West Pharmaceutical Services, which manufactures the injectable packaging and drug delivery systems used in an estimated 70% of the world's injectable medicines, disclosed in an SEC filing that it was hit by a ransomware attack that began on May 4, 2026, and was discovered three days later. The company took systems offline globally as a containment measure, disrupting manufacturing, shipping and receiving operations at multiple facilities.

West said attackers both encrypted systems and exfiltrated data. The company activated its incident response protocols immediately upon detection, engaged external cyber-forensic specialists from Palo Alto Networks' Unit 42, and notified law enforcement. At the time of its SEC filing, the company reported that core enterprise systems had been restored and that critical manufacturing processes were being brought back online in phases, site by site, rather than all at once.

Why a components maker matters more than its name suggests

West Pharmaceutical rarely appears on a prescription label, but its products sit underneath a huge share of the injectable drug supply — vial stoppers, syringe components and drug delivery systems that pharmaceutical manufacturers depend on to package everything from vaccines to biologics. A prolonged disruption at a supplier this deeply embedded in the supply chain doesn't just affect one company's output; it has the potential to ripple into the packaging capacity of every drugmaker that relies on West's components, at a moment when drug shortages are already a recurring concern for regulators and hospital pharmacies.

That concentration risk is exactly what makes pharmaceutical manufacturing an increasingly attractive ransomware target. Security researchers have tracked a sharp rise in operational technology-focused ransomware across the sector, and the same week West disclosed its attack, contract manufacturer Foxconn confirmed a separate breach by the Nitrogen ransomware gang, which stole roughly 8 terabytes of data and more than 11 million files — including hardware schematics and customer project documentation tied to Apple, Nvidia, Intel, Google and Dell Technologies.

A pattern, not an incident

Neither attack has been publicly linked to the other, but together they illustrate the same structural weakness: modern manufacturing runs on tightly coupled operational technology that was built for uptime and precision, not for isolating a ransomware infection once it gets in. Taking systems fully offline — as West did — is often the only reliable way to stop an attack from spreading through connected production lines, but it comes at the direct cost of the very output the plant exists to produce. For an industry where a single supplier's downtime can constrain drug availability nationally, that trade-off is becoming a board-level risk question rather than a purely technical one.