Treasury
3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp 3-MO 3.83% +1bp 6-MO 3.98% unch 1-YR 4.08% +4bp 2-YR 4.28% +5bp 3-YR 4.34% +4bp 5-YR 4.45% +7bp 7-YR 4.59% +7bp 10-YR 4.75% +7bp 20-YR 5.28% +6bp 30-YR 5.27% +6bp
US Treasury par yield curve · Jul 31 · Source: U.S. Treasury
Friday, July 31, 2026
U.S. Edition
Amgen

Amgen has told the SEC that patient health information was taken from cloud environments run by somebody else

Several dozen translucent golden softgel capsules scattered across a plain white surface and lit from above, with no packaging, no lettering and nobody in the frame.
Photo: Supplements On Demand / Pexels

Amgen has disclosed a data breach.

The drugmaker filed a Form 8-K on Friday afternoon under Item 1.05, the heading the form reserves for material cybersecurity incidents, and the disclosure is not about a risk. It is about data that has already gone. Amgen says it identified unauthorized activity in July involving data stored in cloud environments hosted by third-party cloud service providers, and that on detecting it the company activated its cybersecurity response plan, implemented containment measures and engaged independent cybersecurity forensic experts.

What was taken is the part that matters. The company says it has since learned that some of its data, including proprietary data, patient protected health information and other information, has been exfiltrated from those environments. The investigation is still open, and Amgen says it continues to assess whether patient information, confidential business information, intellectual property, research and development material or anything else may have been accessed, acquired or exfiltrated.

Two kinds of material

The filing draws a line that is easy to read straight past.

On 29 July, in connection with evaluating the volume of the files that appear to have been affected and the possibility that the types of information in them could be sensitive, the company determined that the incident is material. A paragraph later it says it believes the incident is not reasonably likely to have a material impact on its financial condition or results of operations. Both can be true. Item 1.05 asks whether an incident is material, which is a question about the event and the trigger for filing at all; the second sentence answers a different question, about the money, and it is the one that would move if the notification bill arrives.

Amgen reports no identified impact to its products, its manufacturing operations, its financial reporting systems, or its ability to meet patient needs.

What the filing does not say

It names nobody. There is no threat actor in the document, no cloud provider, no count of affected individuals and no dollar figure, and the company gives no date for the unauthorized activity beyond the month.

The next step in the document is a notification list. Amgen says it continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients. It has undertaken to amend the filing as information required by Item 1.05(a) is determined or becomes available, which is the mechanism by which the missing numbers, if they come, will come. The report is signed by Jonathan P. Graham, executive vice president, general counsel and secretary.

The document: Amgen Inc., Form 8-K, Item 1.05 Material Cybersecurity Incidents, accession number 0000318154-26-000119, accepted by EDGAR on 31 July 2026 at 16:03:44 Eastern, filed as of 31 July 2026, conformed period of report 29 July 2026, Commission file number 001-37702. The filing document amgn-20260729.htm was downloaded and its full text read here; no fetch-tool summary was relied on, and the acceptance timestamp, filing date, period of report and item code were each matched against the EDGAR index header file rather than inferred from the filing list. Every statement attributed to the company below appears in the Item 1.05 text: identification in July 2026 of unauthorized activity involving data stored in cloud environments hosted by third-party cloud service providers; activation of the cybersecurity response plan, implementation of containment measures and engagement of independent cybersecurity forensic experts; the subsequent learning that some data, including proprietary data, patient protected health information and other information, has been exfiltrated from these cloud environments; no identified impact to products, manufacturing operations, financial reporting systems or the ability to meet patient needs; the continuing assessment of whether patient, confidential business information, intellectual property, research and development or other information may have been accessed, acquired or exfiltrated; the 29 July 2026 determination of materiality made in connection with evaluating the volume of files that appear to have been impacted and the potential sensitivity of the types of information in them; the belief, as of the date of the report, that the incident is not reasonably likely to have a material impact on financial condition or results of operations; the statement that the company continues to evaluate applicable regulatory and legal notification requirements and will make all required notifications based on its findings, including to impacted patients; and the undertaking to amend the report as information required by Item 1.05(a) is determined or becomes available. The report is signed by Jonathan P. Graham, Executive Vice President and General Counsel and Secretary, dated 31 July 2026. The filing names no threat actor, no cloud provider, no number of affected individuals and no dollar figure, and none is asserted here..