ee4e54284 -->\r\n    \t\t<style>\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284, a.scb20be917a3efc78059cf9961ee4e54284{\r\n    \t\t\t\tcolor: #fff;\r\n    \t\t\t\tbackground-color: #00868B;\r\n    \t\t\t}\r\n    \t\t\t.scb20be917a3efc78059cf9961ee4e54284:hover, a.scb20be917a3efc78059cf9961ee4e54284:hover{\r\n    \t\t\t\t    \t\t\t\tbackground-color: #32b8bd;\r\n    \t\t\t}\r\n    \t\t<\/style>\r\n    \t\t<a href=\"https:\/\/www.hexnode.com\/\" class=\"ht-shortcodes-button scb20be917a3efc78059cf9961ee4e54284  hn-cta__blogs--inline-button \" id=\"\" style=\"\" >\r\n    \t\tBook a free demo and explore Hexnode today!<\/a>\r\n    \t\t<\/center><\/p>\n<h2>What Amgen has confirmed and what it hasn&#8217;t<\/h2>\n<p>The Amgen data breach disclosure is narrower than headlines suggest. It confirmed unauthorized activity in July 2026, followed by containment and a forensic investigation. It also confirmed that proprietary data, patient PHI, and other information were exfiltrated from third-party cloud environments.<\/p>\n<p>Beyond that, the filing is deliberately cautious. Amgen has not confirmed:<\/p>\n<ul>\n<li>Whether confidential business information, IP, or R&amp;D data was also accessed<\/li>\n<li>Which cloud platforms were affected<\/li>\n<li>The threat actor&#8217;s identity<\/li>\n<li>How many people are impacted<\/li>\n<\/ul>\n<p>The <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-initial-access-in-cybersecurity\/\">initial access<\/a> vector also remains unestablished. BleepingComputer asked Amgen whether a vishing attack compromised an employee&#8217;s <a href=\"https:\/\/www.hexnode.com\/blogs\/single-sign-on-its-relevance\/\">SSO<\/a> account, which cloud services the incident affected, and whether ShinyHunters had made contact.<\/p>\n<p>Amgen did not respond by publication time. Until Amgen or investigators confirm these details, they remain open questions, not facts.<\/p>\n<div class=\"next_blog\"><div class=\"post-next\"><div class=\"hex_blog_box_parent\"><div class=\"blog_warp_next\"><div class=\"next_blog_thumb\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/threat-analysis-.jpeg?format=webp)\"><\/div><div class=\"next_post_content\"><div class=\"center_box\"><h4>What is Threat Analysis?<\/h4><p>Beginner's guide explaining threat analysis process, elements, types, and Hexnode's role.<\/p><\/div><\/div><\/div><a class=\"hex_blog_box_link hn-cta__blogs--blog-box\" href=\"https:\/\/www.hexnode.com\/blogs\/what-is-threat-analysis\/\" aria-label=\"What is Threat Analysis?\"><\/a><\/div><\/div><\/div>\n<h2>Why third-party cloud environments are a recurring blind spot<\/h2>\n<p>The Amgen data breach fits a broader pattern rather than an isolated case. Health-ISAC has warned of rising data theft activity from the ShinyHunters group targeting the healthcare sector, and Medtronic separately notified customers of a breach widely attributed to the same group, based on the group&#8217;s own claim and subsequent reporting.<\/p>\n<p>These are separate incidents, and nothing in Amgen&#8217;s disclosure confirms a link. No official technical indicators currently tie any of these groups to Amgen&#8217;s Form 8-K, and Amgen&#8217;s filing does not name a threat actor.<\/p>\n<p>The broader trend is still notable: attackers are increasingly bypassing an organization&#8217;s own network perimeter to target:<\/p>\n<ul>\n<li>SaaS platforms<\/li>\n<li>Cloud storage repositories<\/li>\n<li>Third-party data processors<\/li>\n<\/ul>\n<p>That shift changes what &#8220;containment&#8221; means. When data lives in a vendor-hosted environment, the affected organization often depends on that vendor&#8217;s access logs, authentication records, and configuration history to determine what happened.<\/p>\n<ul>\n<li>Investigating cloud-hosted exposure typically requires reviewing:<\/li>\n<li>Identity and access logs<\/li>\n<li>API activity<\/li>\n<li>Service account behavior<\/li>\n<li>Storage permissions<\/li>\n<li>Third-party integration points<\/li>\n<\/ul>\n<p>This goes beyond what endpoint telemetry alone can show. Until investigators review those sources, scope estimates remain provisional.<\/p>\n<h2>Amgen data breach: Disclosure timeline and notification signals<\/h2>\n<table style=\"width: 100%;\">\n<thead>\n<tr>\n<th style=\"width: 29.387%; text-align: left;\">Milestone<\/th>\n<th style=\"width: 34.8837%; text-align: left;\">What&#8217;s Known<\/th>\n<th style=\"width: 34.6723%; text-align: left;\">Why It Matters<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td style=\"width: 29.387%;\">Detection (July 2026)<\/td>\n<td style=\"width: 34.8837%;\">Amgen identified unauthorized cloud activity<\/td>\n<td style=\"width: 34.6723%;\">Triggered incident response and forensic engagement<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 29.387%;\">Materiality determination (July 29, 2026)<\/td>\n<td style=\"width: 34.8837%;\">Based on file volume and likelihood of sensitive content<\/td>\n<td style=\"width: 34.6723%;\">Required SEC disclosure under Form 8-K rules<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 29.387%;\">Public disclosure (July 31, 2026)<\/td>\n<td style=\"width: 34.8837%;\">Confirmed exfiltration of proprietary data and patient PHI<\/td>\n<td style=\"width: 34.6723%;\">Made the incident public and set up separate regulatory\/patient notification review, which Amgen says is still ongoing<\/td>\n<\/tr>\n<tr>\n<td style=\"width: 29.387%;\">Post-disclosure (early August 2026)<\/td>\n<td style=\"width: 34.8837%;\">Amgen has not yet notified affected individuals directly<\/td>\n<td style=\"width: 34.6723%;\">At least one law firm has announced an investigation into the breach on behalf of potentially affected individuals<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>Amgen said it is evaluating notification requirements and will notify patients where required. As of early August, that notification reportedly hadn&#8217;t occurred, and one law firm announced an investigation. Materiality determination and patient notification remain separate obligations on separate timelines.<\/p>\n<h2>Where endpoint visibility fits into a cloud-centric incident<\/h2>\n<p>Cloud storage exfiltration like the Amgen data breach sits largely outside what endpoint tools observe. Hexnode does not:<\/p>\n<ul>\n<li>Monitor third-party cloud storage<\/li>\n<li>Ingest SaaS provider logs<\/li>\n<li>Detect <a href=\"https:\/\/www.hexnode.com\/blogs\/explained\/what-is-data-exfiltration\/\">data exfiltration<\/a> inside an external cloud environment<\/li>\n<\/ul>\n<p>That visibility depends on the cloud provider&#8217;s logging and the organization&#8217;s identity infrastructure.<\/p>\n<h3>Hexnode UEM and XDR contribute on the endpoint side &#8211;<\/h3>\n<ul>\n<li><a href=\"https:\/\/www.hexnode.com\/uem\/\">Hexnode UEM<\/a> enforces device compliance policies and, through Conditional Access integrations with providers like Microsoft Entra ID and Okta, restricts access to corporate resources to managed, compliant devices.<\/li>\n<li><a href=\"https:\/\/www.hexnode.com\/xdr\/\">Hexnode XDR<\/a> can investigate suspicious activity on managed endpoints, primarily Windows and macOS, using endpoint telemetry such as process, script, registry, and network activity, findings that security teams can manually cross-reference with cloud and identity investigation data gathered elsewhere.<\/li>\n<\/ul>\n<p>Neither capability replaces cloud forensic review, access log analysis, or vendor-side containment. Those remain the responsibility of the cloud providers and Amgen&#8217;s investigators. Endpoint visibility complements that work, not a substitute for it.<\/p>\n<section id='resource-single'>\n                    <div class='resource-box'>\n                        <div class='resource-box__image-section'>\n                            <div class='resource-box__image-wrap'>\n                                <img decoding=\"async\" src=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-for-data-security.png?format=webp\" class=\"resource-box__image\" alt=\"hexnode for data security\" loading=\"lazy\" srcset=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-for-data-security.png?format=webp 960w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-for-data-security-300x225.png?format=webp 300w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-for-data-security-768x576.png?format=webp 768w, https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-for-data-security-133x100.png?format=webp 133w\" sizes=\"auto, (max-width: 960px) 100vw, 960px\" title=\"hexnode for data security\" \/>\n                            <\/div>\n                        <\/div>\n                        <div class='resource-box__content-section'>\n                            <h5 class='resource-box__content-subheading'>\n                            Featured resource\n                            <\/h5>\n                            <h4 class='resource-box__content-heading'>\n                            Hexnode for data security\n                            <\/h4>\n                            <p class='resource-box__contents'>\n                            Whitepaper explaining data security fundamentals and how Hexnode UEM strengthens organizational data protection infrastructure.