As cited
Citation snapshot as of .
threat intel
Amgen Breach: What Our January Warning Tells Defenders
In January 2026, Silent Push identified infrastructure staged by the ShinyHunters group targeting over 100 organizations including Amgen, giving defenders seven months of advance warning before the July breach disclosure. Amgen confirmed that attackers compromised patient data and proprietary information stored in third-party vendor cloud environments through social engineering attacks on single sign-on accounts. The attack exploited vendor helpdesk processes to reset multi-factor authentication, bypassing technical controls and granting access to connected cloud platforms.
Why it matters: Defenders at large enterprises with significant cloud footprints, particularly in healthcare and pharmaceuticals, need to monitor for ShinyHunters infrastructure indicators, implement vendor risk controls over third-party SSO accounts, and harden helpdesk verification processes against social engineering before credential resets are executed.
- Source published
- First seen by Cybersecurity Tracker