West Pharmaceutical Services
Incident posture
Linked entities
- Victim
- West Pharmaceutical Services
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
West Pharmaceutical Services experienced a ransomware attack that led to the detection of an intrusion, prompting the proactive shutdown and isolation of affected on‑premise infrastructure. The containment disrupted global business operations across its pharmaceutical packaging and drug delivery supply chain. Attackers exfiltrated data before deploying file‑encrypting ransomware, and the company engaged Palo Alto Networks’ Unit 42 for threat intelligence, incident response and investigation while notifying law enforcement. Core enterprise systems have been restored and critical processes for shipping, receiving and manufacturing have restarted at some sites, with restoration of the remaining sites ongoing and a complete timeline not yet finalized. The firm is investigating the extent of the exfiltrated data and has taken steps to mitigate the risk of its dissemination, though it has not determined whether the incident will have a material impact on its financial condition or results of operations.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
West Pharmaceutical Services detected an intrusion on May 4 2026 and subsequently disclosed a material cyberattack on May 7 2026 after determining that an unauthorized party had exfiltrated certain data and encrypted certain systems. The company initiated a proactive shutdown and isolation of affected on‑premise infrastructure as a containment measure, which disrupted its business operations globally across the pharmaceutical packaging and drug delivery supply chain. The incident was described as a ransomware attack in an SEC filing, with the attackers having deployed file‑encrypting ransomware after the data exfiltration phase. West Pharmaceutical Services reported that the containment actions temporarily halted operations at multiple sites worldwide.
In response, the company restricted access to enterprise systems, activated crisis management protocols, and engaged Palo Alto Networks’ Unit 42 threat intelligence and incident response team to assist with containment, system restoration, and investigation. Law enforcement was notified of the incident. West Pharmaceutical Services stated that it had restored its core enterprise systems and that critical processes for shipping, receiving, and manufacturing had restarted at some sites, while restoration of the remaining sites remained ongoing with no finalized timeline for complete recovery. The company told the SEC that it was investigating the extent of the data affected and had taken steps intended to mitigate the risk of dissemination of the exfiltrated data. It also noted that no known ransomware group had claimed responsibility for the attack.
The disruption temporarily impacted West Pharmaceutical Services’ business operations, though the company has not disclosed the type of data stolen, whether personal information was involved, or the number of individuals affected. West Pharmaceutical Services indicated that it had yet to determine if the attack would have any material impact on its financial condition and results of operations. Founded in 1923 and headquartered in Exton, Pennsylvania, the company manufactures injectable pharmaceutical packaging and delivery systems.
Sources
Sources available to members: 2 sources.