All NewsEducationTV
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
Story archiveAll categories
← All Stories

Amgen discloses data breach, patient information stolen

Created at 31 Jul · 8:31 PM1 source↑ Market-relevant
IN SHORT

Drugmaker Amgen reported a cybersecurity breach involving third-party cloud storage systems, resulting in the theft of company data and patient health information. The company has initiated its cybersecurity response plan and is investigating the incident.

✉Newsletter

PiQ Daily

Pick your topics. Get only what matters, on your cadence.

Key Numbers

3New Hampshire residents impacted by Sirva incident

Who's Involved

Amgen
Drugmaker disclosing data breach
Sirva, Inc.
Amgen service provider impacted by separate data security incident
Amgen discloses data breach, patient information stolen

↳ Why This Matters

The data breach raises concerns about patient privacy and the security of sensitive health information handled by third-party vendors. It also highlights the risks associated with cloud storage systems and the importance of robust cybersecurity measures for healthcare companies.

Key facts

  • Amgen experienced a cybersecurity breach affecting third-party cloud storage systems.
  • Patient health information was among the data stolen.
  • The company has initiated its cybersecurity response and is investigating.
  • A separate incident involving service provider Sirva, Inc. impacted New Hampshire residents.
  • Personal information of 3 New Hampshire residents was accessed via the Sirva incident.

Drugmaker Amgen announced on Friday that a cybersecurity breach involving cloud storage systems managed by third-party providers resulted in the theft of company data and patient health information. The company determined the incident was material on July 29, based on the volume of affected files and the potential sensitivity of the information. Amgen has activated its cybersecurity response plan, implemented containment measures, and enlisted independent forensic experts to investigate the breach.

In a separate incident, Amgen's service provider, Sirva, Inc., experienced a data security incident. Sirva became aware of suspicious activity on its network around September 29, 2023. An investigation revealed that unknown actors accessed certain Sirva systems between August 16, 2023, and October 17, 2023, copying certain files. On April 10, 2024, Sirva informed Amgen that individuals affiliated with Amgen may have been impacted. Following further information from Sirva on August 8, 2024, Amgen notified New Hampshire regulators on September 25, 2024, that the personal information of three New Hampshire residents may have been accessed in connection with the Sirva incident. Amgen stated that no Amgen systems were directly impacted by the Sirva incident.

Frequently asked questions

The stolen information included company data and patient health information.

Amgen determined the incident was material on July 29.

No, the breach involved cloud storage systems run by third-party providers. In a separate incident, Amgen's service provider Sirva, Inc. was impacted, but Amgen's own systems were not.

What Happens Next

01Amgen is providing notice to affected individuals.
02Amgen is cooperating with ongoing investigations into the breach.

Get the newsletter.

Pick the topics you actually care about. We'll email when there's news worth your time, on the cadence you choose. Cancel any time from your account.

Cadence

How It Developed

Amgen disclosed a cybersecurity breach involving third-party cloud storage systems.
Hackers stole company data and patient health information.
Amgen determined the incident was material on July 29.
The company activated its cybersecurity response plan and engaged forensic experts.
A separate incident involving Amgen service provider Sirva, Inc. impacted New Hampshire residents.
Sirva's investigation revealed certain files were copied between August 16 and October 17, 2023.
Sirva notified Amgen on April 10, 2024, that Amgen-affiliated individuals may have been impacted.
Amgen provided notice to New Hampshire regulators on September 25, 2024, regarding the Sirva incident.

Sources

T1
Amgen discloses data breach, says patient information was stolenReuters
T2
September 25, 2024 VIA E-MAIL TO: [email protected] Office of the Attorney General Consumer Protection & Antitrust Bureau 33 Capitol Street Concord, NH 03301 Re: Notice of Data Security Incident Dear Attorney General Formella, I am writing on behalf of Amgen Inc. (“Amgen”) to inform you of a recent data security incident that may affect the personal information of New Hampshire state residents. On or about September 29, 2023, Amgen service provider Sirva, Inc. (“Sirva”) became aware of suspicious activity involving its network and began an investigation. The investigation determined certain Sirva systems were accessed by unknown actors between August 16, 2023 and October 17, 2023, and that during this time certain files were copied. Further, on March 21, 2024, Sirva’s investigation revealed that some personal information relating to individuals associated with Sirva and certain Sirva clients had been accessed. On April 10, 2024, Sirva notified Amgen that some individuals affiliated with Amgen may have been impacted. Amgen promptly coordinated with its legal counsel and with Sirva to provide notifications regarding the incident to affected individuals and to regulators to the extent required by applicable law. Following that initial notification on April 10, 2024, Sirva provided Amgen with information on August 8, 2024 about additional impacted individuals. This notification is being made to you on the basis of that additional information from Sirva. Based on information Amgen has received from Sirva, we are required to provide notice pursuant to New Hampshire law to 3 New Hampshire residents. Per details from Sirva, the impacted files pertaining to these individuals include: . Amgen is in the process of providing notice to these individuals as required by New Hampshire law. No Amgen systems were impacted by this incident. A template copy of the notification letter sent to affected individuals is enclosed as Exhibit A. Please contact me if you have any further questions about this incident.classaction.org
T2
Amgen discloses data breach, says patient information was stolenhk.marketscreener.com
T2
Amgen has learned that one of our servicoag.ca.gov

Related Stories

KKR nears $4.3B deal to acquire medical device maker Integer Holdings
31 Jul · 7:23 PM
NXP in talks to buy chip designer Ambarella, FT reports
31 Jul · 5:09 PM
Love, Bonito warns customers of scam risks after data breach
31 Jul · 3:10 AM
Chime cuts 10% of workforce, about 140 jobs, citing AI efficiencies
31 Jul · 2:36 PM
Amazon sued over seafood sustainability claims
31 Jul · 7:06 PM