Hackers recently accessed Amgen’s cloud environment, stealing sensitive patient health information and proprietary company data, the company disclosed in a securities filing on Friday.
According to a securities filing (PDF), Amgen identified unauthorized activity in its cloud storage systems hosted by external service providers in July. The California company activated its cybersecurity response plan and initiated containment measures. Still, a subsequent forensic investigation confirmed that attackers had stolen those data.
Although Amgen stated that it “has not identified any impact” to its products, manufacturing operations, financial reporting or delivery to patients to date, it has determined that the incident is “material.”
The company added that the breach is “not reasonably likely to have a material impact on the Company's financial condition or results of operations,” although its investigation into the full scope of compromised confidential records remains ongoing.
Amgen said it plans to notify affected patients.
Amgen’s latest encounter adds to a growing series of cybersecurity incidents within the biopharma sector, which often holds high-value intellectual property and sensitive patient records.
Just weeks ago, Novo Nordisk fell victim to a breach to its internal IT systems, accompanied by multi-million-dollar ransom demands from two cyberextortion groups, FulcrumSec and TheUSERS007. Unmatched clinical trial participant information was among data that hackers accessed, according to Novo.
The Danish drugmaker reportedly refused to pay either ransom and advised patients affected to remain vigilant if classified information surfaces online.
Similarly, in 2022, Novartis found itself dealing with a breach by the Industrial Spy extortion group, which claimed to have stolen data related to DNA- and RNA-based drug technologies and attempted to sell them on dark web marketplaces.
Today, the rise of artificial intelligence brings new challenges to corporate cybersecurity. In Novo’s case, TheUSERS007 claimed that it gained access to the diabetes and obesity drug giants’ systems using a self-learning, adaptive AI engine called venomware.
In autonomous hacking cases, major AI developers OpenAI and Anthropic recently both disclosed that their AI systems busted out of their testing environment and hacked other companies, raising concerns over the need for more robust cyberdefense mechanisms. Both OpenAI and Anthropic have formed partnerships for biopharmaceutical companies to use their AI tools, although the recent incidents did not concern biopharma.
Amgen has also established an AI Government Council comprised of cross-functional leadership that oversees the company’s adoption of third-party AI services. More broadly, a cybersecurity and digital trust team is responsible for cybersecurity at Amgen.