A Major Drugmaker Just Got Breached Through Its Cloud Vendors. Your Business Has the Same Vendor Risk.

Warning icon over a cloud storage graphic representing a cloud security breach

Amgen, one of the largest pharmaceutical companies in the world, disclosed on July 31, 2026, that hackers had stolen company data and patient health information. Not from Amgen’s own systems. From cloud storage run by outside vendors Amgen trusted with that data. It’s a textbook case of vendor risk, and it’s a lot closer to your business than a headline about a drugmaker might suggest. The company confirmed the breach in a filing with the SEC, and outlets including BleepingComputer reported the same details independently.

Amgen first spotted the unauthorized activity in July, activated its incident response plan, and brought in outside forensic investigators. By July 29, the company had determined the incident was serious enough to be legally material. Two days later it went public. The investigation into exactly what was taken is still ongoing.

Here’s the detail that should catch your attention even if pharmaceutical data means nothing to you: the breach didn’t happen because Amgen’s own security failed. It happened because of vendor risk, exposure created by outside providers Amgen trusted with its data. That’s a pattern showing up across industries this year, not just healthcare, and it applies just as much to a five-person consulting shop as it does to a company the size of Amgen.

Why Vendor Risk Is Part of Your Security, Whether You Think of It That Way or Not

Every tool connected to your business, cloud storage, your CRM, your payment processor, your email marketing platform, has access to some slice of your data or your customers’ data. Each one of those connections is a form of vendor risk. If one of those vendors gets breached, your business absorbs the fallout. Notification obligations. Reputational damage. In some cases, legal exposure. All of that even though the actual failure wasn’t technically yours.

This is exactly the kind of gap we see when we’re brought in after something’s already gone wrong. A business owner assumes their data is only as exposed as their own laptop and email account, then finds out a scheduling app they signed up for two years ago and forgot about still has access to client contact details. Nobody set out to create that risk. It just accumulates quietly, one integration at a time, and it’s the same slow buildup of vendor risk that caught Amgen off guard.

Three Things Worth Doing This Week to Cut Your Vendor Risk

First, make a simple list of every third-party service that stores or touches customer data on your behalf. Most business owners are surprised how long that list gets once they actually sit down and write it out.

Second, check whether those vendors publish security certifications like SOC 2 or ISO 27001, or at least a clear, specific security policy. If a vendor can’t point you to anything concrete when you ask, that’s worth noting, and it’s a direct signal of how much vendor risk you’re carrying through them.

Third, review who on your team actually has access to what. Breaches often spread further than they need to simply because access wasn’t limited to the people who needed it in the first place.

If working through that list feels like more than you want to take on solo, this is the kind of thing our cybersecurity services cover directly, walking through your actual vendor list and closing the gaps that tend to get missed.

You Don’t Need an Enterprise Security Budget to Manage Vendor Risk Well

Least-privilege access, giving people and tools only the access they actually need, doesn’t cost anything. It’s a settings change, not a purchase order. Same with reviewing your vendor list and switching off integrations you stopped using a year ago but never actually disconnected.

These are the unglamorous habits that do the real work of reducing vendor risk, and they’re well within reach for a business running on a tight budget. If you want a second set of eyes on your setup before deciding what needs attention, our personalized tech consultations are built for exactly that kind of walkthrough.

Related Reading

If this has you thinking about how exposed your own accounts and logins might be, our piece on the Homeland Security network breach covers a related angle: how the systems nobody’s watching closely are usually the ones that get hit first. And if AI tools are part of your stack, our recent article on Anthropic’s record valuation touches on why AI vendors are pushing deeper integrations into the software you already use, which raises some of the same vendor-trust questions.

Vendor risk is only as small as your weakest connected vendor makes it. Spend an hour this week auditing who actually has access to your data. It’s the highest-leverage security work you can do without spending a dollar.


Sources: Amgen SEC filing via DataBreaches.NetBleepingComputerStreetInsider

Leave a Reply

Your email address will not be published. Required fields are marked *