On July 29, 2026, Amgen filed an 8-K with the SEC disclosing that attackers had stolen proprietary business data and patient protected health information (PHI) from cloud environments hosted by third-party providers. If you're an Amgen patient, clinical-trial participant, or received financial assistance through an Amgen program, take these seven steps now to protect your identity and health records.
What Happened in the Amgen Data Breach
Amgen detected unauthorized activity in mid-July 2026 and disclosed the incident on July 29, 2026 through an SEC Form 8-K filing, classifying it as material. According to the disclosure and follow-up reporting, threat actors exfiltrated data from cloud environments operated by third-party service providers Amgen uses for hosting patient and corporate data.
Amgen has not publicly named the compromised cloud vendors, the method of intrusion, or the exact number of people affected. The company said the incident is not expected to affect its manufacturing operations, financial reporting systems, or its ability to supply medicines to patients.
What Information Was Exposed
Based on Amgen's SEC filing and subsequent reporting from HIPAA Journal and BleepingComputer, the stolen files include:
- Patient protected health information (PHI) — HIPAA-regulated data about individuals receiving Amgen therapies or enrolled in Amgen support programs
- Proprietary corporate data — research, intellectual property, and confidential business files
- Other unspecified sensitive information
Why PHI Theft Is Uniquely Dangerous
Health records sell for far more on the dark web than credit card numbers. Criminals use stolen PHI to file fraudulent insurance claims, obtain prescription medications, and commit medical identity theft — which can corrupt your actual health record and put your care at risk.
Step 1: Determine If You're Affected
Under HIPAA's Breach Notification Rule, Amgen must notify affected individuals within 60 days of discovering the breach. Watch your postal mail and the email address on file with any Amgen patient program for an official notification letter.
You may be affected if you have:
- Enrolled in an Amgen patient support program (such as the Amgen Assist or Amgen SupportPlus programs)
- Participated in an Amgen-sponsored clinical trial
- Received financial assistance through Amgen Safety Net Foundation
- Interacted with an Amgen-operated patient portal
You can also check haveibeenpwned.com after breach data is publicly indexed, and monitor the HHS Office for Civil Rights Breach Portal for the official filing.
Step 2: Freeze Your Credit at All Three Bureaus
Freezing your credit prevents anyone from opening new accounts, loans, or credit lines in your name. It's free, doesn't affect your credit score, and takes about 10 minutes total:
- Equifax: 1-800-685-1111 or equifax.com/personal/credit-report-services/credit-freeze
- Experian: 1-888-397-3742 or experian.com/freeze
- TransUnion: 1-888-909-8872 or transunion.com/credit-freeze
Save your PINs somewhere secure — you'll need them to temporarily lift the freeze when you legitimately apply for credit.
Step 3: Request a Copy of Your Medical Records
Medical identity theft is the biggest risk of a PHI breach. Request copies of your medical records from each of your primary providers and review them for any procedures, prescriptions, or diagnoses you don't recognize. Under HIPAA you have a right to your records within 30 days.
You should also request an accounting of disclosures — a list showing who has accessed or received your records — from your providers.
Is your data already out there?
Leaked data ends up on broker sites and in scammers' hands. Run a free 60-second scan to see your exposure — then let us remove it.
Run a free scan★★★★★ 4.8/5 · Trusted by thousands of families
Step 4: Notify Your Health Insurer
Contact your health insurance company and ask them to flag your account for potential medical identity theft. Request an Explanation of Benefits (EOB) statement for the past 24 months and check every entry against services you actually received.
Any claim, prescription, or procedure you don't recognize should be reported to your insurer's fraud line immediately.
Step 5: Enroll in Any Credit Monitoring Amgen Offers
Companies breached under HIPAA typically offer affected individuals 12-24 months of free credit and identity monitoring. Watch for enrollment instructions in the notification letter and sign up promptly — the offer usually has a redemption deadline.
Credit monitoring alone doesn't catch medical identity theft, so you'll still want to review medical statements yourself.
