Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Ransomware - Ransomware Attack Cripples Ingram Micro, Disrupts Global Services
Ransomware Attacks Latest News News & Analysis

Ransomware Attack Cripples Ingram Micro, Disrupts Global Services

Kirsten DoyleBy Kirsten DoyleJuly 8, 20255 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Ransomware Attack Ingram Micro
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Ingram Micro has confirmed a ransomware attack that has forced systems offline and disrupted core services across its global operations. The breach, first reported as an unexplained outage on 3 July has now been linked to the SafePay ransomware group, one of the more active players in the 2025 threat landscape.

By 6 July, the IT distribution giant broke its silence: “Ingram Micro recently identified ransomware on certain of its internal systems,” the company said in a statement. “Promptly after learning of the issue, the Company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.”

The company acknowledged the impact on customer operations and emphasized recovery efforts:  “Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the Company apologizes for any disruption this issue is causing its customers, vendor partners, and others.”

Silent Systems, Sudden Shutdowns

The attack reportedly began in the early hours of 3 July. Employees arriving at work found ransom notes left on their machines. According to BleepingComputer, the notes matched those used by SafePay, though it remains unclear whether systems were encrypted or if any data was exfiltrated.

The incident took down several of Ingram Micro’s core platforms, including its Xvantage AI-powered distribution system and the Impulse license provisioning tool. The company’s website and ordering systems remain offline. Customers and partners around the world have been affected.

Internal sources told BleepingComputer that employees in certain locations were told to work remotely, and the use of the company’s GlobalProtect VPN was suspended. Microsoft 365, Teams, and SharePoint reportedly continue to operate.

SafePay’s Growing Footprint

SafePay emerged in late 2024 and has already claimed over 220 victims. The group often targets corporate networks through VPN gateways, exploiting compromised credentials and weak authentication controls. In Ingram Micro’s case, early indicators suggest the attackers may have accessed the network via its GlobalProtect VPN, though that link is still under investigation.

Palo Alto Networks, the developer of GlobalProtect, responded to the reports:

“At Palo Alto Networks, the security of our customers is our top priority. We are aware of a cybersecurity incident impacting Ingram Micro and reports that mention Palo Alto Networks’ GlobalProtect VPN,” the company told BleepingComputer. “We are currently investigating these claims. Threat actors routinely attempt to exploit stolen credentials or network misconfigurations to gain access through VPN gateways.”

A Global Tech Backbone Disrupted

Ingram Micro is one of the largest technology distributors in the world, connecting hardware, software, cloud services, and supply chain solutions with resellers, systems integrators, and managed service providers. Disruption at this scale sends ripples across entire ecosystems, particularly in a channel-driven industry.

For days, the company offered no details to employees or customers, only acknowledging “ongoing IT issues.” That silence is now explained by the forensic work underway behind the scenes. An advisory remains pinned to the homepage.

The broader implications are still unfolding. SafePay’s tactics, including generic data theft claims in its ransom notes, leave many unanswered questions about the extent of the compromise.

What’s clear is that one of the tech world’s largest intermediaries has been hit hard. Ingram Micro, for now, is in recovery mode. And so are its customers.

A Well-timed Attack

“Organisations such as Ingram Micro work on a very tight schedule, moving inventory quickly in and out of its warehouses, and coordinating its operations really closely across warehouses and corporate headquarters,” comments Erich Kron, Security Awareness Advocate at KnowBe4.

“Ransomware attacks such as this that involve encryption can devastate an organisation with such well-coordinated operations. The fact that this was launched on July 3rd, at the start of the U.S. Independence Day holiday is probably no coincidence. Many times, attackers will delay the attack until a holiday, because they know that response times are going to be slower as employees are away celebrating or traveling.”

This is a popular tactic and should be considered, along with recall and contact procedures, around any holidays. “There is a good chance the attackers have been in the network and laying low for days or weeks already.”

Typically, Kron says attackers also steal a copy of as much data as they can to use as leverage in the ransom negotiation phase. “This means employees or customers may have personal information at risk of being dumped on the dark web.”

He says because ransomware is so effective in highly coordinated and regulated industries, such as manufacturing, medical, or government entities, these sorts of attacks can demand a significant ransom from the victims.

“Organizations in these industries should be very conscious of the ransomware threat, and should employ a comprehensive human risk management plan, as a majority of ransomware is spread through social engineering attacks, or human error such as using poor passwords. In addition, organisations should have regularly tested incident response and continuity of operations plans in place, and should employ data leakage prevention controls.” 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}