\n                            <\/p>\n                            <a class='resource-box__content-link hn-cta__blogs--resource-box' href='https:\/\/www.hexnode.com\/resources\/white-papers\/hexnode-for-data-security\/'>\n                            DOWNLOAD\n                            <svg xmlns='http:\/\/www.w3.org\/2000\/svg' width='20' height='20' viewBox='0 0 20 20'>\n                            <g id='arrow' transform='translate(-309 -191)' opacity='0'>\n                                <rect id='base' width='20' height='20' transform='translate(309 191)' fill='none'\/>\n                                <path id='arrow-2' data-name='arrow' d='M13.093.5,6.8,6.8.5.5' transform='translate(315 207.594) rotate(-90)' fill='none' stroke='#0549d1' stroke-linecap='round' stroke-linejoin='round' stroke-width='1.2'\/>\n                            <\/g>\n                            <\/svg>\n\n                            <\/a>\n                        <\/div>\n                    <\/div>\n                <\/section>\n<div class=\"faq-section-wrapper\" itemscope itemtype=\"https:\/\/schema.org\/FAQPage\"><h2 class=\"faq-main-title\">FAQs<\/h2><div class=\"faq-items\"><div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Does patching endpoint software address this type of breach?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. This incident involved third-party cloud storage, not an endpoint vulnerability. Endpoint patch hygiene is good practice, but it doesn&#8217;t remediate a cloud provider-side compromise.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">Should organizations assume ransomware or a public data leak followed this breach?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>No. Public reporting hasn&#8217;t confirmed ransomware or a public data leak tied to this incident. The confirmed fact is proprietary data theft and PHI exfiltration; anything beyond that remains unestablished.<\/p>\n<\/div><\/div><\/div>\n<div class=\"faq-item\" itemprop=\"mainEntity\" itemscope itemtype=\"https:\/\/schema.org\/Question\"><div class=\"faq-item__question\" role=\"button\" tabindex=\"0\" aria-expanded=\"false\"><span itemprop=\"name\">What should other organizations using third-party cloud storage for regulated data check first?<\/span>\n            <div class=\"toggle\" aria-hidden=\"true\"><span><\/span><span><\/span><\/div>\n        <\/div> <div class=\"faq-item__content\" itemprop=\"acceptedAnswer\" itemscope itemtype=\"https:\/\/schema.org\/Answer\"><div class=\"faq-item__body\" itemprop=\"text\"><p>Review which cloud environments hold PHI or proprietary data, confirm who owns log retention and access monitoring, and restrict access to compliant, managed devices with current identity controls.<\/p>\n<\/div><\/div><\/div><\/div><\/div>\n<h3>Conclusion<\/h3>\n<p>The Amgen breach shows a pattern common to cloud-hosted incidents: confirmed exfiltration paired with an unconfirmed access path, provider, and scope. That gap isn&#8217;t a reporting failure. It reflects how long third-party cloud forensics takes when the affected organization doesn&#8217;t control the underlying logging.<\/p>\n<p>For enterprises handling PHI or proprietary data in third-party cloud environments, the takeaway is to verify vendor logging and notification commitments before an incident, not after. Layered visibility across identity, cloud access, and managed endpoints won&#8217;t prevent every compromise, but it reduces the unknowns security teams face when one occurs.