Yes—Ingram Micro reported that it was back online after the ransomware incident. The distributor said it contained and remediated the affected systems by July 8, 2025, resumed order processing through alternate channels on July 9, and was operational across all countries and regions where it transacted business later that day.
What happened to Ingram Micro?
On July 5, 2025, Ingram Micro said it had identified ransomware on certain internal systems. The company proactively took systems offline, started an investigation with cybersecurity specialists, notified law enforcement and began restoring order-processing and shipping operations.
The incident initially affected customers’ ability to place online orders. Ingram Micro did not publish an independently verified figure for records affected, ransom demanded, downtime or total financial loss.
When did Ingram Micro restore operations?
| Date and time | What Ingram Micro reported |
|---|---|
| July 5, 2025 | Ransomware was identified on certain internal systems; affected systems were taken offline while the company investigated and contained the incident. |
| July 8, 2025 | Ingram Micro said it believed unauthorized access was contained and the affected systems remediated, with help from third-party cybersecurity experts. |
| July 9, 2025, 10:00 a.m. Pacific Time | Teams could process and ship orders received through EDI, phone or email across all business regions. |
| July 9, 2025, 9:50 p.m. Pacific Time | The company said it was operational across all countries and regions where it transacted business. |
| July 10, 2025 | Dark Reading reported that Ingram Micro’s websites were operating globally. |
How did Ingram Micro recover?
Containment and remediation
Ingram Micro said it activated its incident-response and business-continuity procedures, isolated affected systems and worked with outside cybersecurity experts. Its July 8 update said the unauthorized access connected with the incident was believed to be contained and the affected systems remediated.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Restoration from backups
In a later annual-report filing, Ingram Micro said it restored impacted systems using backups. The filing also described spending on investigation, remediation, system restoration and improvements to its cybersecurity program.
Alternate order channels
Before the company announced full regional availability, customers could submit orders through EDI, phone and email. That fallback allowed order processing and shipping to resume while online systems were being restored.
Was SafePay behind the attack?
SafePay was not confirmed as the attacker by Ingram Micro. Dark Reading reported that BleepingComputer had seen an alleged SafePay ransom note, but said the responsible ransomware group remained unclear and that Ingram Micro had not appeared on the group’s leak site at the time of publication. SafePay should therefore be treated as an unverified attribution, not an established fact.
What is known about the business impact?
Ingram Micro’s filing said the incident did not cause a material interruption of operations. It nevertheless acknowledged costs for response and recovery and warned that a future cybersecurity incident could materially affect the company. The filing did not state a dollar amount for this incident.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Confirmed: ransomware was found on certain internal systems, systems were taken offline, backups were used for restoration and operations were reported as globally restored on July 9, 2025.
- Not publicly established: the ransom amount, the number of records or systems affected, the exact duration of the online-order outage and a confirmed attacker identity.
What customers and business partners should take from the incident
Order status
Ingram Micro’s own updates indicate that order processing and shipping resumed through EDI, phone and email at 10:00 a.m. Pacific Time on July 9, followed by broader operational availability later that evening. Businesses with delayed orders should verify status directly through their normal Ingram Micro account or sales contacts rather than assume that every transaction queued during the outage completed automatically.
Resilience lessons
The recovery sequence highlights three practical controls for companies that depend on a distributor or other technology provider: maintain tested backups, keep alternate transaction channels available and define clear incident-communication procedures. Ingram Micro’s disclosure shows that having those channels helped it restore order flow before all online functions were fully available.
Rank #4
Bottom line
Ingram Micro reported that it was up and running after the July 2025 ransomware attack: affected systems were described as contained and remediated on July 8, orders could be processed through EDI, phone and email on July 9, and the company announced operations across all its business regions that night. The company says backups supported system restoration, while claims about SafePay remain unconfirmed.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.




