Amgen data breach (2026-07-31): what to do
- scam alert
- data breach
- amgen
- au
Developing story — first detected 2026-07-31 (AEST). This alert is based on early news reporting and will be updated as Amgen and investigators confirm details. Reported figures are claims, not verified facts, until the company or a regulator confirms them. This is general safety information, not legal or financial advice.
Multiple news outlets are reporting a possible data breach at Amgen. Early coverage of an incident is exactly when follow-up scams start — fake "breach notifications", bogus compensation offers and impersonation calls arrive while people are anxious and before official guidance lands. This page explains what has been reported so far, how to check what's real, and the steps worth taking right now. If a suspicious message about Amgen has already reached you, run it through our free scam checker before you act on it.
What's being reported
As of 2026-07-31, recent coverage includes:
- “Amgen discloses data breach, says patient information was stolen By Reuters”
- “Amgen discloses data breach involving patient health information”
- “Amgen discloses data breach, says patient information was stolen”
The scale, cause and even the existence of a confirmed breach can change quickly in the first hours. Treat numbers in headlines as provisional until Amgen or a regulator confirms them.
Has Amgen confirmed a breach?
At the time this alert was generated, we had not yet linked an official Amgen statement. Companies typically publish incident statements on their website, app or newsroom, and ASX-listed companies must disclose material incidents to the market. Under Australia's Notifiable Data Breaches scheme, organisations must notify affected individuals and the OAIC when a breach is likely to cause serious harm.
Never rely on an email, text or call to tell you whether you're affected. Type the company's web address yourself or use its official app.
The real danger right now: post-breach scams
After every widely reported Australian breach, criminals exploit the headlines — whether or not they hold any stolen data:
🚩 Fake compensation or refund offers. "You are eligible for a payout over the Amgen breach — claim here." No legitimate remediation works through a link-laden message.
🚩 Fake breach notifications asking you to "verify your identity", "secure your account" or "reset your password" through a supplied link. Real notifications name the official website and never ask for passwords, one-time codes or card details.
🚩 Impersonation calls quoting real personal details. If data really did leak, a caller knowing your name, date of birth or account history proves nothing. Hang up and call back on the number from the company's official website or your bill.
🚩 Bank-impersonation follow-ups. Scammers use breach anxiety to stage "your money is at risk, move it to a safe account" calls. No bank or government agency ever asks that.
Unsure about any message or caller? Use our free scam checker or the scam phone number checker first.
What to do now — 7 steps
- Don't click links in breach-related messages. Go directly to the company's website or app for statements.
- Verify any contact independently using a phone number from the official website, your bill or the back of your card — never one supplied in a message.
- Change your password for the affected service to a long, unique one, and anywhere you reused it. Turn on multi-factor authentication, starting with your email account.
- Watch bank and card statements and query unexpected transactions with your bank immediately.
- Consider a credit report check or ban with Equifax, Experian and illion — Moneysmart explains how.
- Get free expert help from IDCARE, Australia and New Zealand's national identity and cyber support service, on 1800 595 160.
- Report scam attempts to Scamwatch and cybercrime to ReportCyber. Already clicked or paid? Follow our damage-control checklist now.
Where to get official help (Australia)
- IDCARE (free identity & cyber support): 1800 595 160 · idcare.org
- Scamwatch (National Anti-Scam Centre): report a scam
- ReportCyber / ACSC: cyber.gov.au · 1300 CYBER1 (1300 292 371)
- OAIC (privacy regulator): your rights after a data breach
- Your bank: the number on the back of your card, at the first sign of unusual activity.
Frequently asked questions
How do I know if my Amgen data was exposed?
You likely can't yet. Companies confirm scope through official statements and direct notifications, which take time. Watch the official website and be suspicious of anyone who claims they can check for you.
Should I do anything before the breach is confirmed?
Yes — the low-cost steps above (unique password, MFA, statement checks) are worth doing regardless, and they blunt the scams that exploit the headlines either way.
Is a message about this breach legitimate?
Assume not until proven otherwise. Verify through the company's official website or phone line, and check the message with our free scanner — it flags breach-compensation lures, lookalike domains and known-reported scam contacts.