West Pharmaceutical Services suffers data theft and systems lockout
West Pharmaceutical Services reported a cyberattack that combined data theft and systems lockout, temporarily disrupting manufacturing, logistics and the supply chain.

News summary
West Pharmaceutical Services reported a cyberattack that combined data theft and systems lockout, temporarily disrupting manufacturing, logistics and the supply chain. The company restored operations on a facility-by-facility basis.
The combination of exfiltration and operational downtime necessitates addressing security and continuity simultaneously. Immutable copies, segmentation and prioritised recovery are especially important.
Source: Reuters — 27 July 2026
What happened
West Pharmaceutical Services disclosed a cyberattack that combined data theft with system lockdown, temporarily disrupting the company's manufacturing, logistics and supply chain. Operations were restored facility by facility rather than across the whole organisation at once.
This combination of information exfiltration with encryption or system lockdown is characteristic of the most aggressive ransomware attacks, where the attacker seeks to pressure the victim both by threatening to publish data and by forcing payment through operational disruption.
What it teaches a manufacturing business
When an attack hits both data and system availability at once, security and business continuity can no longer be treated separately: backups are of little use if they take days to restore or were also encrypted.
The gradual, facility-by-facility recovery rather than a global restart suggests a criticality-based prioritisation, a sensible approach when everything cannot be safely recovered at the same time.
What to review
Elements that make the difference between a fast recovery and a prolonged one:
- Whether backups are immutable and isolated from the main network.
- Whether the manufacturing network is segmented from the corporate and office network.
- Which facilities or production lines would be restored first based on criticality.
- Whether there is a plan to communicate with supply-chain customers in the event of a stoppage.
Frequently Asked Questions
- What kind of attack combines data theft and system lockdown?
- It's the standard pattern of modern ransomware, which exfiltrates information before encrypting systems to apply a double-extortion threat.
- Why was recovery facility by facility rather than global?
- A staged restore lets teams prioritise the most critical plants and verify each environment is clean before reconnecting it.
- What matters most for a manufacturing company?
- Having immutable backups and a segmented plant network, so recovery doesn't depend on restoring everything at once.
Is your company prepared for an incident of this nature? At Seintec, we can review access, backups, cloud, endpoints and procedures to reduce exposure and recovery times. Let’s talk.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.