Amgen Patient PHI Stolen via Vendor Cloud: HIPAA and SEC Clocks Both Running

August 2, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: techtimes.com

Threat Risk: High
Victim: Pharmaceutical and Healthcare organizations
Incident: Data exfiltration of patient PHI and proprietary data via compromised vendor cloud environments.
Impact: Significant regulatory risk under HIPAA and SEC guidelines due to the exposure of sensitive health information.
Attacker: ShinyHunters (in alliance with Scattered Spider and LAPSUS$)
Analysis: The breach highlights a systemic vulnerability in the supply chain where attackers bypass technical controls via social engineering. By targeting vendor helpdesks to reset MFA, actors gained full SSO access to sensitive cloud repositories. This demonstrates a strategic pivot from targeting primary organizations to exploiting trusted service providers.
Recommendations: Implement strict identity verification protocols for MFA resets at the helpdesk level.; Enforce hardware-based MFA, such as FIDO2, to mitigate vishing and session hijacking.; Conduct comprehensive security audits and continuous monitoring of third-party vendor identity controls.
Source: TechTimes

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *