The real exposure is where the data sat, not just inside Amgen. Once patient and corporate records live in third-party cloud systems, one compromise can spill sensitive information from more than one connected repository at once.
Amgen says attackers stole corporate data and patient information from multiple cloud systems run by outside service providers. That puts patient health records and proprietary information outside the company perimeter, and it makes the supplier relationship part of the breach surface.
For healthcare and life sciences firms that store regulated data with cloud vendors, the trust boundary is broader than the corporate network. A breach can reach across several providers and leave data exposed even when the company itself is not the only target.
Biotech giant Amgen says patient data stolen from third-party cloud systems
The biotech giant Amgen informed regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems.
Amgen says cloud data breach exposed patient health, proprietary info
Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.