West Pharmaceutical Services disclosed a material cybersecurity incident after detecting suspicious activity on May 4 and determining by May 7 that an unauthorized actor had exfiltrated data and encrypted multiple internal systems. In an SEC filing, the pharmaceutical packaging and drug-delivery manufacturer said the attack disrupted parts of its global operations, including manufacturing, shipping, and enterprise functions. The company isolated affected systems, restricted enterprise network access, notified law enforcement, and brought in external incident-response support from Palo Alto Networks Unit 42 while recovery efforts continued.
West said some production and distribution systems have been restored and manufacturing has partially resumed, but the investigation is ongoing and the full scope of stolen data and financial impact remains unknown. No ransomware group has publicly claimed responsibility, though the combination of data theft and encryption matches double-extortion ransomware tactics that have repeatedly hit pharmaceutical manufacturers and broader healthcare supply chains, including earlier warnings from Indian drugmaker Sun Pharma that a ransomware attack could lead to revenue loss and litigation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
West Pharmaceutical Services disclosed the incident as a material cybersecurity attack in an SEC filing. The company said some production and distribution systems had been restored and manufacturing had partially resumed while the investigation continued.
Following the discovery, West activated incident response and crisis management procedures, isolated affected systems, restricted enterprise access, notified law enforcement, and engaged external experts including Palo Alto Networks Unit 42.
By May 7, 2026, West determined that an unauthorized actor had exfiltrated data and encrypted multiple internal systems. The incident disrupted parts of its global operations, including manufacturing, shipping, and enterprise functions.
West Pharmaceutical Services detected suspicious activity on its network on May 4, 2026, prompting the company to begin investigating a cybersecurity incident.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.