CSIDB logo
Incident

Ingram Micro

Incident posture

Attack window
Jul 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:43

Linked entities

Victim
Ingram Micro
Threat actors
1 actor
Sources
4 sources

Timeline

Occurred
Jul 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

In July 2025, the IT distributor suffered a ransomware attack that forced it to take certain internal systems offline, causing widespread service outages and paralyzing logistics operations for roughly a week before restoration was completed. An investigation revealed that an unauthorized third party accessed internal systems between July 2 and 3, exfiltrating files containing employment and job applicant records. The compromised data included names, dates of birth, Social Security numbers, passport numbers, driver's license numbers, other government-issued identification numbers, and employment-related information, impacting approximately 42,500 current and former employees as well as job applicants. The Safepay ransomware group later claimed responsibility, alleging the theft of 3.5 terabytes of data, and ultimately published the allegedly stolen data after the company apparently did not pay a ransom.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In early July 2025, Ingram Micro, a major global IT distributor headquartered in Irvine, California, identified a ransomware attack affecting certain of its internal systems. On July 5, 2025, the company publicly disclosed the incident through an official statement and a Reuters report, noting that it had promptly taken steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement. The Irvine, California-based organization said it was working diligently to restore the affected systems so that it could resume processing and shipping orders and apologized for any disruption the issue caused to its customers, vendor partners, and others. Shortly after the incident became public, the ransomware group known as Safepay listed Ingram Micro on its Tor-based leak site, claiming responsibility for the attack and asserting that it had stolen 3.5 terabytes of data from the company.

According to subsequent notifications and filings, the unauthorized activity took place between July 2 and July 3, 2025, during which time an external party accessed certain company systems and took files from some internal file repositories. As a containment measure, Ingram Micro was forced to take certain systems offline, which resulted in significant outages across the company's services. The company employs approximately 23,500 people worldwide, and its logistics and ordering systems were paralyzed for roughly a week as a result of the incident. Ingram Micro was able to restore the affected systems and resume operations across all countries and regions by July 9, 2025. Safepay, a ransomware gang that emerged in September 2024 and has since become one of the more active cybercriminal groups, made the allegedly stolen data publicly available in early August 2025, suggesting that Ingram Micro did not pay a ransom.

An investigation later determined that the attackers had accessed files containing employment and job applicant records. In a mandatory filing with US authorities, specifically the Maine Attorney General's Office, Ingram Micro reported that 42,521 people were impacted by the incident. The compromised information included basic personal data such as names and contact information, as well as more sensitive identifiers including dates of birth, Social Security numbers, passport numbers, driver's license numbers, and other government-issued identification numbers. Additionally, documents from application processes and employee evaluations were among the stolen data. The affected individuals comprised current and former employees as well as job applicants. In response to the breach, Ingram Micro began sending notification letters to potentially affected individuals and announced that it would provide 24 months of free credit monitoring and identity protection services to those impacted by the data exposure.

Sources

Sources available to members: 4 sources.

CSIDB