The real exposure is where the data sat, not just inside Amgen. Once patient and corporate records live in third-party cloud systems, one compromise can spill sensitive information from more than one connected repository at once.
Amgen says attackers stole corporate data and patient information from multiple cloud systems run by outside service providers. That puts patient health records and proprietary information outside the company perimeter, and it makes the supplier relationship part of the breach surface.
For healthcare and life sciences firms that store regulated data with cloud vendors, the trust boundary is broader than the corporate network. A breach can reach across several providers and leave data exposed even when the company itself is not the only target.