Ingram Micro confirms ransomware behind multi-day outage
ID: c6c4294e-c1d5-5c64-8a2c-b2b7b34736b4
STIX ID: report--c6c4294e-c1d5-5c64-8a2c-b2b7b34736b4
Feed Name: The Register (Security)
Ingram Micro experienced a ransomware attack (claimed by the SafePay group) beginning 3 July 2025 that caused systems and phone lines to go down, prevented order placement and license management, and forced staff to disconnect devices; SafePay claims they encrypted files and exfiltrated sensitive financial, IP, accounting, legal, and customer data, possibly gaining access via a GlobalProtect VPN misconfiguration or stolen credentials. The company has taken affected systems offline, engaged cybersecurity experts, notified law enforcement, and is working to restore services while the extortion claim remains under investigation and unverified.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
