logo

Ingram Micro confirms ransomware behind multi-day outage

ID: c6c4294e-c1d5-5c64-8a2c-b2b7b34736b4

STIX ID: report--c6c4294e-c1d5-5c64-8a2c-b2b7b34736b4

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-07-06

Date Updated: 2026-04-26

Author: Paul Kunert

...
...

Ingram Micro experienced a ransomware attack (claimed by the SafePay group) beginning 3 July 2025 that caused systems and phone lines to go down, prevented order placement and license management, and forced staff to disconnect devices; SafePay claims they encrypted files and exfiltrated sensitive financial, IP, accounting, legal, and customer data, possibly gaining access via a GlobalProtect VPN misconfiguration or stolen credentials. The company has taken affected systems offline, engaged cybersecurity experts, notified law enforcement, and is working to restore services while the extortion claim remains under investigation and unverified.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.