Cyber Incident Victim: West Pharmaceutical Services
Date:
May 2026
Location:
United States of America
Summary
West Pharmaceutical Services detected an intrusion, took its systems offline globally to contain the globally to contain the attack, and disclosed that an unauthorized party exfiltrated data and encrypted systems. The disruption affected its pharmaceutical packaging and drug delivery supply chain operations worldwide. The company engaged Palo Alto Networks Unit 42 for incident response, restricted access to enterprise systems, activated crisis management protocols, and notified law enforcement. While core enterprise systems have been restored and critical shipping, receiving, and manufacturing processes have resumed at some sites, full restoration remains ongoing and the extent of the exfiltrated data is under investigation.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On May 4, 2026, West Pharmaceutical Services detected an intrusion into its systems and later disclosed a material cyberattack on May 7, 2026. The company stated that an unauthorized party exfiltrated certain data and then deployed file‑encrypting ransomware, prompting a proactive shutdown and isolation of affected on‑premise infrastructure. This containment action disrupted the company’s business operations globally across its pharmaceutical packaging and drug delivery supply chain. In response, West restricted access to enterprise systems, activated crisis management protocols, and notified law enforcement. The firm engaged Palo Alto Networks’ Unit 42 threat intelligence and incident response team to assist with containment, system restoration, and investigation. While core enterprise systems have been restored and critical processes for shipping, receiving, and manufacturing have restarted at some sites, work continues to restore the remaining sites and a final timeline for complete restoration has not been finalized.

The company told the SEC that it is investigating the extent of the data affected by the exfiltration and has taken steps intended to mitigate the risk of dissemination of the exfiltrated data. SecurityWeek reported that no known ransomware group has claimed responsibility for the attack. West Pharmaceutical Services said it has yet to determine whether the incident will have any material impact on its financial condition or results of operations. The firm has not disclosed specifics about the type of data that was stolen, whether any personal information was involved, or how many individuals might have been affected. Founded in 1923 and headquartered in Exton, Pennsylvania, West Pharmaceutical Services manufactures injectable pharmaceutical packaging and delivery systems. The incident remains under investigation with no further details on attacker identity or data volume released publicly.
