Amgen data breach (2026): was your email exposed?

The biotech company Amgen disclosed that attackers took patient health information and proprietary data from cloud environments run by third-party providers, and told investors on July 29, 2026 that it considered the incident material. Check whether your email was caught up in it — and lock down your accounts before the data is misused.

See which breaches hold my email — free →
Breach date
2026
Publicly disclosed
July 2026
People affected
Not disclosed
Website
amgen.com
An email check won’t confirm this one

This incident is known from Amgen’s own notice and regulatory filings, not from a set of leaked records that anyone can search. The data was taken, but it hasn’t been published — so no breach-checking tool, ours included, can tell you whether you were in it. The letter is the answer: if one arrived, treat yourself as affected. A free check is still worth running for a different reason — it shows which other breaches already hold your email.

Amgen has not said how many people are affected; no figure has been filed publicly yet. Source: Amgen's securities filing of July 29, 2026 and reporting by Reuters, Bloomberg and security press.

What happened in the Amgen breach?

Amgen identified unauthorized activity in July 2026 in data held in cloud environments operated by outside providers, brought in forensic investigators, and on July 29 told regulators it had concluded the incident was material — a judgement it based on the volume of files involved and how sensitive their contents were. The company said the attackers took proprietary information along with patient protected health information.

Almost everything else is still open. Amgen has not named the third-party providers, has not described how the intrusion happened, and has not said how many people are affected. There is no published list of records, so nobody outside the investigation can check an individual name against it.

For patients this is the awkward middle stage of a breach: something is known to have been taken, but who was in the files has not been established yet. Notification letters, if they are required, come after that work finishes, and with health data the assessment can run for months. If you have been in an Amgen patient support or clinical programme, treat a future letter as plausible rather than suspicious — and treat any email or call claiming to be about this breach right now as very likely fake, because the company has not yet contacted individuals.

The practical move while the scope is unknown is the one that costs nothing and helps against any health-data exposure: watch for medical bills or insurance statements for care you did not receive, which is how health-data misuse usually surfaces first.

What data was exposed in the Amgen breach?

The Amgen breach exposed patient health information and proprietary company data. The more of these are tied to you, the more ways an attacker can impersonate you or break into your other accounts.

Patient health informationProprietary company data

How the leaked Amgen data can be used against you

Because the Amgen breach exposed patient health information and proprietary company data, exposed medical and insurance details enable medical identity theft — treatment or prescriptions billed in your name — and make health-themed scam calls far more convincing.

How to check if you were affected

For this one, the notification letter is the only confirmation there is — nothing about it is searchable yet. If you got a letter, use only the contact details printed on it, because scam waves follow every notification rollout. What you can check right now is the rest of your exposure: which known breaches already hold your email, and what leaked in them.

Check my email against known breaches — free →

What to do if your Amgen account was breached

These steps are prioritized for exactly the kind of data the Amgen breach exposed.

1
Turn on two-factor authentication

Add 2FA — ideally an authenticator app or a passkey rather than SMS — to your email, banking and other important accounts, so a stolen password alone can’t get in.

2
Check your medical bills and insurance statements

Health data misuse shows up as care you never received: a bill, an explanation-of-benefits letter, or a claim on your policy for a treatment that isn’t yours. Read those statements instead of filing them, and query anything unfamiliar with the provider and your insurer — medical identity theft is usually caught this way rather than by credit monitoring.

3
Monitor whether your data resurfaces

Leaked data is resold for years, so a one-time clean-up isn’t enough. Ongoing breach and dark-web monitoring tells you the moment your details reappear, so you can act before an account is misused.

Common questions

The Amgen breach, answered

Was I affected by the Amgen breach?

The notification letter is the only confirmation. Nothing from this incident has been published as a searchable set of records, so no breach-checking tool can answer it for you — including ours. If a letter reached you, treat yourself as affected and act on it; if none did, there is nothing to check yet.

Is the Amgen breach letter I received genuine?

Letters from a real notification rollout do arrive by post and can look alarming. Verify it the safe way: use only the phone number or web address printed on the letter itself, typed in by hand — never a link in an email or text about the breach. Notification waves are followed by scams that copy the wording of the real letter.

What data was involved in the Amgen breach?

Per the disclosure, the data included patient health information and proprietary company data. Affected people: not disclosed. Amgen has not said how many people are affected; no figure has been filed publicly yet.

What should I do after the Amgen breach?

Watch medical bills and insurance statements for care you never received, since that is how health-data misuse usually surfaces. Be sceptical of any call or email about this breach, especially one asking you to confirm details — the company contacts people by post first.

When did the Amgen breach happen?

The incident is dated July 2026 and became public in July 2026. Source: Amgen's securities filing of July 29, 2026 and reporting by Reuters, Bloomberg and security press.

Was your email in the Amgen breach?

Check free in about a minute — then we’ll help you remove your exposed data and keep it monitored.

Run my free breach check →