West Pharmaceutical Services, Inc.

West Pharmaceutical Services detected a cyberattack on May 4, 2026, in which an unauthorized party exfiltrated data and encrypted systems. The company took systems offline globally, disrupting manufacturing, shipping, receiving, and enterprise operations before reporting full operational restoration on May 20.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Internal or external network connectivity was unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Manufacturing, production, assembly, processing, or industrial operations were reduced, stopped, or impaired.
Procurement, inventory, warehousing, shipping, delivery, vendor, or other supply-chain processes were materially affected.
Services continued but with longer processing, response, delivery, or completion times.
Employees or contractors were unable to perform normal duties because systems, data, facilities, or communications were unavailable.
The incident may involve extortion, but available evidence does not establish which extortion indicators were present.
DysruptionHub’s published report documented that West Pharmaceutical Services experienced a May 4, 2026 cyberattack that disrupted global operations. West’s Form 8-K said an unauthorized party exfiltrated certain data and encrypted certain systems, prompting the company to take systems offline globally for containment.
DysruptionHub assesses with high confidence that the incident was a ransomware-style intrusion involving both encryption and data theft. West did not publicly confirm a ransom demand, payment, ransomware family or threat actor, so the public record supports high-confidence ransomware rather than confirmed extortion attribution.
The incident disrupted West’s global manufacturing and supply-chain operations. The company said core enterprise systems were restored first, while shipping, receiving and manufacturing restarted in phases across multiple sites. West supplies components and delivery systems used by pharmaceutical and biotechnology manufacturers, so prolonged disruption carried downstream supply-continuity risk even though no patient-facing service interruption was publicly documented.
West used business-continuity measures and coordinated with customers while restoring operations. A May 15 update said shipping, receiving and manufacturing were operational or ramping across the company’s major site groups. West’s May 20 Form 8-K/A then said critical manufacturing, receiving and shipping processes had restarted at all sites and that manufacturing, supply-chain and commercial sites were fully operational globally.
West’s official locations directory identifies U.S. facilities in Scottsdale and Tempe, Arizona; Clearwater and St. Petersburg, Florida; Greenfield, Indiana; Walker, Michigan, which West labels Grand Rapids; Kearney, Nebraska; Kinston, North Carolina; Exton, Jersey Shore, Radnor, Upper Darby and Williamsport, Pennsylvania; and Cidra, Puerto Rico. Because West described the incident and recovery as global and across all sites, DysruptionHub assesses with medium confidence that these facilities were within the incident’s operational scope. West did not publish site-specific outage durations or severity.
West publicly disclosed the incident through customer updates and SEC filings. Its statements identified the intrusion date, global containment actions, data exfiltration, system encryption, phased operational recovery, law-enforcement notification and engagement of external forensic specialists.
The company did not identify the categories or volume of exfiltrated data, whether customers or employees were affected, whether a ransom demand was received, or whether any payment or negotiation occurred. West said it took steps intended to reduce the risk that the exfiltrated data would be disseminated, but that statement does not establish extortion or payment.
West’s second-quarter results referenced nonrecurring professional fees associated with the May cyber incident but did not isolate an incident-specific amount. The company raised full-year sales and earnings guidance, consistent with its earlier assessment that the event was not reasonably likely to materially affect 2026 guidance.
Confidence is high that unauthorized access, data exfiltration, encryption and global operational disruption occurred because West stated each fact in its SEC filing and public updates. Confidence is high that operations were restored because the company declared all manufacturing, supply-chain and commercial sites fully operational on May 20.
Ransomware confidence is high, based on the combination of data theft and system encryption, but the organization did not publicly use that term in the reviewed primary sources. Extortion indicators remain unresolved because no ransom note, demand, leak-site listing, deadline, payment instruction or threat actor was publicly identified.
West reported full operational restoration on May 20. Its May 27 update said Unit 42 had found no continuing related unauthorized activity as of May 5 and that production was still ramping to support customers. DysruptionHub therefore assesses the incident as resolved while using May 27 as the latest dated observation of operational recovery work.
The reviewed sources do not establish the initial access vector, compromised account or device, vulnerability exploited, ransomware family, dwell time, encryption scope by site, backup impact, ransom demand, payment status or threat actor. They also do not identify the categories, volume, ownership or notification implications of the exfiltrated data, or quantify the impact at individual facilities.

West lists two Scottsdale facilities; company updates described systems offline globally and restoration across all sites.
West lists two Tempe manufacturing facilities; company updates described systems offline globally and restoration across all sites.
West lists a Clearwater receiving, warehouse and distribution facility; company updates described global supply-chain restoration.
West lists a St. Petersburg manufacturing facility; company updates described systems offline globally and restoration across all sites.
West lists a Greenfield assembly and packaging facility; company updates described systems offline globally and restoration across all sites.
West labels the Walker facility as Grand Rapids; company updates described systems offline globally and restoration across all sites.
West lists a Kearney manufacturing facility; company updates described systems offline globally and restoration across all sites.
West lists a Kinston manufacturing facility; company updates described systems offline globally and restoration across all sites.
West lists a Jersey Shore manufacturing facility; company updates described systems offline globally and restoration across all sites.
West lists a Radnor research facility; global enterprise systems were restricted and restored during the incident.
West lists an Upper Darby tooling facility supporting manufacturing; company updates described systems offline globally and restoration across all sites.
West lists a Williamsport manufacturing facility; company updates described systems offline globally and restoration across all sites.
West lists a Cidra contract-manufacturing facility; company updates described systems offline globally and restoration across all sites.
West Pharmaceutical Services said a May 4 cyberattack disrupted global operations. The company confirmed that data was exfiltrated, systems were encrypted, and shipping, receiving, and manufacturing processes were being restored in stages.
West said it determined on May 7 that it had experienced a material cybersecurity attack in which certain data was exfiltrated and certain systems were encrypted. The company took systems offline globally, disrupting business operations while manufacturing, shipping, and receiving were restored in phases.
Cybersecurity Dive reported that West was restoring global operations after attackers stole data and encrypted systems, affecting critical manufacturing, shipping, and receiving processes.
West reported on May 20 that manufacturing, supply-chain, and commercial sites were fully operational globally. Earlier updates described phased restoration of enterprise systems, shipping, receiving, and manufacturing across multiple sites.
West said critical manufacturing, receiving and shipping processes had restarted at all sites and that manufacturing, supply-chain and commercial sites were fully operational globally. It said no continuing unauthorized activity had been observed since May 5 and did not expect a material effect on 2026 guidance.
West’s second-quarter results referenced nonrecurring professional fees associated with the May cybersecurity incident but did not isolate the incident-specific amount. The company raised its full-year net-sales and earnings guidance.
Signed-in members can report an error, update, or missing source.