Key facts
- Amgen experienced a cybersecurity breach affecting third-party cloud storage systems.
- Patient health information was among the data stolen.
- The company has initiated its cybersecurity response and is investigating.
- A separate incident involving service provider Sirva, Inc. impacted New Hampshire residents.
- Personal information of 3 New Hampshire residents was accessed via the Sirva incident.
Drugmaker Amgen announced on Friday that a cybersecurity breach involving cloud storage systems managed by third-party providers resulted in the theft of company data and patient health information. The company determined the incident was material on July 29, based on the volume of affected files and the potential sensitivity of the information. Amgen has activated its cybersecurity response plan, implemented containment measures, and enlisted independent forensic experts to investigate the breach.
In a separate incident, Amgen's service provider, Sirva, Inc., experienced a data security incident. Sirva became aware of suspicious activity on its network around September 29, 2023. An investigation revealed that unknown actors accessed certain Sirva systems between August 16, 2023, and October 17, 2023, copying certain files. On April 10, 2024, Sirva informed Amgen that individuals affiliated with Amgen may have been impacted. Following further information from Sirva on August 8, 2024, Amgen notified New Hampshire regulators on September 25, 2024, that the personal information of three New Hampshire residents may have been accessed in connection with the Sirva incident. Amgen stated that no Amgen systems were directly impacted by the Sirva incident.
