Did Amgen Inc have a data breach?
Answer
Yes. Amgen Inc reported a data breach to the Indiana Attorney General on August 17, 2026.
View the official filingWhat the filing says
- Reported to
- Indiana Attorney General
- Filing date
- August 17, 2026
- Breach date
- July 1, 2026
- People affected
- Not stated in the filing
Information involved
- Full Name
- Date of Birth
- Social Security Number
- Clinical Trial Participation Records
- Medical History and Treatment Information
- Health Insurance ID Number
- Mailing Address
- Email Address
In plain terms
Amgen Inc is one of the world's leading independent biotechnology and pharmaceutical companies, dedicated to discovering, developing, manufacturing, and delivering innovative human therapeutics to patients suffering from serious illnesses. Operating at the cutting edge of life sciences, Amgen routinely processes and maintains vast repositories of sensitive information. This includes not only proprietary clinical trial data and research records, but also extensive personal data concerning clinical trial participants, employees, healthcare professionals, and patients who utilize their specialized therapies. Because of its pivotal role in the global healthcare and pharmaceutical ecosystem, the organization is entrusted with highly confidential medical, genetic, and personal identifiers that demand the highest levels of digital and physical security.
In 2026, Amgen Inc reported a significant data security incident to the Indiana Attorney General, drawing the immediate attention of regulatory bodies, cybersecurity experts, and legal advocates. While the exact technical vectors of the breach continue to be scrutinized, security incidents affecting major biotechnology and pharmaceutical entities typically involve sophisticated cyberattacks, unauthorized intrusions into corporate or clinical databases, ransomware deployments, or vulnerabilities within third-party vendor supply chains. Because pharmaceutical companies are prime targets for malicious actors seeking intellectual property, valuable patient demographics, and corporate espionage assets, an enterprise-wide network compromise can expose sensitive internal systems and compromise the confidentiality of stored data.
Preliminary indications suggest that the breach compromised a diverse array of sensitive personal and health-related information. Depending on the precise scope of the files accessed, the compromised data likely includes full names, dates of birth, Social Security numbers, contact information, and in many instances, specialized medical history, clinical trial participation details, health insurance information, and prescription records. The exposure of this specific data cocktail creates severe, multi-faceted risks for affected individuals. Medical identity theft can lead to fraudulent insurance claims, compromised medical histories, and dangerous discrepancies in future healthcare treatment. Concurrently, the exposure of core personal identifiers like Social Security numbers and dates of birth lays the groundwork for pervasive financial identity theft, unauthorized credit openings, tax fraud, and sophisticated phishing schemes.
As a major corporate entity operating across multiple jurisdictions and handling protected health and personal information, Amgen Inc was bound by stringent legal obligations to safeguard this sensitive data. Under federal and state legal frameworks—including the Health Insurance Portability and Accountability Act (HIPAA) where applicable, state consumer protection statutes, and common law duties of care—the company had an affirmative legal duty to implement robust administrative, technical, and physical safeguards. These regulations mandate continuous security monitoring, encryption of data at rest and in transit, strict access controls, and regular vulnerability assessments. The occurrence of a data breach of this magnitude strongly suggests potential systemic failures or lapses in maintaining these mandated security protocols.
Receiving an official data notification letter from Amgen Inc serves as formal confirmation that your confidential information was compromised due to inadequate security measures. Legally, the receipt of this letter establishes the foundational standing required to participate in class action litigation against the company. Crucially, affected individuals do not need to demonstrate that they have already suffered actual financial loss or identity theft to pursue legal recourse; the compromise of private data and the resultant imminent risk of harm are sufficient under the law. Our class action law firm is actively investigating this data breach on a contingency fee basis, meaning there are never any out-of-pocket costs or upfront legal fees, and we only collect compensation if we successfully recover damages on your behalf.
Commonly recommended next steps
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Check for medical identity theft
Review the Explanation of Benefits statements from your health insurer for services or claims you never received, which can signal misuse of your medical identity.
Secure your online accounts
Change the password on any account that reused an exposed password and turn on two-factor authentication wherever it's offered.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Look up another company
Other breaches reported in Indiana
- Teamsters Local 17Yes — reportedIndiana
- BankYes — reportedIndiana
- PeoplesBankYes — reportedIndiana · October 8, 2026
- McKenzie Creative BrandsYes — reportedIndiana · September 30, 2026
- MEBS Global ReachYes — reportedIndiana · September 30, 2026
- Midvale Indemnity and American Family Connect Insurance CompanyYes — reportedIndiana · September 30, 2026
- American Motorcyclist AssociationYes — reportedIndiana · September 30, 2026
- Nishiyamato AcademyYes — reportedIndiana · September 30, 2026
- Deer Management Co. LLC dba Bessemer Venture PartnersYes — reportedIndiana · September 30, 2026
- 9World Acceptance CorporationYes — reportedIndiana · September 30, 2026
DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Amgen Inc.