NG Solution Team
Cybersecurity

Amgen cybersecurity breach exposes patient data, SEC filing says

Amgen disclosed in an SEC filing on Friday that a cybersecurity breach in cloud storage hosted by third‑party service providers resulted in the exfiltration of some of its data, including proprietary information and patient protected health information.

Amgen cybersecurity breach details

The company said investigators detected “unauthorized activity” in those cloud repositories and that an investigation is ongoing. Amgen characterizes the event as “material,” citing the “volume of the files that appear to have been impacted” and the potentially sensitive nature of the information accessed.

Amgen reported that, to date, the incident has had no discernible impact on its ability to meet patient needs and does not appear to have compromised the company’s financial reporting, manufacturing operations or products. The company does not expect its financial condition to be affected.

Amgen added that it “takes its obligation to safeguard privacy and security of its patients’ data very seriously” and will make the appropriate regulatory and legal notifications as needed. The filing noted that the company did not provide avenues of recourse for patients who may be affected by the breach.

Amgen is scheduled to report second‑quarter earnings on Tuesday.

Context: regulatory and product challenges

The disclosure comes amid several recent setbacks for Amgen. In January, the FDA called for the voluntary withdrawal of Tavneos, a rare‑disease drug acquired with ChemoCentryx in 2022; Amgen has refused the withdrawal. The FDA in April alleged that pivotal data supporting Tavneos’ approval had been manipulated. Amgen has requested a hearing with the regulator and last month submitted a data and analyses package along with patient testimonials to support its case.

Separately, in early July Amgen recalled nearly a million bottles of its chronic heart failure drug Corlanor over contamination concerns.

Amgen is not alone among large drugmakers to face recent cyberattacks. In June, Novo Nordisk reported a data breach that affected “a limited amount of information related to patients participating in some of our clinical trials,” and said only deidentified data had been accessed while urging trial participants to be vigilant.

Related posts

Kenya restores president’s website after Bitcoin ransom hack

James Smith

Do smartphones store too much data without protection?

Jessica Williams

Was Cal Water’s cybersecurity breach by Iranian hackers limited?

James Smith

This website uses cookies to improve your experience. We assume you agree, but you can opt out if you wish. Accept More Info

Privacy & Cookies Policy