Step 6: Watch for Targeted Phishing and "Recovery" Scams
After any healthcare breach, scammers impersonate the breached company, government agencies, and "identity recovery services" to trick victims into handing over more data. Expect:
- Emails claiming to be from Amgen asking you to "verify your identity" or "confirm your treatment records"
- Phone calls from people impersonating HHS, HIPAA, or law-enforcement investigators
- Text messages with links to "check if you're affected" or "claim your settlement"
- Fake class-action notices offering compensation in exchange for banking information
How to Verify a Real Amgen Notification
Legitimate breach notifications will come by U.S. mail with a case reference and phone number to a dedicated response center. They will never ask for your Social Security number, health insurance ID, or bank information over the phone. When in doubt, hang up and call the number printed on your Amgen patient program materials.
Step 7: File Reports With the Right Agencies
If you find signs of identity theft or medical fraud:
- IdentityTheft.gov — file an FTC identity theft report to unlock official recovery tools
- HHS Office for Civil Rights — file a HIPAA complaint at hhs.gov/ocr
- Your state attorney general — some states require notification and offer additional victim resources
- Your local police — a police report is helpful when disputing fraudulent charges
Reduce Your Long-Term Exposure With Data Broker Removal
Once your name, address, and health-related purchasing history are on the dark web, data brokers scoop up whatever they can and add it to your existing profile — accelerating spam, scam calls, and targeted phishing tied to your diagnosis. PrivacyOn continuously monitors and removes your information from 100+ people-search and data broker sites, adds 24/7 dark web monitoring, and covers up to 5 family members from $8.33/month. Start with a free scan to see which brokers currently expose your address, phone number, and relatives — the same fields Amgen breach victims are most likely to see reused in follow-up scams.
Combined with a credit freeze and vigilant EOB monitoring, broker removal is the layer that stops attackers from linking your leaked Amgen data to a live profile they can exploit years later.
Frequently Asked Questions
Is the Amgen data breach the same as the Salesforce breach wave?
No. The Amgen breach involves data stolen from Amgen's third-party cloud environments and was disclosed on July 29, 2026. It's separate from the ShinyHunters-driven Salesforce breach wave, though both involve cloud-hosted business data. Amgen has not attributed the attack to a specific threat actor as of the SEC filing.
How many people were affected by the Amgen breach?
Amgen has not disclosed the number of affected individuals in its July 2026 SEC filing. Under HIPAA, the total will eventually be published in the HHS Office for Civil Rights Breach Portal once notification requirements are met.
What data did Amgen lose in the 2026 breach?
According to Amgen's 8-K disclosure, attackers stole proprietary corporate data, patient protected health information (PHI), and other sensitive files from cloud environments operated by third-party providers. The exact fields — names, addresses, health conditions, insurance details — will be spelled out in individual notification letters.
Should I sign up for a free credit monitoring offer from Amgen?
Yes — but only through the enrollment code included in your official notification letter. Never enroll through links in unsolicited emails or texts claiming to offer Amgen breach protection, as scammers routinely impersonate breached companies to harvest more data.
Is there a better long-term protection than credit monitoring after the Amgen breach?
Yes. Credit monitoring is reactive — it tells you after fraud happens. A service like PrivacyOn is preventive: it removes your address, phone, relatives, and workplace from 100+ data broker sites so attackers can't easily correlate leaked health data with your current profile, and adds 24/7 dark web monitoring for early warning. Family plans cover up to 5 people from $8.33/month.
What is medical identity theft and how do I know if it's happened to me?
Medical identity theft is when a criminal uses your name and insurance information to obtain healthcare, prescriptions, or fraudulent claims. Warning signs include EOB statements for services you didn't receive, bills from unknown providers, insurance claim denials for "benefits already used," and unfamiliar diagnoses in your medical records. Review both your credit and medical statements every month.
Can I sue Amgen over the breach?
Class-action lawsuits are already being investigated by consumer protection firms. Whether you can join depends on your state, whether your data was actually included, and the terms of the eventual settlement. Before signing up with any "class action" website, verify the case number at PACER.gov or your state court's official docket.