Amgen Inc. Data Breach Notice (Massachusetts Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Amgen Inc. notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on August 18, 2026, and the notice lists social security numbers and medical records among the information exposed.
The exposure of your Social Security number alongside medical records creates a lifelong risk that cannot be undone by a simple password change or credit freeze. With 354 Massachusetts residents named in this filing, the combination of these two data types gives identity thieves the exact pairing they need to open accounts, file fraudulent tax returns, or submit false medical claims that could damage both your finances and your health record for years.
Social Security Numbers Cannot Be Replaced
A Social Security number is permanent. Unlike a credit card or password, it cannot be reissued on request. Once it is in the hands of unknown parties, it remains a usable key for identity theft for the rest of your life. The Massachusetts filing lists Social Security numbers as exposed, which means anyone in the affected group now carries that permanent risk.
Medical records add another dimension. They often contain diagnoses, treatment histories, and other sensitive health details that can be used for insurance fraud, prescription scams, or blackmail. When paired with a Social Security number, this information becomes far more valuable to criminals than either piece alone. The filing confirms both categories were involved in the incident reported on August 18, 2026.
What the Numbers Actually Mean for You
354 people is a relatively contained number for a company the size of Amgen. The filing does not state whether the records belonged to clinical trial participants, employees, or patients in specific programs. What matters is that the exposed data includes the two categories that matter most for long-term fraud: Social Security numbers and medical records. No passwords were exposed.
This matters because medical identity theft is harder to detect than financial fraud. You may not learn for months or years that someone used your information to obtain care, rack up bills in your name, or file claims that corrupt your insurance history. A stolen Social Security number makes that theft easier to sustain.
The Only Reliable Way to Know If You Are Affected
Amgen is required to notify affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not included in this incident. However, letters can go to outdated addresses. Anyone who has moved since the incident should contact Amgen directly to confirm whether their records were involved. The filing does not provide an incident date, so the letter itself remains the clearest indicator available.
Why This Combination Stays Dangerous for Decades
Unlike credit card numbers that expire or can be canceled, a Social Security number tied to medical history creates persistent value on the black market. Criminals can use it to:
- File fraudulent tax returns before you do
- Open new lines of credit in your name
- Submit false medical claims that exhaust your insurance benefits
- Apply for government benefits using your identity
Medical records make these schemes more convincing. A forged claim that references actual past treatments is far harder for insurers to spot. This is why the pairing listed in the Massachusetts filing is treated as especially serious.
What You Can Still Control
While you cannot change your Social Security number, you retain several practical levers. Placing a freeze on your credit reports at the three major bureaus remains one of the strongest steps. It will not stop medical fraud, but it blocks many financial crimes that begin with a stolen SSN.
Monitoring Explanation of Benefits statements from every health insurer you use is essential. Look for claims you did not file or services you did not receive. Early detection is the only realistic defense once medical records are loose.
Consider requesting your full medical records from every provider you have used in the past several years. Having your own clean copy makes it easier to dispute fraudulent entries later. Annual credit reports from all three bureaus should become part of your routine, not just a one-time check.
Tax fraud is another realistic threat. File your taxes as early as possible each year. If someone tries to file using your Social Security number first, the IRS will reject their attempt and you will have a paper trail to resolve the issue faster.
The Gap Between Filing and Incident
The record reached the Massachusetts Office of Consumer Affairs on August 18, 2026. The filing does not disclose when the incident itself occurred. Without that date, it is impossible to judge how long the information may have been at risk or when Amgen first learned of the exposure. The only date we have is the filing date itself.
This lack of timeline is common in these notifications. It leaves affected individuals without clear guidance on when to watch for specific types of fraud. In practice, the safest assumption is that the data could have been exposed at any point before the filing and should be treated as compromised from now on.
The exposure of medical records alongside Social Security numbers for 354 people represents a serious but contained incident. The data cannot be recalled. Your defense now rests on vigilance, credit freezes, careful monitoring of insurance statements, and early tax filing. These steps cannot eliminate the risk, but they remain the most effective tools available when permanent identifiers are involved.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Amgen Inc..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
- Read your next explanation of benefits. Medical identity theft shows up as treatment you did not receive, billed to your policy and written into your medical record. Your insurer can flag the policy, and you can request an accounting of disclosures from the provider named here.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
el-group Listed by Inc Ransom Ransomware Group
el-group was listed on the Inc Ransom ransomware leak site. The group claims to have stolen internal…
Victory Personal Care, Inc Listed by Nightspire Ransomware Group
Victory Personal Care, Inc was listed on the Nightspire ransomware leak site. The group claims to ha…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…