HackingStolen CredentialsSupply Chain (3P Vendor)Data ExfiltratedEmployee Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENTMediumContained
AMGEN INC.
bd_7ed9e3ab9ae795bb · schema v1 · pii pii-v1
Full breach record for AMGEN INC. →Amgen Inc. notified individuals that their personal information may have been accessed due to a data security incident at its service provider, Sirva Relocation, LLC. Unknown actors accessed Sirva systems between August 16, 2023, and October 17, 2023, copying files containing employee data including names, SSNs, financial accounts, and health information. Sirva detected the activity on September 29, 2023. Amgen engaged in an investigation, secured the network, and offered identity monitoring services via Kroll.
California clockDiscovered Sep 29, 2023 → Notified Sep 25, 2024362d ✗ CA 60-day late52 weeks discovery → filing
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_8dc1b2716cb164fdIndiana State AGfiled 2024-09-25Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-592382
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 25, 2024
- Raw hash
- d999064a949572a782fe974193f40caf9ec9dd951b6faa08e57aa9b77a928d80
Reporting entity
- Name
- AMGEN INC.norm: amgen
Victim entity
- Name
- AMGEN INC.norm: amgen
Incident
- Discovered
- Sep 29, 2023
- Materiality determined
- —
- Notification sent
- Sep 25, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTHEALTH_BASICEMPLOYMENT
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- External
- Regulator citations
- Notification to law enforcement and regulatorsProviding notification of this incident to global data protection authorities and applicable U.S. state regulators, including state Attorneys General
- Third party
- via Sirva Relocation, LLC
- Initial access
- trusted_relationship
Compliance
- Time to disclose
- 52 weeks(362 days from discovery to filing)
- Compliance flags
- CA 60-day late · 362d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Sep 29, 2023→ Notified: Sep 25, 2024362d 60 days (analyst band, pre-2026 discoveries) CA 60-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.