October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Ingram Micro Confirms Cyberattack as Ransomware Disrupts Internal Operations

Ingram Micro took internal systems offline after confirming ransomware in July 2025. Later filings detail restored operations, a 42,521-person breach notice, and $6.168 million in response costs.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ingram Micro confirmed on July 5, 2025, that ransomware had been found on certain internal systems. The distributor took affected systems offline, disrupting order processing and shipping, then announced global operational restoration on July 9. Later disclosures added a separate personal-data notification covering 42,521 people and reported $6.168 million in fiscal 2025 response costs. Ingram Micro did not publicly identify the attacker, confirm a ransom payment, or verify the alleged 3.5 TB data theft.

What Ingram Micro confirmed

Ingram Micro’s July 5 statement and Form 8-K said ransomware was detected on “certain” internal systems. The company said it:

  • Took affected and related systems offline as a containment measure.
  • Implemented mitigation measures and began an investigation with outside cybersecurity experts.
  • Notified law enforcement.
  • Warned customers and vendor partners that order processing and shipping could be disrupted.

Those disclosures do not establish that every Ingram Micro operation, customer, partner system, or database was compromised. They also do not say whether a ransom was demanded, negotiated, or paid.

Outage and recovery timeline

Date What is documented
July 2–3, 2025 A later Maine breach notice identifies this as the period in which the breach occurred.
July 5, 2025 Ingram Micro publicly confirms ransomware, systems taken offline, an investigation, and law-enforcement notification.
July 8, 2025 The company says the incident is contained and remediated. Subscription orders, renewals, and modifications are available globally; phone and email ordering is available in specified regions, while hardware and other technology orders remain limited. See the incident updates.
July 9, 2025, 10:00 a.m. PT Ingram Micro reports EDI, phone, and email order processing available across its business regions, subject to remaining limitations.
July 9, 2025, 9:50 p.m. PT The company announces that operations are restored globally in the countries and regions where it transacts business.
December 26, 2025 The Maine notice lists this as the date the breach was discovered.
January 16, 2026 Consumer notifications are dated this day in the Maine filing.
March 3, 2026 Ingram Micro’s fiscal 2025 Form 10-K discloses backup restoration, response costs, notifications, and its materiality assessment.

“Operational globally” was a broad status statement, not a technical inventory proving that every portal, API, warehouse workflow, invoice, inventory feed, or partner integration returned simultaneously.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How customers and channel partners were affected

The incident affected transactional systems, not merely the public website. Ingram Micro specifically warned about order processing and shipping. During restoration, subscription transactions returned before all hardware and technology orders.

For a reseller or vendor, a short outage can create practical problems even if it does not meet the company’s accounting definition of a material interruption:

  • Orders or renewals may have been submitted twice after services returned.
  • EDI or API queues may require reconciliation.
  • Inventory, pricing, tax, fulfillment, invoice, return, credit, or tracking records may have lagged.
  • Customer commitments can be delayed even when the distributor’s overall business remains solvent and operational.

In its 2026 10-K, Ingram Micro said the event did not cause a material interruption of operations or a material adverse effect on its financial condition or reputation. That is a securities-reporting and accounting assessment; it does not mean customers experienced no disruption.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Was personal data stolen?

A later Maine Attorney General notice records an external-system hacking breach affecting 42,521 people, including five Maine residents. It says notifications were sent January 16, 2026, and that affected individuals were offered 24 months of Experian credit monitoring and identity-protection services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The filing refers to “persons affected,” not necessarily Ingram Micro customers or employees. The accessible notice does not establish one universal set of compromised data elements. Anyone relying on the disclosure should use the actual notification letter and Ingram Micro’s verified instructions rather than infer exposure from the ransomware event alone.

Who was responsible?

Security reporting and leak-site coverage attributed the incident to the SafePay ransomware operation. The Record reported that attribution, but Ingram Micro’s official disclosures did not name a threat actor. Reports that approximately 3.5 TB of data was stolen came from external reporting or threat-actor claims, including TechRadar’s account; the volume has not been independently established in the cited company filings.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What did the incident cost?

