October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Ingram Micro Back Online After July 2025 Ransomware Attack

Ingram Micro reported containment on July 8, 2025, resumed orders through EDI, phone and email on July 9, and restored operations worldwide later that day. Backups supported recovery; SafePay attribution remains unconfirmed.
From TheFinanceBase Team3 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—Ingram Micro reported that it was back online after the ransomware incident. The distributor said it contained and remediated the affected systems by July 8, 2025, resumed order processing through alternate channels on July 9, and was operational across all countries and regions where it transacted business later that day.

What happened to Ingram Micro?

On July 5, 2025, Ingram Micro said it had identified ransomware on certain internal systems. The company proactively took systems offline, started an investigation with cybersecurity specialists, notified law enforcement and began restoring order-processing and shipping operations.

The incident initially affected customers’ ability to place online orders. Ingram Micro did not publish an independently verified figure for records affected, ransom demanded, downtime or total financial loss.

When did Ingram Micro restore operations?

Date and time What Ingram Micro reported
July 5, 2025 Ransomware was identified on certain internal systems; affected systems were taken offline while the company investigated and contained the incident.
July 8, 2025 Ingram Micro said it believed unauthorized access was contained and the affected systems remediated, with help from third-party cybersecurity experts.
July 9, 2025, 10:00 a.m. Pacific Time Teams could process and ship orders received through EDI, phone or email across all business regions.
July 9, 2025, 9:50 p.m. Pacific Time The company said it was operational across all countries and regions where it transacted business.
July 10, 2025 Dark Reading reported that Ingram Micro’s websites were operating globally.

How did Ingram Micro recover?

Containment and remediation

Ingram Micro said it activated its incident-response and business-continuity procedures, isolated affected systems and worked with outside cybersecurity experts. Its July 8 update said the unauthorized access connected with the incident was believed to be contained and the affected systems remediated.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Restoration from backups

In a later annual-report filing, Ingram Micro said it restored impacted systems using backups. The filing also described spending on investigation, remediation, system restoration and improvements to its cybersecurity program.

Alternate order channels

Before the company announced full regional availability, customers could submit orders through EDI, phone and email. That fallback allowed order processing and shipping to resume while online systems were being restored.

Was SafePay behind the attack?

SafePay was not confirmed as the attacker by Ingram Micro. Dark Reading reported that BleepingComputer had seen an alleged SafePay ransom note, but said the responsible ransomware group remained unclear and that Ingram Micro had not appeared on the group’s leak site at the time of publication. SafePay should therefore be treated as an unverified attribution, not an established fact.

What is known about the business impact?

Ingram Micro’s filing said the incident did not cause a material interruption of operations. It nevertheless acknowledged costs for response and recovery and warned that a future cybersecurity incident could materially affect the company. The filing did not state a dollar amount for this incident.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Confirmed: ransomware was found on certain internal systems, systems were taken offline, backups were used for restoration and operations were reported as globally restored on July 9, 2025.
  • Not publicly established: the ransom amount, the number of records or systems affected, the exact duration of the online-order outage and a confirmed attacker identity.

What customers and business partners should take from the incident

Order status

Ingram Micro’s own updates indicate that order processing and shipping resumed through EDI, phone and email at 10:00 a.m. Pacific Time on July 9, followed by broader operational availability later that evening. Businesses with delayed orders should verify status directly through their normal Ingram Micro account or sales contacts rather than assume that every transaction queued during the outage completed automatically.

Resilience lessons

The recovery sequence highlights three practical controls for companies that depend on a distributor or other technology provider: maintain tested backups, keep alternate transaction channels available and define clear incident-communication procedures. Ingram Micro’s disclosure shows that having those channels helped it restore order flow before all online functions were fully available.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Bottom line

Ingram Micro reported that it was up and running after the July 2025 ransomware attack: affected systems were described as contained and remediated on July 8, orders could be processed through EDI, phone and email on July 9, and the company announced operations across all its business regions that night. The company says backups supported system restoration, while claims about SafePay remain unconfirmed.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.