Breach taxonomy
Summary
West Pharmaceutical Services detected an intrusion on May 4, 2026 and determined on May 7, 2026 that it had experienced a material cybersecurity attack in which data was exfiltrated by an unauthorized party and certain systems were encrypted. The company proactively took systems offline globally for containment, notified law enforcement, and engaged external forensic experts. Per this 8-K/A, core enterprise systems and manufacturing, receiving and shipping processes were restored at all sites and the company is fully operational globally, with no unauthorized activity observed since May 5, 2026.
Tagging rationale
ThreatUnknown
Filing refers only to 'an unauthorized party' with no attribution -> UNKNOWN.
MethodsRansomwareData Exfil
Filing states 'certain data was exfiltrated by an unauthorized party and certain systems were encrypted' -> RANSOMWARE (encryption) + DATA-EXFIL.
AssetsRevenue ProcessConfidential Biz
Global manufacturing, receiving and shipping operations were taken offline and required restoration -> REVENUE-PROCESS; 'certain data was exfiltrated' with extent still under investigation -> CONFIDENTIAL-BIZ.
EffectsBiz InterruptionInfo Privacy Loss
Systems were taken offline globally with manufacturing and shipping needing restart at all sites -> BIZ-INTERRUPTION, plus data exfiltration -> INFO-PRIVACY-LOSS.
Business continuityEffective
Company activated incident response protocols, proactively took systems offline, and by the amendment was 'fully operational across its manufacturing, supply chain and commercial sites globally' with core systems restored -> Effective.
Impact
Material encryption-and-exfiltration attack forced a global proactive shutdown of enterprise and manufacturing systems across all sites for roughly two weeks -> score 4.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 1.05 Material Cybersecurity Incidents. As previously disclosed in the Original Report, the Company determined on May 7, 2026 that the Company had experienced a material cybersecurity attack, in which certain data was exfiltrated by an unauthorized party and certain systems were encrypted. Upon initial detection of an intrusion on May 4, 2026, the Company promptly activated its incident response protocols, including proactively taking systems offline globally for containment purposes, notifying law enforcement, and engaging external cyber-forensic experts. Remediation efforts have since progressed, with core enterprise systems restored in addition to critical processes for manufacturing, receiving and shipping restarted at all sites. The Company is now fully operational across its manufacturing, supply chain and commercial sites globally. While the Company's investigation into the nature and scope of the incident is continuing, including with respect to the extent of the data affected, no unauthorized activity or access is ongoing or has been observed since May 5, 2026. Based on the investigation to date and information currently available, the Company believes that the incident has not had, and is not reasonably likely to have, a material impact on the Company's operations going forward.