West Pharmaceutical Services experienced a ransomware incident.

Towfiqu barbhuiya via Unsplash
On May 7, West Pharmaceutical Services revealed it experienced a cyberattack.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity at Suzu Labs, remarks, “West’s SEC filing notes the company is still investigating what data was compromised. That uncertainty is a data inventory problem, and most organizations share it regardless of sector. They can tell you systems are down. Fewer can tell you exactly what data sat in those systems and who it affects. That gap extends every phase of incident response from materiality determination to customer notification. Complete data inventory is what allows an organization to answer the first question every board and every regulator will ask after a breach. What was taken.”
On May 11, the company announced that the cyber incident response measures temporarily disrupted global operations, including essential processes for shipping, receiving, and manufacturing. As of May 13, enterprise systems have been restored, and some shipping, receiving, and manufacturing processes have been restarted — but not all are back to full operations.
“The West Pharmaceutical attack is a direct hit on the ‘sterile core’ of the global drug supply chain,” says Damon Small, Board of Directors at Xcape, Inc. “By forcing a proactive global shutdown of manufacturing and shipping, the attackers didn’t just lock servers; they paralyzed the delivery mechanism for approximately 70% of the world’s injectable drugs. This incident demonstrates that in high-stakes manufacturing, the ‘proactive shutdown’ is often as disruptive as the malware itself, creating a massive backlog in a sector where sterile integrity and just-in-time delivery are non-negotiable.
“This breach proves that for critical suppliers, operational downtime is a secondary threat compared to the quiet extortion of proprietary IP. The absence of a public leak site listing suggests West is likely negotiating to protect specialized packaging designs and shipping manifests that represent a single point of failure for giants like Pfizer and Moderna. Restoration of enterprise systems is only half the battle; the ‘phased’ restart of global factories reveals a deep distrust in the underlying OT segmentation that allowed a corporate IT breach to reach the production line.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!
Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Targeted Phishing Attack Breaches Biotech Company Data | 0 | 5.85 | 16-03-2026 |
| 2 | When Cyberattacks Hit Medical Devices, Patients Pay the Price | 0 | 5.17 | 03-08-2026 |
| 3 | 2.6M Accounts Exposed in DentaQuest Data Breach | 0 | 12.98 | 05-06-2026 |
| 4 | Во Владимирской области из-за атаки загорелся логистический объект Wildberries | 0 | 21.11 | 03-08-2026 |
| 5 | В Подмосковье при атаке БПЛА загорелся склад с медикаментами | 0 | 10 | 16-08-2026 |
| 6 | Стало известно о пострадавших в результате атаки БПЛА на российский регион | 0 | 10 | 17-08-2026 |
| 7 | Мирошник: 10 сотрудников WB пострадали за неделю от атак ВСУ на склады | 0 | 10.41 | 04-08-2026 |
| 8 | Стало известно о серьезных последствиях атаки ВСУ на Ростовскую область | 0 | 10 | 25-07-2026 |
| 9 | Беспилотники атаковали склад Wildberries в Пензе | 0 | 10 | 30-07-2026 |
| 10 | На Западе ужаснулись происходящему в зоне СВО | 0 | 10 | 28-07-2026 |