Amgen has confirmed that patient health data and proprietary information were stolen from third-party cloud systems, becoming the latest name in a growing list of healthcare-adjacent supply-chain breaches. For UK healthcare and pharma IT buyers relying on cloud security solutions, the incident is a prompt to check exactly who controls their data in multi-tenant environments.
View the data behind this chart
| UK healthcare orgs… | Breaches via unsecured… | Third-party attacks… | |
|---|---|---|---|
| Share affected | %67 | %48 | %35 |
What Amgen has disclosed so far
Amgen, the California biotech behind treatments for cancer, cardiovascular disease and rare illnesses, told the US Securities and Exchange Commission it detected unauthorised activity across multiple third-party cloud systems in July 2026. The company activated its cybersecurity response plan, brought in independent forensic investigators, and confirmed in its Form 8-K filing that attackers exfiltrated "proprietary data, patient protected health information, and other information" from those cloud environments.
Amgen determined the breach was material on 29 July 2026 after reviewing the volume of potentially affected files and the sensitivity of the data involved, though it currently believes the incident is unlikely to materially affect its finances. The company has not named the cloud providers involved, disclosed how the environments were breached, confirmed how many people are affected, or linked the attack to a known threat group. BleepingComputer has asked Amgen whether a vishing attack against an employee's single sign-on account was involved and whether ShinyHunters has made contact — Amgen had not responded at the time of reporting.
A pattern UK buyers should recognise
This is not an isolated cloud misconfiguration story. Health-ISAC has already warned that ShinyHunters is running supply-chain and identity-based campaigns against healthcare SaaS and storage platforms, frequently via OAuth token abuse and SSO compromise, and has urged phishing-resistant MFA, tighter helpdesk reset procedures and rapid revocation of suspicious sessions. SecurityScorecard data cited by Computer Weekly found healthcare among the most victimised sectors for third-party attacks, with 35% of observed incidents hitting health specialists specifically — evidence that attackers see vendor and cloud relationships as the easiest route into sensitive medical data.
The NHS has already lived this scenario
UK healthcare buyers do not need to imagine the fallout — it has already happened at scale. The June 2024 cyberattack on pathology provider Synnovis disrupted several London NHS trusts, forced ambulance diversions, cancelled operations at Guy's and St Thomas' and King's College Hospital, and significantly disrupted blood transfusions and South East London primary care. Board documents later showed Guy's and St Thomas' had known about weaknesses in its systems and supply chain for years, with governance still questioning data-security risk as late as January 2024. Advanced Computer Software Group separately faced a potential £6.09m fine after LockBit attackers used legitimate credentials on a third-party account without MFA to move laterally and steal data from nearly 83,000 people during an incident that crippled NHS 111 services. Capita's 2023 breach showed the same dynamic hitting councils, the NHS and defence simultaneously through a single supplier.

Why multi-tenant cloud and data residency now matter more
A VMware-linked Computer Weekly study found many NHS and social care bodies already run workloads on major public clouds such as AWS, Google Cloud and Azure, yet data held by such providers can still fall under external jurisdictional control in some circumstances — a live concern given 59% of respondents said they trust the NHS to safeguard personal data, leaving a substantial minority uneasy. The Register's July 2026 analysis of Britain's cloud exposure described UK cloud dependence as a "billion-pound risk," reinforcing that residency, jurisdiction and third-party access arrangements need active scrutiny rather than one-off sign-off. Any organisation handling patient or R&D data through data loss prevention strategies should treat cloud tenancy design as a governance decision, not just a procurement one.
- •Confirm which jurisdiction(s) hold your patient and IP data, and under what legal access rules
- •Map every third-party SaaS and cloud integration with access to clinical or research systems
- •Verify MFA and session controls exist on all admin and helpdesk-facing accounts, including vendor-managed ones
What UK healthcare and pharma buyers should audit now
NCSC guidance on managed service providers is explicit: MSPs administering cloud services should hold only the minimum access required, use MFA on admin interfaces, operate from privileged access workstations, and be measured against the same 14 cloud security principles as a direct cloud provider. That standard should extend to every SaaS vendor touching clinical, research or commercial data. Buyers reviewing existing contracts should run this through formal IT risk assessment services rather than relying on vendor assurances alone, and pair it with zero trust architecture to limit blast radius if a single account is compromised. Organisations in healthcare IT solutions should also confirm incident response plans cover third-party notification obligations, and that managed detection & response coverage extends into cloud and SaaS telemetry, not just the internal network.
- 01BleepingComputer — Amgen says cloud data breach exposed patient health, proprietary info · 31 July 2026
- 02Computer Weekly — 75% of third-party breaches target software/IT supply chains · 1 January 2026
- 03Computer Weekly — Two-thirds of UK healthcare organisations breached last year · 1 January 2019
- 04TechRadar — London NHS hospitals divert ambulances and cancel operations amid cyberattack · 1 June 2024
- 05TechRadar — London hospital vulnerabilities were known years before cyberattack · 1 June 2024
- 06Computer Weekly — Advanced faces fine over LockBit attack that crippled NHS 111 · 1 January 2026
- 07NCSC — Using MSPs to administer your cloud services · 1 January 2025
- 08BleepingComputer — Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare · 1 July 2026
- 09Computer Weekly — UK public increasingly concerned over NHS data sovereignty · 1 January 2026
- 10The Register — Britain's cloud habit has become a billion-pound risk · 9 July 2026
