CYBERSECURITYTRACKER
TRACKING3,967 stories737 vuln stories
Permanent story citation

Amgen Breach: What Our January Warning Tells Defenders

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 3760

As cited

Citation snapshot as of .

threat intel

Amgen Breach: What Our January Warning Tells Defenders

In January 2026, Silent Push identified infrastructure staged by the ShinyHunters group targeting over 100 organizations including Amgen, giving defenders seven months of advance warning before the July breach disclosure. Amgen confirmed that attackers compromised patient data and proprietary information stored in third-party vendor cloud environments through social engineering attacks on single sign-on accounts. The attack exploited vendor helpdesk processes to reset multi-factor authentication, bypassing technical controls and granting access to connected cloud platforms.

Why it matters: Defenders at large enterprises with significant cloud footprints, particularly in healthcare and pharmaceuticals, need to monitor for ShinyHunters infrastructure indicators, implement vendor risk controls over third-party SSO accounts, and harden helpdesk verification processes against social engineering before credential resets are executed.

Source published
First seen by Cybersecurity Tracker

Source attribution