ctipilot.ch

West Pharmaceutical Services SEC 8-K Item 1.05 — data exfiltrated, systems encrypted, global operations partially restarted (2026-05-11)

incident · incident:west-pharma-8k-2026

Coverage timeline
1
first 2026-05-12 → last 2026-05-18
Briefs
1
1 distinct
Sources cited
16
8 hosts
Sections touched
1
active_threats
Co-occurring entities
8
see Related entities below

Story timeline

  1. 2026-05-12CTI Daily Brief — 2026-05-12
    active_threatsFirst coverage. Form 8-K Item 1.05 filed 2026-05-11. Detection 2026-05-04; materiality determination 2026-05-07. Double-extortion pattern (data exfiltration + system encryption). Core systems restored; shipping/receiving/manufacturing partially restarted; full timeline TBD. ~11,000 staff, ~50 sites worldwide; pharmaceutical packaging supply-chain exposure for EU biopharma.

Where this entity is cited

  • active_threats1

Source distribution

  • attack.mitre.org8 (50%)
  • sec.gov2 (12%)
  • cybersecuritydive.com1 (6%)
  • bleepingcomputer.com1 (6%)
  • frenchbreaches.com1 (6%)
  • novonordisk.com1 (6%)
  • theregister.com1 (6%)
  • welivesecurity.com1 (6%)

Related entities

All cited sources (16)

Items in briefs about West Pharmaceutical Services SEC 8-K Item 1.05 — data exfiltrated, systems encrypted, global operations partially restarted (2026-05-11) (4)

UPDATE: West Pharmaceutical Services — 8-K/A confirms full operational restoration, data investigation ongoing

From CTI Daily Brief — 2026-05-22 · published 2026-05-22 · view item permalink →

UPDATE (originally covered 2026-W21): West Pharmaceutical Services (NYSE: WST) filed an 8-K/A amendment under SEC Item 1.05 on 2026-05-20 confirming full operational restoration across all manufacturing, supply chain, and commercial sites globally after the May 4 ransomware intrusion (SEC EDGAR 8-K/A, 2026-05-20). No unauthorized activity observed since 2026-05-05. Data exfiltration scope and threat actor attribution remain under investigation; Palo Alto Networks Unit 42 is conducting the forensic response. The 8-K/A marks formal closure of the containment phase under the SEC's mandatory cyber-incident disclosure cycle; data impact scope will require a further disclosure when the investigation concludes.

West Pharmaceutical Services — 8-K/A confirms full operational restoration

From CTI Weekly Summary — 2026-W21 (May 18 – May 24, 2026) · published 2026-05-18 · view item permalink →

West Pharmaceutical Services (NYSE: WST) filed an 8-K/A amendment under SEC Item 1.05 on 2026-05-20 confirming full operational restoration across all manufacturing facilities, with the data investigation still ongoing. Closing the loop on the W20 disclosure: the manufacturing-line continuity risk this audience was tracking has resolved; the residual is the data-scope determination.

West Pharmaceutical Services — SEC Form 8-K Item 1.05 [SINGLE-SOURCE-OTHER]

From CTI Weekly Summary — 2026-W20 (May 11 – May 17, 2026) · published 2026-05-17 · view item permalink →

Data exfiltrated, systems encrypted, global operations partially restarted. SEC 8-K Item 1.05 disclosure — single-source as of week-end with no independent corroborating breach analysis. Operational relevance to Swiss / EU public-sector defenders: West Pharmaceutical supplies drug-delivery components into EU pharmaceutical-manufacturing supply chains; the "global operations partially restarted" language indicates ongoing IT-side recovery that may yet propagate downstream supply-chain impact (daily 2026-05-12).

[SINGLE-SOURCE-OTHER] West Pharmaceutical Services files SEC Form 8-K Item 1.05 — data exfiltrated, systems encrypted, global operations partially restarted

From CTI Daily Brief — 2026-05-12 · published 2026-05-12 · view item permalink →

West Pharmaceutical Services Inc. (NYSE: WST), a US-headquartered global manufacturer of drug-delivery and packaging components, filed a Form 8-K on 2026-05-11 disclosing a material cybersecurity incident under Item 1.05 (SEC EDGAR — WST 8-K, 2026-05-11). The filing states that detection occurred on May 4 2026, materiality was determined May 7, and that "certain data was exfiltrated by an unauthorized party and certain systems were encrypted" — terminology consistent with a T1486 Data Encrypted for Impact plus T1041 Exfiltration Over C2 Channel double-extortion ransomware pattern. The company took global systems offline, activated incident response, notified law enforcement and engaged external forensics; core enterprise systems are restored, shipping/receiving/manufacturing are partially restarted at some facilities, and full restoration timeline and material financial impact remain undetermined. No threat actor has claimed responsibility publicly at time of filing.

Defender takeaway: A double-extortion event against an OT-adjacent pharmaceutical packaging manufacturer is a high-supply-chain-risk template — West Pharma's elastomeric closures, vials and drug-delivery devices feed European biopharma packaging lines including those of national-formulary suppliers. EU public-sector procurement teams handling pharmaceutical resilience plans should validate continuity-of-supply with downstream vendors that source closures or delivery devices from West. Detection pivot for analogous targets: large-volume SMB enumeration, VSSAdmin / WBEM shadow-copy deletion (T1490 Inhibit System Recovery), and abnormal DLP egress volume in the days preceding encryption — the encryption event is rarely the first indicator if logs are retained.