Pennsylvania pharma giant West Pharmaceutical Services experienced a significant ransomware incident on May 4, prompting immediate action to contain the attack and causing global operational disruptions.
Incident Details
The company initiated a "proactive shutdown and isolation of affected on-premise infrastructure" following the attack discovery. This containment measure disrupted global business operations, as documented in the company's SEC filing dated May 7, 2026.
Response measures included restricting enterprise system access and activating crisis management protocols. West Pharmaceutical Services engaged Palo Alto Networks' Unit 42 for threat intelligence, incident response, containment, system restoration, and investigation support. Law enforcement was also notified.
Data Exfiltration and Encryption
Before deploying file-encrypting ransomware, attackers exfiltrated data from the company's systems. The company is investigating the extent of affected data but has not yet determined the specific types of information compromised or how many individuals might be impacted.
Recovery Status
Core enterprise systems have been partially restored, with "critical processes for shipping, receiving, and manufacturing have restarted at some sites." However, the timeline for complete restoration has not yet been finalized. The company has not disclosed financial impact assessments.
About West Pharmaceutical Services
Founded in 1923 and headquartered in Exton, Pennsylvania, the company manufactures injectable pharmaceutical packaging and delivery systems. The company serves major pharmaceutical and biotechnology companies globally. A disruption to its manufacturing operations could have downstream effects on drug packaging and delivery supply chains.
Industry Trend
This attack follows a broader pattern of ransomware groups targeting pharmaceutical and healthcare supply chain companies, recognizing the operational disruption pressure these organizations face when manufacturing processes are halted.