Ingram Micro
Incident posture
Linked entities
- Victim
- Ingram Micro
- Threat actors
- 1 actor
- Sources
- 4 sources
Timeline
Summary
In July 2025, the IT distributor suffered a ransomware attack that forced it to take certain internal systems offline, causing widespread service outages and paralyzing logistics operations for roughly a week before restoration was completed. An investigation revealed that an unauthorized third party accessed internal systems between July 2 and 3, exfiltrating files containing employment and job applicant records. The compromised data included names, dates of birth, Social Security numbers, passport numbers, driver's license numbers, other government-issued identification numbers, and employment-related information, impacting approximately 42,500 current and former employees as well as job applicants. The Safepay ransomware group later claimed responsibility, alleging the theft of 3.5 terabytes of data, and ultimately published the allegedly stolen data after the company apparently did not pay a ransom.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In early July 2025, Ingram Micro, a major global IT distributor headquartered in Irvine, California, identified a ransomware attack affecting certain of its internal systems. On July 5, 2025, the company publicly disclosed the incident through an official statement and a Reuters report, noting that it had promptly taken steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement. The Irvine, California-based organization said it was working diligently to restore the affected systems so that it could resume processing and shipping orders and apologized for any disruption the issue caused to its customers, vendor partners, and others. Shortly after the incident became public, the ransomware group known as Safepay listed Ingram Micro on its Tor-based leak site, claiming responsibility for the attack and asserting that it had stolen 3.5 terabytes of data from the company.
According to subsequent notifications and filings, the unauthorized activity took place between July 2 and July 3, 2025, during which time an external party accessed certain company systems and took files from some internal file repositories. As a containment measure, Ingram Micro was forced to take certain systems offline, which resulted in significant outages across the company's services. The company employs approximately 23,500 people worldwide, and its logistics and ordering systems were paralyzed for roughly a week as a result of the incident. Ingram Micro was able to restore the affected systems and resume operations across all countries and regions by July 9, 2025. Safepay, a ransomware gang that emerged in September 2024 and has since become one of the more active cybercriminal groups, made the allegedly stolen data publicly available in early August 2025, suggesting that Ingram Micro did not pay a ransom.
An investigation later determined that the attackers had accessed files containing employment and job applicant records. In a mandatory filing with US authorities, specifically the Maine Attorney General's Office, Ingram Micro reported that 42,521 people were impacted by the incident. The compromised information included basic personal data such as names and contact information, as well as more sensitive identifiers including dates of birth, Social Security numbers, passport numbers, driver's license numbers, and other government-issued identification numbers. Additionally, documents from application processes and employee evaluations were among the stolen data. The affected individuals comprised current and former employees as well as job applicants. In response to the breach, Ingram Micro began sending notification letters to potentially affected individuals and announced that it would provide 24 months of free credit monitoring and identity protection services to those impacted by the data exposure.
Sources
Sources available to members: 4 sources.