HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Amgen Reports Cloud‑Scale Data Exfiltration of Patient PHI and Trade Secrets

Amgen disclosed to the SEC that unauthorized activity in July resulted in the theft of patient PHI, research data, and confidential business files from cloud services hosted by third‑party providers. The breach highlights the need for continuous vendor‑risk monitoring to satisfy SOC 2 audit requirements.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 databreachtoday.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
databreachtoday.com

Amgen Reports Cloud‑Scale Data Exfiltration of Patient PHI and Trade Secrets

What Happened – Amgen disclosed to the SEC that unauthorized activity in July led to the exfiltration of patient protected health information (PHI), research data, and confidential business files from cloud environments hosted by third‑party providers. The breach is attributed to a threat group known for large‑scale cloud attacks.

Why It Matters for Compliance & Audit Readiness

  • This scenario directly tests SOC 2 vendor‑management controls (CC6.1) that require continuous monitoring of third‑party cloud services.
  • Demonstrating timely detection, containment, and forensic evidence collection is essential for a defensible audit trail.
  • Maintaining up‑to‑date third‑party risk assessments helps prove due diligence when material data is at stake.

Who Is Affected – Pharmaceutical and biotechnology firms that store PHI and IP in third‑party cloud platforms.

Recommended Actions – Map the incident to SOC 2 vendor‑management controls, gather evidence of cloud‑security assessments, verify third‑party provider attestations, and update incident‑response playbooks to include continuous monitoring checkpoints. Source: DataBreachToday

Technical Notes – The breach involved unauthorized access to cloud storage; no specific CVE was disclosed. Threat actors identified align with the ShinyHunters group, known for exploiting mis‑configurations and compromised credentials in cloud environments. Data types exfiltrated include PHI, R&D files, and proprietary business documents. Source: DataBreachToday

📰 Original Source
https://www.databreachtoday.com/amgen-tells-sec-hack-exposed-patient-data-trade-secrets-a-32401

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →