Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Attacks - Cyberattack on West Pharmaceutical halts manufacturing across multiple sites
Attacks Critical Infrastructure Security Latest News News & Analysis Security

Cyberattack on West Pharmaceutical halts manufacturing across multiple sites

Kirsten DoyleBy Kirsten DoyleMay 15, 20265 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
West Pharmaceutical
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

West Pharmaceutical Services has disclosed a ransomware attack that disrupted manufacturing, shipping, and receiving operations across multiple global facilities after bad actors breached the company’s network on 4 May.  

The pharmaceutical packaging manufacturer said attackers exfiltrated data and encrypted systems, forcing the company to proactively shut down portions of its infrastructure to contain the incident. 

“We continue to make good progress in the restoration of our systems. Our outside counsel promptly engaged Palo Alto Networks Unit 42 to support the Company’s investigation, containment, and recovery efforts, in coordination with other external experts,” the company added.” 

It said it has restored its core enterprise systems, and critical processes for shipping, receiving, and manufacturing have restarted at some sites with restoration at remaining sites ongoing. “This is a 24/7 effort and top priority for our entire organization.” 

In a letter posted on its website, West said based on the forensic evidence reviewed and the threat hunting activities performed across the environment, no persistent activity has been identified. The incident has only impacted domain-joined devices of West Pharmaceutical Services. 

Also, all known indicators of compromises associated with this incident are in the process of being successfully identified and addressed. 

“Unit 42 has engaged with a global restoration service to assist with recovery of the identity infrastructure and has reported that existing accounts have been secured,” the letter read.  

“We remain steadfast in our commitment to supporting our customers and the critical role of our products to improving patients’ lives across the globe.” 

West said it will continue to provide timely updates as additional information becomes available. 

Target selection follows market logic 

 Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, at Suzu Labs, said: “Ransomware has completed its transition from disparate criminal hackers into a full industry. According to Chainalysis, claimed attacks surged 50% in 2025 across as many as 85 active extortion groups competing for victims.” 

He said these groups run affiliate programs with revenue sharing and dedicated support infrastructure. “Target selection follows market logic, and a manufacturer that produces the injectable packaging and delivery systems drug companies depend on to get medication to patients cannot absorb extended downtime without that disruption cascading downstream.” 

Treat ransomware as an operational assumption and invest accordingly 

Krell said businesses occupying critical supply chain positions should treat ransomware as an operational assumption and invest accordingly. That means blast radius reduction and validated recovery capabilities, supported by proactive threat hunting. Perimeter defense alone is insufficient when adversaries operate with the speed and specialization of a professional operation. 

“West’s SEC filing notes the company is still investigating what data was compromised. That uncertainty is a data inventory problem, and most organizations share it regardless of sector. They can tell you systems are down. Fewer can tell you exactly what data sat in those systems and who it affects. That gap extends every phase of incident response from materiality determination to customer notification. Complete data inventory is what allows an organization to answer the first question every board and every regulator will ask after a breach. What was taken.” 

Forcing a proactive global shutdown 

Damon Small, Board of Directors, at Xcape Inc, added: “The West Pharmaceutical attack is a direct hit on the “sterile core” of the global drug supply chain. By forcing a proactive global shutdown of manufacturing and shipping, the attackers didn’t just lock servers; they paralyzed the delivery mechanism for approximately 70% of the world’s injectable drugs. This incident demonstrates that in high-stakes manufacturing, the “proactive shutdown” is often as disruptive as the malware itself, creating a massive backlog in a sector where sterile integrity and just-in-time delivery are non-negotiable.

“This breach proves that for critical suppliers, operational downtime is a secondary threat compared to the quiet extortion of proprietary IP. The absence of a public leak site listing suggests West is likely negotiating to protect specialized packaging designs and shipping manifests that represent a single point of failure for giants like Pfizer and Moderna. Restoration of enterprise systems is only half the battle; the “phased” restart of global factories reveals a deep distrust in the underlying OT segmentation that allowed a corporate IT breach to reach the production line. 

Start demanding proof of “clean room” recovery environments 

To do better, Small says security teams must stop treating supply chain risk as a paperwork exercise and start demanding proof of “clean room” recovery environments from their Tier-1 vendors. “Defenders should prioritize isolating the OT control plane from the business network with strict, unidirectional gateways and move toward immutable, off-site backups that can survive a global “kill switch” event. A reference architecture – the Purdue Model – that describes in detail how to accomplish this has existed since 1995 so there is little excuse for not understanding these concepts. 

He believes true resilience in the pharmaceutical space requires a shift from reactive containment to a proactive architecture where the loss of an IT domain controller doesn’t result in a worldwide manufacturing cardiac arrest.  “In manufacturing, a “phased restoration” is usually just corporate-speak for “we paid the ransom, and now we’re just waiting for the hackers to give us our factory back.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw
  • Kirsten Doyle
    CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet
  • Kirsten Doyle
    Threat Actors Deploy Tiflux RMM for Persistent Remote Access

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Dutch police, NCSC take down major botnet

June 4, 20264 Mins Read

CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet

June 1, 20265 Mins Read

Threat Actors Deploy Tiflux RMM for Persistent Remote Access

May 29, 20263 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}