Amgen says patient health and research data stolen from third-party cloud systems
Biotechnology company Amgen disclosed that attackers stole patient and corporate data from multiple cloud systems run by third-party providers, rather than from its own servers. In a securities filing, Amgen said it detected the intrusion in July, confirmed data was exfiltrated, and determined the incident material based on the volume and sensitivity of affected files. Confirmed stolen data includes proprietary company information and patient protected health information, and the company is still assessing whether intellectual property, research and development data, and further patient records were taken. Operations, product supply, and financial systems were not disrupted. Amgen has not named a provider, entry point, or responsible party.
- Check
- Organizations relying on third-party cloud providers should confirm what sensitive data those providers hold, how it is protected, and whether breach notification and monitoring obligations are covered in contracts.
- Affected
- Amgen patients and partners whose protected health information and proprietary data sat in third-party cloud environments; intellectual property and research data may also be affected, deepening the impact beyond ordinary personal information.
- Fix
- Minimize and segment sensitive data held by vendors, require strong access controls and logging on third-party cloud environments, monitor for bulk exfiltration, and prepare for extortion and phishing after healthcare breaches.