West Pharmaceutical Services disclosed that attackers breached its network, stole data, and encrypted parts of its environment in a ransomware attack that disrupted global business operations. The Pennsylvania-based manufacturer said it detected the incident on May 4 and responded by shutting down and isolating affected on-premise infrastructure, restricting access to enterprise systems, notifying law enforcement, and bringing in Palo Alto Networks' Unit 42 to support containment, forensics, and recovery.
The company said the attack affected critical systems used for shipping, receiving, and manufacturing products, though core enterprise systems have since been restored and some sites have resumed critical processes and partial manufacturing operations. West is still investigating what data was exfiltrated and whether the incident will have a material financial impact, and no ransomware group had publicly claimed responsibility at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By the time of public reporting on May 12-13, 2026, West said core enterprise systems had been restored and some critical processes and affected sites had restarted operations. The company continued investigating the breach while determining the extent of data theft and business impact.
On May 7, 2026, West Pharmaceutical disclosed the ransomware incident in an SEC filing, stating that data had been stolen and systems encrypted. The filing said the company was still assessing the scope of compromised data and the potential financial impact.
Following detection of the attack, West proactively shut down and isolated affected on-premise infrastructure, restricted access to enterprise systems, and notified law enforcement. The company also engaged Palo Alto Networks Unit 42 and other external incident response experts to investigate, contain, and remediate the incident.
On May 4, 2026, West Pharmaceutical Services detected a cyberattack in which an intruder breached its network, exfiltrated data, and encrypted certain systems. The incident disrupted global operations, including systems supporting shipping, receiving, and manufacturing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourceinvestor.westpharma.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.