Replace 7/6/25: Added Ingram Micro’s affirmation it suffered a ransomware assault under. Additionally up to date ransom notice with clearer model.
An ongoing outage at IT big Ingram Micro is brought on by a SafePay ransomware assault that led to the shutdown of inner methods, BleepingComputer has realized.
Ingram Micro is among the world’s largest business-to-business know-how distributors and repair suppliers, providing a variety of options together with {hardware}, software program, cloud companies, logistics, and coaching to resellers and managed service suppliers worldwide.
Since Thursday, Ingram Micro’s web site and on-line ordering methods have been down, with the corporate not disclosing the reason for the problems.
BleepingComputer has now realized that the outages are brought on by a cyberattack that occurred early Thursday morning, with staff abruptly discovering ransom notes created on their gadgets.
The ransom notice, seen by BleepingComputer, is related to the SafePay ransomware operation, which has turn into one of many extra lively operations in 2025. It’s unclear if gadgets have been truly encrypted within the assault.
It must be famous that whereas the ransom notice claims to have stolen all kinds of knowledge, that is generic language utilized in all SafePay ransom notes and will not be true for the Ingram Micro assault.

Supply: BleepingComputer
Do you’ve got details about this or one other cyberattack? If you wish to share the knowledge, you possibly can contact us securely and confidentially on Sign at LawrenceA.11, through e-mail at lawrence.abrams@bleepingcomputer.com, or by utilizing our ideas type.
Sources have advised BleepingComputer that it’s believed the menace actors breached Ingram Micro by means of its GlobalProtect VPN platform.
As soon as the assault was found, staff in some places have been advised to work at home. The corporate additionally shut down inner methods, telling staff to not use the corporate’s GlobalProtect VPN entry, which was stated to be impacted by the IT outage.
Techniques which might be impacted in lots of places embrace the corporate’s AI-powered Xvantage distribution platform and the Impulse license provisioning platform. Nevertheless, BleepingComputer was advised that different inner companies, similar to Microsoft 365, Groups, and SharePoint, proceed to function as normal.
As of yesterday, Ingram Micro has not disclosed the assault publicly or to its staff, solely stating there are ongoing IT points, as indicated by company-wide advisories shared with BleepingComputer.
The SafePay ransomware gang is a comparatively new operation that was first seen in November 2024, accumulating over 220 victims since then.
The ransomware operation has been beforehand noticed breaching company networks by means of VPN gateways utilizing compromised credentials and password spray assaults.
BleepingComputer contacted Ingram Micro yesterday and right now in regards to the outages and ransomware assault, however didn’t obtain a response to our emails.
Replace 7/6/25: In a short Sunday morning announcement, Ingram Micro has confirmed that they suffered a ransomware assault.
“Ingram Micro not too long ago recognized ransomware on sure of its inner methods,” reads Ingram Micro’s assertion.
“Promptly after studying of the problem, the Firm took steps to safe the related atmosphere, together with proactively taking sure methods offline and implementing different mitigation measures. The Firm additionally launched an investigation with the help of main cybersecurity specialists and notified legislation enforcement.”
“Ingram Micro is working diligently to revive the affected methods in order that it may well course of and ship orders, and the Firm apologizes for any disruption this subject is inflicting its clients, vendor companions, and others.”