www.securityweek.com 5/12/2026, 1:15:50 PM · via preferred

West Pharma Takes Systems Offline After Global Ransomware Breach

West Pharma Takes Systems Offline After Global Ransomware Breach
CyberSIXT Evidence Panel Source marked as original reporting

WEST Pharmaceutical Services says it took systems offline globally after hackers exfiltrated data and deployed file-encrypting ransomware, with the incident occurring on 4 May and prompting proactive shutdowns of affected on-premise infrastructure. The containment measures disrupted operations across the company, which later disclosed the issue in a Monday filing with the Securities and Exchange Commission (SEC).

The company also restricted access to enterprise systems, activated crisis management protocols, and retained Palo Alto Networks’ Unit 42 threat intelligence and incident response team to aid with containment, restoration, and investigation, while notifying law enforcement. West Pharmaceutical Services says it has restored core enterprise systems and some sites are back to shipping, receiving, and manufacturing, but a complete restoration timeline has not yet been finalised.

The firm told the SEC that attackers exfiltrated data before deploying ransomware and is investigating the extent of data affected; it did not name the ransomware group and SecurityWeek has not seen a group claim responsibility.

View full article

Article by CyberSIXT