Ingram Micro’s fiscal 2025 10-K records $6.168 million for external services and other expenses related to the ransomware response. This is a disclosed fiscal-year accounting amount, not necessarily the event’s lifetime cost. It may not include all internal labor, lost sales, insurance recoveries, legal exposure, notification costs, or future remediation.

The filing also warns that claims, regulatory inquiries, and additional costs could arise. The company says impacted systems were restored using backups and that it notified authorities, customers, and partners.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What changed afterward?

Ingram Micro reports that it continued standardizing its disaster-recovery program, conducting penetration tests, testing backup and recovery procedures, auditing its data-security program, and maintaining active data-security certifications. These are company-reported controls, not independent proof that every control is effective.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Why a distributor outage matters to the technology supply chain

Ingram Micro connects manufacturers, cloud and software providers, resellers, managed service providers, and business customers. A disruption can therefore affect organizations that were not directly compromised through:

  • Hardware fulfillment and inventory visibility.
  • Cloud, licensing, and subscription renewals.
  • EDI, ERP, warehouse, and billing dependencies.
  • Reseller cash flow and delivery commitments.
  • Vendor channel reporting and partner communications.

A separate technology company’s 2025 annual report identified Ingram Micro as a channel partner whose ransomware-related operational failure could disrupt orders and distribution. That supports the supply-chain significance, but does not prove a particular company suffered a measured loss.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What customers, resellers, and individuals should do

Customers and resellers

  1. Review orders, renewals, licenses, and shipments placed during July 2–9, 2025.
  2. Reconcile EDI and API queues and check for duplicate submissions.
  3. Confirm inventory, pricing, tax, fulfillment, invoice, credit, return, and tracking records.
  4. Contact Ingram Micro through a known account representative or trusted support channel.
  5. Do not click unsolicited incident-update links or provide credentials to callers or email senders claiming to represent the company.

People who received a breach notification

  • Verify the notice using a known-good Ingram Micro or provider website.
  • Enroll in the offered monitoring service through the verified instructions.
  • Change passwords reused on other services and enable multifactor authentication.
  • Monitor financial, tax, email, and identity accounts for suspicious activity.
  • Expect follow-up phishing; credit monitoring does not prevent identity theft.

Security and IT leaders

  • Segment identity, transactional, public-facing, and warehouse systems.
  • Use offline or immutable backups and test clean restoration regularly.
  • Deploy endpoint detection and response, managed monitoring, privileged-access controls, and phishing-resistant MFA.
  • Design EDI/API failover and reconciliation procedures before an outage.
  • Set explicit criteria for taking systems offline and prepare partner communications.
  • Assess concentration risk when one distributor supports critical ordering and fulfillment.

Confirmed, externally reported, and still unknown

Confirmed in company or regulatory filings Reported externally Not publicly established in the cited sources
Ransomware on certain internal systems SafePay attribution Initial access vector
Systems taken offline and order-processing disruption Alleged 3.5 TB data theft Whether a ransom was paid
Investigation and law-enforcement notification Threat-actor leak claims Complete data categories for all affected people
Restoration using backups Whether every alleged stolen file was genuine
42,521 people listed in a later breach notice Full lifetime cost and all downstream losses
$6.168 million in fiscal 2025 response expenses

Frequently Asked Questions

Did Ingram Micro pay a ransom?

No verified source cited here says whether a ransom was demanded, negotiated, or paid. The company documented recovery using backups, which does not answer that question.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Does the 42,521 figure mean 42,521 Ingram Micro customers were hacked?

No. The Maine notice lists 42,521 affected people. It does not establish that all were customers or employees, nor does the accessible filing provide a universal list of compromised data elements.

Was the entire Ingram Micro business shut down?

No. Certain internal systems were taken offline and ordering and shipping were disrupted. Ingram Micro announced global operational restoration on July 9, 2025, and later said the event did not materially interrupt operations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.