Ingram Micro Recovers from Ransomware Attack, Restores Operations

Edward Zhou
Edward Zhou

CEO & Co-Founder

 
July 17, 2025
3 min read

Ingram Micro Ransomware Attack

Ingram Micro

Ingram Micro reported a ransomware incident on July 4 that targeted its internal systems. The company took affected systems offline immediately after discovering the ransomware. Ingram Micro stated, “The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.” The company is working to restore operations while apologizing for disruptions experienced by customers and vendor partners.

Ingram Micro reported $48 billion in sales last fiscal year, operating as a key connector between organizations and technology manufacturers. The attack was noted to be linked to the SafePay ransomware gang, which has been responsible for multiple attacks, including on other organizations such as government contractor Conduent.

Further details from cybersecurity expert Rebecca Moody indicate that SafePay has conducted 238 attacks, averaging 111 GB of stolen data per incident.

Links:

Progress on Restoring Operations

As of July 5, Ingram Micro announced it could again process and ship orders electronically across all business regions following the ransomware attack. The company confirmed that its systems were remediated with the help of third-party cybersecurity vendors, and partners could place orders via email and phone.

Ingram Micro's update emphasized that their teams were making progress in restoring functionalities, stating, “We believe the unauthorized access to our systems in connection with the incident is contained and the affected systems remediated.” The company has faced criticism from partners for the time taken to restore operations, and many had to source products from other distributors.

Links:

Operational Challenges and Updates

Ingram Micro Xvantage

Ingram Micro is working on restoring its transactional business, which was disrupted by the ransomware attack linked to SafePay. The company operates a digital platform called Ingram Micro Xvantage, which includes order tracking and personalized recommendations. While subscription orders are being processed, limitations still exist for hardware and technology orders.

The company has communicated ongoing updates about the status of its operations and confirmed that it filed with the Securities and Exchange Commission regarding the incident.

Links:

Erie Insurance Network Outage Recovery

Erie Insurance Logo

Erie Insurance has restored full business operations following a month-long network outage. The company confirmed that there is “no evidence” of any data breach during this incident. The insurer stated, “Key services and systems have been safely and securely restored,” and local agents and customer care teams are back to serving customers.

The network outage initiated by Erie was aimed at containing a potential threat. The company previously faced two class-action lawsuits alleging a ransomware group accessed their network, but their recent announcement indicated no such breaches occurred.

Links:

Explore our services or contact us for more information. For inquiries, please visit our website.

Edward Zhou
Edward Zhou

CEO & Co-Founder

 

CEO & Co-Founder of Gopher Security, leading the development of Post-Quantum cybersecurity technologies and solutions.

Related News

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture
zero trust architecture maturity model

New Industry Report Defines Enterprise Maturity Benchmarks for Zero Trust Identity and Access Architecture

Discover how the new Zero Trust Maturity Model is replacing perimeter-based security with identity-centric frameworks for modern enterprise protection.

By Alan V Gutnov August 5, 2026 5 min read
common.read_full_article
Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking
CVE-2026-59726

Critical Ruflo MCP Bridge Vulnerability Enables Arbitrary Command Execution and AI Agent Hijacking

Urgent: CVE-2026-59726 'RufRoot' vulnerability exposes Ruflo AI to RCE and agent hijacking. Update to v3.16.3 immediately to prevent total system compromise.

By Divyansh Ingle August 4, 2026 4 min read
common.read_full_article
Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access
zero trust architecture maturity model

Rising Endpoint Security Breaches Drive Shift Toward Zero-Trust Architectures for Global Enterprise Remote Access

Discover why Zero Trust is the new baseline for enterprise security. Learn how to combat rising endpoint breaches and secure a distributed, hybrid workforce.

By Brandon Woo August 3, 2026 5 min read
common.read_full_article
NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration
NIST post-quantum cryptography standards

NIST Lead Andrew Regenscheid Details Strategic Roadmap for Enterprise Post-Quantum Cryptography Migration

Learn how to migrate to NIST PQC standards. Expert Andrew Regenscheid details strategies against 'harvest now, decrypt later' quantum threats in 2026.

By Alan V Gutnov July 31, 2026 4 min read
common.read_full_article