CSIDB logo
Incident

West Pharmaceutical Services

Incident posture

Attack window
May 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 23:18

Linked entities

Victim
West Pharmaceutical Services
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
May 2026
Discovered
May 2026
Disclosed
May 2026
Resolved
Pending

Summary

West Pharmaceutical Services experienced a ransomware attack that led to the detection of an intrusion, prompting the proactive shutdown and isolation of affected on‑premise infrastructure. The containment disrupted global business operations across its pharmaceutical packaging and drug delivery supply chain. Attackers exfiltrated data before deploying file‑encrypting ransomware, and the company engaged Palo Alto Networks’ Unit 42 for threat intelligence, incident response and investigation while notifying law enforcement. Core enterprise systems have been restored and critical processes for shipping, receiving and manufacturing have restarted at some sites, with restoration of the remaining sites ongoing and a complete timeline not yet finalized. The firm is investigating the extent of the exfiltrated data and has taken steps to mitigate the risk of its dissemination, though it has not determined whether the incident will have a material impact on its financial condition or results of operations.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

West Pharmaceutical Services detected an intrusion on May 4 2026 and subsequently disclosed a material cyberattack on May 7 2026 after determining that an unauthorized party had exfiltrated certain data and encrypted certain systems. The company initiated a proactive shutdown and isolation of affected on‑premise infrastructure as a containment measure, which disrupted its business operations globally across the pharmaceutical packaging and drug delivery supply chain. The incident was described as a ransomware attack in an SEC filing, with the attackers having deployed file‑encrypting ransomware after the data exfiltration phase. West Pharmaceutical Services reported that the containment actions temporarily halted operations at multiple sites worldwide.

In response, the company restricted access to enterprise systems, activated crisis management protocols, and engaged Palo Alto Networks’ Unit 42 threat intelligence and incident response team to assist with containment, system restoration, and investigation. Law enforcement was notified of the incident. West Pharmaceutical Services stated that it had restored its core enterprise systems and that critical processes for shipping, receiving, and manufacturing had restarted at some sites, while restoration of the remaining sites remained ongoing with no finalized timeline for complete recovery. The company told the SEC that it was investigating the extent of the data affected and had taken steps intended to mitigate the risk of dissemination of the exfiltrated data. It also noted that no known ransomware group had claimed responsibility for the attack.

The disruption temporarily impacted West Pharmaceutical Services’ business operations, though the company has not disclosed the type of data stolen, whether personal information was involved, or the number of individuals affected. West Pharmaceutical Services indicated that it had yet to determine if the attack would have any material impact on its financial condition and results of operations. Founded in 1923 and headquartered in Exton, Pennsylvania, the company manufactures injectable pharmaceutical packaging and delivery systems.

Sources

Sources available to members: 2 sources.

CSIDB