FEDERALItem 1.05 · mandatoryMalwareRansomwareData ExfiltratedData EncryptedMulti-Stage ChainCustomer Data InvolvedPIIIPLowActive
West Pharmaceutical Services, Inc.
bd_7869724e0f5d9c92 · schema v1 · pii pii-v1
Full breach record for West Pharmaceutical Services, Inc. →West Pharmaceutical Services, Inc. disclosed a material cybersecurity incident on May 7, 2026. The company detected an intrusion on May 4, 2026, involving data exfiltration and system encryption. The company activated incident response protocols, took systems offline globally, notified law enforcement, and engaged forensic experts. Core enterprise systems have been restored, though full restoration is ongoing. The investigation into the scope of affected data is active.
SEC clockMateriality determined May 7, 2026 → Filed May 11, 20264d ✓ SEC 4-day OK7 days discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/105770/000010577026000068/wst-20260507.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- May 11, 2026
- Raw hash
- e6b0ec3e9cfe99b7866e9fc3270670d8a2980955733d7330a534fda55c5a095a
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- West Pharmaceutical Services, Inc.norm: west pharmaceutical
- SEC CIK
- 0000105770
Victim entity
- Name
- West Pharmaceutical Services, Inc.norm: west pharmaceutical
- SEC CIK
- 0000105770
Incident
- Discovered
- May 4, 2026
- Materiality determined
- May 7, 2026
- Notification sent
- May 11, 2026
- Affected individuals
- Not disclosed
- Data types
- PIIIP
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1041 Exfiltration Over C2 Channel
- Threat actor
- ExternalFinancial
- Regulator citations
- notifying law enforcement
Compliance
- Time to disclose
- 7 days(7 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 4d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: May 7, 2026→ Filed: May 11, 20264d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.