FEDERALItem 1.05 · mandatoryMalwareHealthcareManufacturingHealthcareRansomwareData ExfiltratedData EncryptedRansom DemandedLowContained
West Pharmaceutical Services, Inc.
bd_6cf422be95e67c2f · schema v1 · pii pii-v1
Full breach record for West Pharmaceutical Services, Inc. →West Pharmaceutical Services filed an 8-K/A on May 20, 2026 amending its May 11 disclosure of a material cybersecurity incident. The company detected an intrusion on May 4, 2026 and determined materiality on May 7, 2026. An unauthorized party exfiltrated certain data and encrypted certain systems. The company took systems offline globally, notified law enforcement, and engaged external cyber-forensic experts. Core enterprise and manufacturing systems have been restored; no unauthorized activity has been observed since May 5, 2026.
SEC clockMateriality determined May 7, 2026 → Filed May 20, 202613d ✗ SEC 4-day late16 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/105770/000010577026000077/wst-20260507.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 20, 2026
- Raw hash
- 35ac3476d27d5c23e5515f04081130a628ed8a802b3f560316ff26dbe07f2d47
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- West Pharmaceutical Services, Inc.norm: west pharmaceutical
- SEC CIK
- 0000105770
Victim entity
- Name
- West Pharmaceutical Services, Inc.norm: west pharmaceutical
- SEC CIK
- 0000105770
- Industry
- Pharmaceutical packaging/delivery components and devices
- Industry
- HealthcarellmManufacturingllm
Incident
- Discovered
- May 4, 2026
- Materiality determined
- May 7, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- —
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- Filed Form 8-K/A (Amendment No. 1) with the SEC under Item 1.05Notifying law enforcement
Compliance
- Time to disclose
- 16 days(16 days from discovery to filing)
- Compliance flags
- SEC 4-day late · 13d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: May 7, 2026→ Filed: May 20, 202613d cal. 4 business days SEC 4-day late
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.