Amgen Inc. Data Breach Notice (Vermont Attorney General)
If you were named in this filing, here’s what the filing says was exposed, and what to do about it.
Amgen Inc. notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on August 17, 2026, and the notice lists social security numbers, health records among the information exposed.
The filing from the Vermont Attorney General establishes that Amgen Inc. exposed the Social Security numbers and health records of 24 people. If you received a notification from Amgen, this means those two categories of information tied to you are now outside the company’s control.
What those two records actually enable
A Social Security number combined with health records creates a high-value package for identity theft and medical fraud. Thieves can use your SSN to open accounts, file fraudulent tax returns, or apply for government benefits in your name. The health records add another layer: they can support false insurance claims, prescription fraud, or even blackmail attempts based on sensitive medical details.
Unlike a credit card or password, neither of these can be cancelled or replaced at will. Your SSN is permanent. Your medical history is permanent. Once they are loose, the risk does not expire.
No passwords were exposed in this incident. That is genuinely good news. You do not need to change any Amgen-related password, and there is no evidence here of credential theft.
The scale and what the filing does not say
Only 24 Vermont residents are named in this specific filing. The record does not disclose when the incident occurred, how the information was accessed, or whether a third party was involved. Those details remain unknown to the public.
The organisation is required to notify affected individuals directly, usually by post. If you have not received a letter from Amgen, it is likely your information was not included. However, if you have moved since the time of the incident, letters sent to your previous address may not have reached you. In that case, contact Amgen directly to confirm whether you were affected.
Why health records and SSNs together matter long-term
Health records can reveal diagnoses, treatments, medications, and other personal details that retain value to criminals for years. When paired with a Social Security number, the combination makes it easier to impersonate you convincingly across financial, insurance, and government systems.
Because these identifiers cannot be reissued like a compromised credit card, the exposure creates a lifelong risk that you must manage rather than eliminate. The filing lists only these two categories for this incident. No other information types are named.
What remains under your control
You cannot change what has already happened, but you can reduce what criminals can do with the exposed data. Monitoring and early detection are the most practical tools available.
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name without your explicit permission.
- Review every Explanation of Benefits statement from your health insurance providers. Look for claims you did not make or services you did not receive.
- Request your free annual credit reports and check them carefully for unfamiliar accounts or inquiries.
- File your taxes early each year so that any fraudulent return filed with your SSN is rejected.
- Consider placing an extended fraud alert on your credit files, which requires lenders to verify your identity before issuing new credit.
These steps do not undo the breach, but they address the specific risks created by the combination of Social Security numbers and health records. The letter from Amgen remains the only definitive way to know whether your records were part of the 24 affected in this filing.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on Amgen Inc..
- Freeze your credit — this is the one that matters. A freeze is free, it takes minutes, and it has to be done separately at all three bureaus: Equifax, Experian and TransUnion. It stops a new account being opened in your name, which is what a Social Security number in the wrong hands is for. You can lift it temporarily whenever you need credit.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
Report details & sourcing
Related breaches
Victory Personal Care, Inc Listed by Nightspire Ransomware Group
Victory Personal Care, Inc was listed on the Nightspire ransomware leak site. The group claims to ha…
Victory Personal Care, Inc Listed by nightspire Ransomware Group
Data is not available now.…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…