Breach taxonomy
Summary
West Pharmaceutical Services detected a network intrusion on May 4, 2026 and on May 7, 2026 determined it to be a material cybersecurity incident. An unauthorized party exfiltrated certain data and encrypted certain systems. The Company proactively took systems offline globally for containment, notified law enforcement, and engaged Palo Alto Networks' Unit 42 along with other external forensic experts. The incident temporarily disrupted business operations globally; core enterprise systems have been restored and critical shipping, receiving, and manufacturing processes have restarted at some sites with restoration at remaining sites ongoing as of filing. Timeline for complete restoration is not finalized and the financial impact has not yet been determined.
Tagging rationale
ThreatUnknown
Filing refers only to an 'unauthorized party' without describing actor type, motivation, geography, or attribution. Does not name a criminal group, nation-state, or insider -> UNKNOWN.
MethodsRansomwareData Exfil
Filing states 'certain data was exfiltrated by an unauthorized party and certain systems were encrypted' - encryption of systems plus exfiltration matches the double-extortion ransomware pattern -> RANSOMWARE + DATA-EXFIL.
AssetsRevenue ProcessConfidential Biz
Filing states 'business operations globally' were disrupted and shipping/receiving/manufacturing processes were halted (REVENUE-PROCESS). Separately, 'certain data was exfiltrated' without specifying it was customer PII or IP, so the broader CONFIDENTIAL-BIZ tag captures the exfiltrated business data.
EffectsBiz InterruptionCyber Extortion
Filing states the incident 'temporarily disrupted the Company's business operations globally' (BIZ-INTERRUPTION) and that the Company 'has taken steps intended to mitigate the risk of dissemination of the exfiltrated data,' indicating a double-extortion / extortion threat dynamic -> CYBER-EXTORTION.
Business continuityPartial
Filing and accompanying press release confirm West 'activated its incident response protocols' and 'is leveraging its business continuity plans'; core enterprise systems are restored and some sites are operational, but other sites remain in restoration with no finalized timeline -> Partial.
Impact
A material cybersecurity attack on a globally operating pharmaceutical packaging supplier (S&P 500 component) that took systems offline globally, disrupted shipping/manufacturing across multiple sites, and remained incompletely restored as of filing -> High (4); financial impact not yet quantified.
InsuranceNot disclosed
Filing and accompanying website statement make no mention of cyber insurance or insurance proceeds -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. On May 7, 2026, West Pharmaceutical Services, Inc. (the "Company") determined that the Company has experienced a material cybersecurity attack, in which certain data was exfiltrated by an unauthorized party and certain systems were encrypted. Upon initial detection of an intrusion on May 4, 2026, the Company promptly activated its incident response protocols, including proactively taking systems offline globally for containment purposes, notifying law enforcement, and engaging external cyber-forensic experts. The Company's investigation into the nature and scope of the incident remains ongoing, including the extent of the data affected. The Company has taken steps intended to mitigate the risk of dissemination of the exfiltrated data. The incident and the Company's proactive response have temporarily disrupted the Company's business operations globally. While the Company has restored its core enterprise systems, and critical processes for shipping, receiving, and manufacturing have restarted at some sites with restoration of the remaining sites in process, the timeline for a complete restoration has not yet been finalized. The incident's material impact on the Company's financial condition and results of operations, if any, has not been determined at the time of filing. Forward-Looking Statements This Current Report on Form 8-K contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, but not limited to, statements regarding the Company's expectations regarding future events, actions or performance related to the cybersecurity incident, including the results of the Company's ongoing investigation thereof and the impact of the cybersecurity incident on the Company, and its financial or operational performance. Forward-looking statements may be identified by words such as "believe," "expect," "intend," "estimate," "plan," "anticipate," "project," "forecast," "guidance," "target," "may," "will," "continue" and similar expressions. These statements are based on current expectations and assumptions and are subject to risks and uncertainties that could cause actual results to differ materially from those expressed or implied by such forward-looking statements. For additional information regarding these risks as well as other risks, uncertainties and factors that could affect our forward-looking statements, please refer to Part I Item 1A, entitled "Risk Factors," of the Company's most recent Annual Report on Form 10-K and any amendments thereto, as well as the Company's most recently filed Quarterly Reports on Form 10-Q and other filings the Company makes with the Securities and Exchange Commission. Forward-looking statements speak only as of the date of this Current Report on Form 8-K. Except as required by law or regulation, West Pharmaceutical Services, Inc. undertakes no obligation to update or revise any forward-looking statements, whether as a result of new information, future events or otherwise.