Amgen’s Data Breach Is a Warning for Healthcare: Cybersecurity, AI Governance, and AI-Driven Threats (AI-DT)
- Merlin @GovernanceCentral

- Aug 5
- 4 min read
Healthcare organizations are facing a difficult reality: as they become more digital, they also become more vulnerable.
That reality came into focus when Amgen disclosed a cybersecurity incident last week (Fri July 31 via an 8-K) involving unauthorized access to cloud environments operated by third-party providers. (The cloud provider was not disclosed. But in the past, Amgen used AWS HealthOmics and Veeva Systems [Veeva Clinical Platform].) According to the company, attackers stole proprietary corporate data and patient protected health information (PHI).
While Amgen says it has not identified any impact on its products, manufacturing operations, financial reporting systems, or ability to serve patients, the incident highlights broader concerns about cybersecurity, AI governance, and the growing risk of AI-driven threats (AI-DT). [insurancejournal.com], [money.usnews.com], [bleepingcomputer.com]
What Happened at Amgen?
Amgen reported that it detected unauthorized activity within cloud environments hosted by external service providers. The company later determined that some of its data had been exfiltrated, including patient health information and proprietary business data. The company has engaged independent forensic experts and continues to investigate the full scope of the breach. [insurancejournal.com], [money.usnews.com], [bleepingcomputer.com]
Importantly, Amgen has not disclosed:
How the attackers gained access
Which cloud providers were affected
How many individuals were impacted
Whether intellectual property was stolen
Whether a known threat actor was responsible for the attack [money.usnews.com], [bleepingcomputer.com]
What Does Unauthorized Access Mean?
One of the most common questions following a data breach is: How did the hackers get in?
The term “unauthorized access” simply means someone gained access to systems or data without permission. Contrary to popular belief, modern cyberattacks often do not involve attackers breaking through highly sophisticated security barriers. In many cases, cybercriminals gain access by:
Stealing employee credentials
Sending phishing emails that trick users into revealing passwords
Compromising third-party vendor accounts
Exploiting software vulnerabilities
Taking advantage of cloud security misconfigurations
In other words, many breaches occur because attackers successfully impersonate trusted users rather than force their way into systems. At this time, Amgen has not publicly disclosed how unauthorized access occurred. [money.usnews.com], [bleepingcomputer.com]
Why Healthcare Organizations Are Prime Targets
Healthcare organizations store some of the world’s most valuable data:
Patient medical records
Clinical trial data
Drug research
Intellectual property
Sensitive operational information
Unlike a stolen credit card number, medical records cannot be replaced. Research data can represent years of scientific development and billions of dollars in investment.
For cybercriminals, that makes healthcare a high-value target.
Amgen Is Not Alone
The Amgen breach is part of a growing pattern affecting healthcare and pharmaceutical companies worldwide.
Novo Nordisk
Earlier this year, Novo Nordisk disclosed that attackers gained unauthorized access to internal IT systems and copied certain non-public information, including data related to clinical trial participants. The company said the affected patient information was pseudonymized and not directly linked to patient identities. [cybersecur...tynews.com], [theregister.com]
Stryker
Medical technology company Stryker experienced a cybersecurity incident that disrupted operations, demonstrating how cyberattacks can affect critical healthcare infrastructure. [insurancejournal.com]
Intuitive Surgical
Intuitive Surgical, maker of robotic surgery systems, also disclosed a cybersecurity incident, adding to the growing list of healthcare technology companies reporting cyber intrusions. [insurancejournal.com]
Change Healthcare
The Change Healthcare cyberattack became one of the most disruptive healthcare incidents in recent years, affecting healthcare providers, pharmacies, insurers, and patients across the United States.
Taken together, these incidents demonstrate that healthcare cybersecurity is no longer a niche IT issue. It is a business risk, a patient safety concern, and a trust issue.
Why AI Governance Matters
Although there is no evidence that artificial intelligence was used in the Amgen attack, the incident arrives as healthcare organizations rapidly adopt AI technologies.
AI is increasingly used to:
Analyze clinical data
Accelerate drug discovery
Improve operational efficiency
Support research and development
Enhance decision-making
As AI systems gain access to larger amounts of sensitive information, strong governance becomes essential.
AI governance refers to the policies, oversight mechanisms, and accountability structures that help ensure AI systems are used safely and responsibly. Healthcare leaders should be asking:
Who has access to sensitive data?
What information can AI systems use?
How is patient privacy protected?
How are third-party AI providers evaluated?
Who is accountable for AI-related risks?
Notably, reporting on the Amgen incident indicates the company has established an AI Government Council to oversee its adoption of third-party AI services, reflecting growing recognition that AI oversight is becoming a strategic business priority. [fiercepharma.com]
The Growing Challenge of AI-Driven Threats (AI-DT)
At the same time healthcare organizations are adopting AI, cybercriminals are beginning to use the technology as well.
AI-driven threats (AI-DT) refer to cyberattacks that leverage artificial intelligence to increase the speed, scale, and effectiveness of malicious activities. Examples include:
AI-generated phishing emails that are more convincing than traditional scams
Automated identification of security vulnerabilities
AI-assisted social engineering campaigns
Faster analysis of stolen data
Automated reconnaissance of target organizations
These capabilities allow attackers to operate more efficiently and potentially target more organizations simultaneously.
While there is no public evidence that AI-DT played a role in the Amgen incident, security experts increasingly view AI-driven threats as a major emerging risk for healthcare organizations because of the sensitive data they manage.
The Bigger Picture
The Amgen breach should not be viewed as an isolated cybersecurity event.
It reflects three major trends reshaping healthcare:
Cybersecurity Risk
Healthcare organizations are managing expanding digital ecosystems that include cloud providers, vendors, contractors, and business partners. Each connection creates potential exposure.
AI Governance
As organizations adopt AI tools, they need clear oversight to ensure patient data is protected and used responsibly.
AI-Driven Threats (AI-DT)
Attackers are increasingly using artificial intelligence to make cyberattacks faster, more scalable, and more difficult to detect.
Key Takeaway
The lesson from Amgen is simple: protecting patient data requires more than deploying security technology.
Healthcare organizations must strengthen cybersecurity programs, establish robust AI governance frameworks, and prepare for a future in which AI-driven threats (AI-DR) become increasingly common.
In the age of cloud computing and artificial intelligence, trust is built not only through medical innovation but through the ability to protect the data that patients and partners entrust to healthcare organizations every day
See Cyber Crisis Pressure Test (TM) in boardroom simulations.





Comments