<\/p>\n<div class=\"signup_box\"><div class=\"signup_wrap_img\"><div class=\"signup-bg\" style=\"background-image:url(https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/Hexnode-MDM-free-trial.jpg?format=webp)\"><\/div><\/div><div class=\"signup_wrap\"><h5>Strengthen Endpoint Access Hygiene Enterprise-Wide <\/h5><p>Apply consistent device compliance controls across trusted, managed endpoints. \r\n<\/p><a href=\"https:\/\/www.hexnode.com\/mobile-device-management\/cloud\/signup\/\" class=\"hn-cta__blogs--signup-stripe\" target=\"_blank\"> SIGN UP NOW<\/a><\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>The Amgen data breach involved unauthorized access to data stored across third-party cloud environments, the&#8230;<\/p>\n","protected":false},"author":5,"featured_media":914,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[13,19],"class_list":["post-913","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-identity-abuse","category-cloud-and-saas","product_category-identity-provider","tab_group-identity-and-phishing"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed<\/title>\n<meta name=\"description\" content=\"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed\" \/>\n<meta property=\"og:description\" content=\"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/\" \/>\n<meta property=\"og:site_name\" content=\"Hexnode Threat Watch\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hexnode\/\" \/>\n<meta property=\"article:published_time\" content=\"2026-08-05T06:16:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-19T06:19:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1340\" \/>\n\t<meta property=\"og:image:height\" content=\"700\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Sophia Hart\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:site\" content=\"@thehexnode\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sophia Hart\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":[\"Article\",\"BlogPosting\"],\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/\"},\"author\":{\"name\":\"Sophia Hart\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\"},\"headline\":\"Amgen Data Breach: What the Disclosure Confirms and Omits\",\"datePublished\":\"2026-08-05T06:16:07+00:00\",\"dateModified\":\"2026-08-19T06:19:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/\"},\"wordCount\":1103,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/amgen-data-breach.jpeg?format=webp\",\"articleSection\":[\"Identity Abuse\",\"Cloud and SaaS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/\",\"name\":\"Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/amgen-data-breach.jpeg?format=webp\",\"datePublished\":\"2026-08-05T06:16:07+00:00\",\"dateModified\":\"2026-08-19T06:19:25+00:00\",\"description\":\"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/amgen-data-breach.jpeg?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/amgen-data-breach.jpeg?format=webp\",\"width\":1340,\"height\":700,\"caption\":\"amgen data breach\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/amgen-data-breach-what-the-disclosure-confirms-and-omits\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Amgen Data Breach: What the Disclosure Confirms and Omits\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#website\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"name\":\"Hexnode Threat Watch\",\"description\":\"Latest cyber threats, smarter enterprise response.\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\"},\"alternateName\":\"Threat Watch\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#organization\",\"name\":\"Hexnode\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"contentUrl\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/hexnode-2.png?format=webp\",\"width\":100,\"height\":100,\"caption\":\"Hexnode\"},\"image\":{\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/Hexnode\\\/\",\"https:\\\/\\\/x.com\\\/thehexnode\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/hexnode\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/#\\\/schema\\\/person\\\/7303d7e90665b5fbccde155fa1c11430\",\"name\":\"Sophia Hart\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g\",\"caption\":\"Sophia Hart\"},\"url\":\"https:\\\/\\\/www.hexnode.com\\\/threat-watch\\\/author\\\/sophia-hart\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed","description":"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/","og_locale":"en_US","og_type":"article","og_title":"Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed","og_description":"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.","og_url":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/","og_site_name":"Hexnode Threat Watch","article_publisher":"https:\/\/www.facebook.com\/Hexnode\/","article_published_time":"2026-08-05T06:16:07+00:00","article_modified_time":"2026-08-19T06:19:25+00:00","og_image":[{"width":1340,"height":700,"url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp","type":"image\/jpeg"}],"author":"Sophia Hart","twitter_card":"summary_large_image","twitter_creator":"@thehexnode","twitter_site":"@thehexnode","twitter_misc":{"Written by":"Sophia Hart","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":["Article","BlogPosting"],"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#article","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/"},"author":{"name":"Sophia Hart","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430"},"headline":"Amgen Data Breach: What the Disclosure Confirms and Omits","datePublished":"2026-08-05T06:16:07+00:00","dateModified":"2026-08-19T06:19:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/"},"wordCount":1103,"commentCount":0,"publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp","articleSection":["Identity Abuse","Cloud and SaaS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/","url":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/","name":"Amgen Data Breach: Cloud Exposure of Patient PHI Confirmed","isPartOf":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#primaryimage"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#primaryimage"},"thumbnailUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp","datePublished":"2026-08-05T06:16:07+00:00","dateModified":"2026-08-19T06:19:25+00:00","description":"Amgen data breach: SEC filing confirms cloud exposure of patient PHI and proprietary data, but key details remain unconfirmed.","breadcrumb":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#primaryimage","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/amgen-data-breach.jpeg?format=webp","width":1340,"height":700,"caption":"amgen data breach"},{"@type":"BreadcrumbList","@id":"https:\/\/www.hexnode.com\/threat-watch\/amgen-data-breach-what-the-disclosure-confirms-and-omits\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.hexnode.com\/threat-watch\/"},{"@type":"ListItem","position":2,"name":"Amgen Data Breach: What the Disclosure Confirms and Omits"}]},{"@type":"WebSite","@id":"https:\/\/www.hexnode.com\/threat-watch\/#website","url":"https:\/\/www.hexnode.com\/threat-watch\/","name":"Hexnode Threat Watch","description":"Latest cyber threats, smarter enterprise response.","publisher":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization"},"alternateName":"Threat Watch","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.hexnode.com\/threat-watch\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.hexnode.com\/threat-watch\/#organization","name":"Hexnode","url":"https:\/\/www.hexnode.com\/threat-watch\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/","url":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","contentUrl":"https:\/\/www.hexnode.com\/threat-watch\/wp-content\/uploads\/2026\/08\/hexnode-2.png?format=webp","width":100,"height":100,"caption":"Hexnode"},"image":{"@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hexnode\/","https:\/\/x.com\/thehexnode","https:\/\/www.linkedin.com\/company\/hexnode"]},{"@type":"Person","@id":"https:\/\/www.hexnode.com\/threat-watch\/#\/schema\/person\/7303d7e90665b5fbccde155fa1c11430","name":"Sophia Hart","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9f2fcf8cf2a94925b3769939d19f157c643407bd45ff69fd553f22903b961f3a?s=96&d=mm&r=g","caption":"Sophia Hart"},"url":"https:\/\/www.hexnode.com\/threat-watch\/author\/sophia-hart\/"}]}},"_links":{"self":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/913","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/comments?post=913"}],"version-history":[{"count":2,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/913\/revisions"}],"predecessor-version":[{"id":916,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/posts\/913\/revisions\/916"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media\/914"}],"wp:attachment":[{"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/media?parent=913"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexnode.com\/threat-watch\/wp-json\/wp\/v2\/categories?post=913"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}