PrivacySignal
Breach

Biotech giant Amgen says patient data stolen from third-party cloud systems

The Record · · International · Data Breaches

Amgen has disclosed to regulators that patient information and proprietary company data were accessed through a breach affecting third-party cloud systems the company relied on. The incident adds to a growing pattern of healthcare and biotech firms suffering data losses through vendors rather than their own internal infrastructure.

Why this matters: Patient data at a biotech company is not just names and emails. It can include diagnoses, clinical trial participation, genetic information, and treatment histories — things people shared with a healthcare system, not a cloud vendor they never heard of. When the breach happens at a third party, accountability gets murky fast. Amgen made the choice to store sensitive data in those systems. That choice carries responsibility. The fact that someone else's infrastructure failed does not change whose patients were exposed.

Who should care: Cybersecurity · Privacy officers · Administrators · Healthcare professionals · Compliance · Lawyers

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
Nextgov/FCW · · US Federal

Lawmakers propose giving 2015 OPM breach victims identity protection for life

Legislators are proposing permanent identity protection services for the roughly 22 million people whose personal data was stolen in the 2015 Office of Personnel Management breaches, linked to Chinese state-backed hackers. Current federal coverage for those victims is set to expire on September 30.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

KR: Seoul lawmaker criticizes 5,000-won compensation for 4.62 million-person data breach

Seoul Facilities Corporation is facing political backlash over its proposed response to a data breach affecting approximately 4.62 million people. The company plans to offer each affected person roughly 5,000 won — about $3.50 USD — as compensation, a figure a Seoul city council member has publicly criticized as inadequate.

Who should care: Cybersecurity · Privacy officers · Administrators · General readers · Policy

#breach#privacy Read original →
Breach
DataBreaches.net · · International

UK: Details of 100,000 police staff leaked on the dark web after hack

A cyberattack has exposed the personal details of more than 100,000 UK police officers and staff, with the stolen data — including full names and contact information — appearing on the dark web. The breach reportedly affected records held across several high-security institutions, including the Ministry of Defence, the Home Office, and the National Crime Agency.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
DataBreaches.net · · International

A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside the NotVPN / SplitVPN Breach

They advertised and pinky swore “no logs.” But according to research by MysteriumVPN, they logged. Key takeaways from MysteriumVPN: A threat actor on the Altenen cybercrime forum is distributing a 17 GB SQL database they claim was stolen from SplitVPN (formerly NotVPN), a Russian VPN used to bypass internet blocks. The Mysterium research team obtained... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

Brinks Home Confirms Data Breach Following ShinyHunters Claim

Guru Baran reports: Brinks Home, one of North America’s largest residential security providers, has confirmed that hackers breached its IT systems after the notorious ShinyHunters extortion group claimed responsibility for stealing nearly five million records tied to the company’s Salesforce environment. The confirmation comes after the threat actors listed “BH Security, LLC (brinkshome.com)” on their... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →