Skip to main content
Scam Checker
Back to all scam alerts and blog posts

Amgen data breach: confirmed facts and patient next steps

By Published Updated Reviewed by Shubham Singla
  • scam alert
  • data breach
  • amgen

Updated 4 September 2026. This article now includes Amgen's official disclosure and patient guidance. It replaces our earlier uncertainty about confirmation and consolidates the duplicate next-day article. The original publication date is retained; it is not the date the incident began.

Amgen has confirmed a cybersecurity incident involving data in third-party cloud environments. Its Form 8-K, signed on 31 July 2026, reports that data including patient protected health information was taken. Amgen also has an official cybersecurity-event page for patients.

Those public statements cannot establish whether a particular reader's information was involved. Use Amgen's own notice and support route to ask about your circumstances. A scam-checking result, familiar sender name or convincing message cannot settle that question.

What is confirmed, and what remains unknown?

Amgen's July filing describes unauthorized activity in third-party cloud environments, exfiltration including patient protected health information, and an ongoing investigation. It records 29 July as the date Amgen determined the incident was material.

The filing supplies no affected-person total or Australian cohort, and does not confirm theft of every information category under assessment. Those are limits of a dated source. Follow the company's current patient guidance; repeated headlines do not establish separate incidents or independently confirm a new figure.

Find the official patient support route

As checked on 4 September, Amgen's patient page says affected patients will receive a letter and are being offered 24 months of identity monitoring at no cost. It publishes a dedicated call centre for patients and healthcare professionals. Check the current contact details and support instructions on that page before responding to an unexpected message.

Keep any letter privately. If you have a question about receipt, eligibility or a notification's authenticity, ask through the independently obtained company contact route. This article cannot check the affected-person list or enrol you in the offered service. Do not post patient identifiers, medical records or an enrolment code in a public report, comment or scam-checking input.

Choose the next step for what actually happened

You have only read a headline or message. Pause any requested payment, sign-in or download. Open the official company site through a known address. You do not need to enter personal details into another site just to investigate a news story.

You received a notification. Verify its instructions through the company's official support route. Read which information the notice says was involved, rather than assuming all accounts or records were exposed. If support is offered, check the actual eligibility and enrolment process independently before sharing details.

You already gave information or money to a suspicious contact. Contact the relevant bank, card issuer or account provider promptly through its genuine app or known contact details. If you entered a password, change it through the real service and anywhere you reused it. Do not wait for a scanner result before securing an account. Our damage-control checklist separates common exposure types and next steps.

For US readers, the FTC's data-breach guidance at IdentityTheft.gov provides steps matched to the information exposed, credit monitoring/freezing guidance and a route for reporting actual identity theft. Outside the US, use the relevant services in your country; our official reporting directory can help locate them. A US company's disclosure does not make every country's reporting or credit rules interchangeable.

A fictional follow-up message to practise with

Imagine receiving: “Your Amgen compensation is ready. Pay a small processing fee today to release it.” This is an invented teaching example, not a reported Amgen campaign or evidence that a real payout exists.

The useful response is to pause the payment and verify independently. Do not infer authenticity from the company name, details the sender knows or a deadline. The FTC's phishing guidance explains how unexpected messages use familiar organisations and urgent requests to obtain information or money.

You can use our free message checker to examine warning signs after removing private details. It cannot authenticate an Amgen letter, determine whether your medical information was exposed or guarantee that a contact is safe. Official account and patient support take priority over a tool result.

Frequently asked questions

Was this an Australian breach?

The primary sources reviewed here do not identify an Australian affected group. The earlier article's generic Australian framing did not establish one. Check the company notice for your situation and choose local support based on where you are.

Does knowing my name prove a caller is genuine?

No. A name or other familiar detail does not authenticate the caller. End an unexpected call and use independently verified contact details to ask about it. Do not read out passwords or security codes to someone who contacted you unexpectedly.

Can Scam Checker tell me whether I am affected?

No. We do not have Amgen's affected-patient list. Ask through the official patient support route, and keep sensitive information out of public reports. This page explains public evidence and how to verify a contact; it is not an individual exposure check.

Sources and correction note

Sources were checked on 4 September 2026. The SEC filing is signed 31 July; the company patient page did not display an update date. The earlier version relied on headline summaries, lacked an official statement link and incorrectly labelled its first-detected date as AEST. Those claims have been replaced with the attributed chronology above. The duplicate 1 August coverage concerned the same described July incident and contained no distinct verified finding.

External sources and references