Skip to content
Rush Commerce
Software & Dev3 min read

Amgen's breach happened in someone else's cloud

Amgen's 8-K discloses data exfiltrated from third-party cloud environments — with the provider, the method, and the count all still unknown. Inventory your vendors.

Amgen filed an 8-K telling the SEC that its data was stolen. Not from Amgen's network — from third-party cloud environments run by service providers Amgen doesn't name. One of the largest pharmaceutical companies in the world, with a real security budget, got breached through infrastructure it doesn't operate — and as of the filing it still can't say which provider, how, or how many people are affected. That gap is the story.

What actually happened

Per BleepingComputer, Amgen detected unauthorized activity in July 2026 and determined the incident material on July 29. The company activated its response plan, contained the activity, and brought in outside forensics.

The disclosure itself is blunt: some of the company's data, including proprietary data and patient protected health information, was exfiltrated from those cloud environments. Amgen is still working out whether more went — confidential business information, intellectual property, R&D data, additional patient records. It does not currently expect the incident to materially affect its financial results.

What Amgen did not disclose is the more instructive list: which third-party cloud providers were involved, how those environments were compromised, how many individuals are affected, and whether any known threat actor is behind it. Four unknowns, in a filing legally required to describe a material event.

Why it matters for your business

You are not Amgen, and that's the point. Amgen has a CISO, a forensics retainer, and a legal team that files 8-Ks. It still ended up telling regulators about data it couldn't see, in systems it didn't run, on a timeline it didn't control. Your exposure is structurally identical and your leverage is worse — you find out when the vendor emails you, and the email arrives after the news does.

The fix isn't a security product. It's an inventory nobody enjoys building. Write down every SaaS tool and cloud service that holds customer records, and for each one: what data is in it, who at your company can export it, what the vendor's breach-notification commitment is in the contract, and what you'd tell customers if that vendor called tomorrow. Most small operators can't complete that list, which is the actual finding.

Then narrow what's sitting there. Data you don't send to a vendor is data that vendor can't lose — so audit what your integrations are actually syncing, not what you assumed they sync when you set them up two years ago. Half the exposure in a typical stack is fields nobody needed to push in the first place.

Key takeaways

  • Amgen's 8-K discloses data exfiltrated from third-party cloud environments, including proprietary data and patient PHI
  • Detected July 2026, deemed material July 29 — provider, attack method, victim count and threat actor all undisclosed
  • The breach happened in infrastructure Amgen doesn't operate; scope determination is still in progress
  • Build the vendor inventory: what data each SaaS holds, who can export it, and what the contract says about notification

Can you list every system holding your customer data? We map your integrations, cut the fields that don't need to leave your systems, and build automations that keep the sensitive data where you control it. See what we build or have us audit what your vendors hold.

Sources: BleepingComputer.

  • #data-breach
  • #third-party-risk
  • #cloud
  • #vendor-management
  • #compliance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.