Amgen Breach: What Our January Warning Tells Defenders

industry, platform, threat

In January 2026, the Silent Push research team mapped a cluster of adversary infrastructure staged for takeover of single sign-on accounts across more than 100 large organizations. Amgen was one of the named targets, grouped with other pharmaceutical and biotech companies.

On July 31, Amgen filed a Form 8-K with the SEC confirming that attackers had stolen patient protected health information and proprietary data from cloud environments run by its third-party vendors.

Seven months passed between the January infrastructure findings and Amgen’s July disclosure. That is enough time for a targeted organization to block the infrastructure, watch the named accounts, and tighten identity controls before an attack lands. In Amgen’s case, the disclosure came at the end of it.

Who is ShinyHunters, and who do they target?

ShinyHunters is a data theft and extortion group that operates as part of Scattered LAPSUS$ Hunters, an alliance that also includes Scattered Spider and LAPSUS$. The group gets in through social engineering, moves through connected cloud platforms, and uses the stolen data to pressure its victims into paying. Its focus is identity and SaaS access, which is what makes a single compromised SSO account so valuable to it.

The targets are large enterprises with heavy cloud footprints, the kind of organizations that run day-to-day operations through platforms like Salesforce, Microsoft 365, and SharePoint. The infrastructure behind this campaign has pointed at more than 100 such organizations across several industries, and recent activity has concentrated on healthcare, medical technology, and pharmaceutical companies. Amgen sits squarely in that profile.

What Silent Push saw in January

The Silent Push platform maps adversary infrastructure by watching for the setup work that happens before an attack, the domains a group registers, the certificates and hosting it stands up, and the tooling it stages while preparing to move against a target. We turn that activity into Indicators of Future Attack® (IOFA), which give a security team a named threat and a timeframe to act on before anything reaches their environment. In January, that work identified the Scattered LAPSUS$ Hunters campaign while it was still being built, months before any of it was used against a target.

In Silent Push research, the average lead time between spotting this kind of infrastructure and an attack landing is 154 days. In Amgen’s case, the public timeline ran to about seven months.

How the attack chain works

Health-ISAC, the information-sharing group for the healthcare sector, published an advisory on July 24 describing the pattern in detail. The short version is that the attack runs on social engineering aimed at a vendor’s helpdesk. Someone calls posing as internal IT and persuades a representative to reset multi-factor authentication on a chosen employee’s account. The weak point is the human process that verifies who is calling, so the attacker never has to defeat a technical control. That reset hands over a single signed-in session, and that session reaches the cloud apps the account can open. From there the group pulls data out of connected platforms before alerting catches up.

Amgen’s disclosure places the unauthorized activity in cloud environments run by third-party service providers, and the company reported no impact to its products, manufacturing operations, or financial reporting systems. The exposed records sat with outside vendors contracted to store and process patient data on Amgen’s behalf, in infrastructure Amgen does not run or directly monitor. An organization can operate a mature security program across its own estate and still inherit the risk carried by every vendor that holds its regulated data.

What is preemptive cyber defense?

Preemptive cyber defense means finding adversary infrastructure while it is being built and acting on it before it gets used in an attack. The signal for that work is an Indicator of Future Attack® (IOFA), which names a threat while it is still being staged, early enough for a team to respond. An Indicator of Compromise (IOC) is the older, well-known kind of signal, the forensic evidence collected after a breach that helps with investigation once the loss has already happened.

Silent Push maps the infrastructure a threat group stages against its targets and delivers it as IOFAs. That gives teams time to block domains, monitor key accounts, and harden identity controls while the attack is still being set up.

What security teams can do now

The Health-ISAC advisory lists controls that are procedural more than technical. The first control to adopt is a no-same-call rule, which stops a helpdesk from resetting a password, resetting MFA, or enrolling a new device on the same call that requests it. The request goes into a ticket and gets a callback to a number already on file for the account. That single step breaks the part of the chain the group relies on most.

For higher-risk accounts such as administrators, security staff, and finance employees, the advisory recommends a second approval and an out-of-band identity check before any credential change. It also points to phishing-resistant MFA such as FIDO2 keys or passkeys, which cannot be talked out of a person over the phone.

The point of seeing it early

Amgen is one company, and the pattern is common across the sector. A strong internal security program can still carry the risk of a vendor it can vet but cannot watch in real time. Spotting the infrastructure in January gives a targeted team the chance to act months before the attack lands. That is what ‘neutralize before compromise’ means in practice. It is the chance to move on a threat while it is still being built, before it reaches a patient’s data.

This post is commentary on public reporting and regulatory frameworks. It is not legal or compliance advice.


Did Silent Push predict the Amgen breach?

Silent Push did not predict a specific breach. In January 2026 the Silent Push team mapped adversary infrastructure staged for SSO account takeover and named Amgen among more than 100 targeted organizations. Amgen disclosed a breach of patient data held by third-party vendors on July 31, 2026. Amgen has not confirmed the threat actor, and no group has publicly claimed the attack, so the connection is a strong pattern match that stops short of confirmed attribution.

What is an Indicator of Future Attack?

An Indicator of Future Attack (IOFA) is a signal that identifies adversary infrastructure while it is being staged, before it is used in an attack. It gives a security team a named threat and a timeframe to act on in advance. An Indicator of Compromise is the related but later signal, the forensic evidence collected after a breach has already happened.

How did attackers reach Amgen’s data without breaching Amgen?

According to a July 24 Health-ISAC advisory, the group uses voice social engineering to get a vendor helpdesk to reset multi-factor authentication on an employee account. That opens a signed-in SSO session that reaches connected cloud apps, and the attackers pull data from those apps. The compromised systems belonged to Amgen’s third-party vendors, which is why Amgen’s own operations were unaffected while patient data was still exposed.

What is preemptive cyber defense?

Preemptive cyber defense is the practice of finding and acting on adversary infrastructure while it is being built, before it is used in an attack. Silent Push maps the infrastructure a threat group stages against its targets and delivers it as Indicators of Future Attack, so teams can block domains, monitor accounts, and harden identity controls during the planning window.