Ingram Micro Recovers from Ransomware Attack, Restores Operations

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025 3 min read

Ingram Micro Ransomware Attack

Ingram Micro
Ingram Micro reported a ransomware incident on July 4 that targeted its internal systems. The company took affected systems offline immediately after discovering the ransomware. Ingram Micro stated, “The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.” The company is working to restore operations while apologizing for disruptions experienced by customers and vendor partners.

Ingram Micro reported $48 billion in sales last fiscal year, operating as a key connector between organizations and technology manufacturers. The attack was noted to be linked to the SafePay ransomware gang, which has been responsible for multiple attacks, including on other organizations such as government contractor Conduent.

Further details from cybersecurity expert Rebecca Moody indicate that SafePay has conducted 238 attacks, averaging 111 GB of stolen data per incident.

Links:

Progress on Restoring Operations

As of July 5, Ingram Micro announced it could again process and ship orders electronically across all business regions following the ransomware attack. The company confirmed that its systems were remediated with the help of third-party cybersecurity vendors, and partners could place orders via email and phone.

Ingram Micro's update emphasized that their teams were making progress in restoring functionalities, stating, “We believe the unauthorized access to our systems in connection with the incident is contained and the affected systems remediated.” The company has faced criticism from partners for the time taken to restore operations, and many had to source products from other distributors.

Links:

Operational Challenges and Updates

Ingram Micro Xvantage
Ingram Micro is working on restoring its transactional business, which was disrupted by the ransomware attack linked to SafePay. The company operates a digital platform called Ingram Micro Xvantage, which includes order tracking and personalized recommendations. While subscription orders are being processed, limitations still exist for hardware and technology orders.

The company has communicated ongoing updates about the status of its operations and confirmed that it filed with the Securities and Exchange Commission regarding the incident.

Links:

Erie Insurance Network Outage Recovery

Erie Insurance Logo
Erie Insurance has restored full business operations following a month-long network outage. The company confirmed that there is “no evidence” of any data breach during this incident. The insurer stated, “Key services and systems have been safely and securely restored,” and local agents and customer care teams are back to serving customers.

The network outage initiated by Erie was aimed at containing a potential threat. The company previously faced two class-action lawsuits alleging a ransomware group accessed their network, but their recent announcement indicated no such breaches occurred.

Links:

Explore our services or contact us for more information. For inquiries, please visit our website.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

React2Shell Vulnerability CVE-2025-55182: Exploitation Threats and Trends
React2Shell vulnerability

React2Shell Vulnerability CVE-2025-55182: Exploitation Threats and Trends

Critical React2Shell RCE vulnerability exploited by threat actors. Learn about attacker techniques, observed payloads like crypto miners, and how to protect your systems. Read now!

By Divyansh Ingle December 12, 2025 8 min read
Read full article
WinRAR CVE-2025-6218 Vulnerability Under Active Attack by Threat Groups
WinRAR vulnerability

WinRAR CVE-2025-6218 Vulnerability Under Active Attack by Threat Groups

CISA flags WinRAR CVE-2025-6218 as actively exploited. Learn about this path traversal flaw and how to protect your systems. Update now!

By Jim Gagnard December 11, 2025 3 min read
Read full article
Malicious VSCode Extensions Launch Multi-Stage Attacks and Infostealers
malicious VSCode extensions

Malicious VSCode Extensions Launch Multi-Stage Attacks and Infostealers

Beware of malicious VSCode extensions & device code phishing scams. Learn how these attacks steal credentials, capture screens, and hijack sessions. Protect yourself now!

By Alan V Gutnov December 10, 2025 6 min read
Read full article
PRC State-Sponsored BRICKSTORM Malware Targets Critical Infrastructure
BRICKSTORM malware

PRC State-Sponsored BRICKSTORM Malware Targets Critical Infrastructure

Discover how PRC state actors are using BRICKSTORM malware to gain persistent access via VMware. Learn about its advanced evasion techniques and how to defend your systems. Read now!

By Divyansh Ingle December 9, 2025 3 min read
Read full article