Ingram Micro confirmed on July 5, 2025, that ransomware had been found on certain internal systems. The distributor took affected systems offline, disrupting order processing and shipping, then announced global operational restoration on July 9. Later disclosures added a separate personal-data notification covering 42,521 people and reported $6.168 million in fiscal 2025 response costs. Ingram Micro did not publicly identify the attacker, confirm a ransom payment, or verify the alleged 3.5 TB data theft.
What Ingram Micro confirmed
Ingram Micro’s July 5 statement and Form 8-K said ransomware was detected on “certain” internal systems. The company said it:
- Took affected and related systems offline as a containment measure.
- Implemented mitigation measures and began an investigation with outside cybersecurity experts.
- Notified law enforcement.
- Warned customers and vendor partners that order processing and shipping could be disrupted.
Those disclosures do not establish that every Ingram Micro operation, customer, partner system, or database was compromised. They also do not say whether a ransom was demanded, negotiated, or paid.
Outage and recovery timeline
| Date | What is documented |
|---|---|
| July 2–3, 2025 | A later Maine breach notice identifies this as the period in which the breach occurred. |
| July 5, 2025 | Ingram Micro publicly confirms ransomware, systems taken offline, an investigation, and law-enforcement notification. |
| July 8, 2025 | The company says the incident is contained and remediated. Subscription orders, renewals, and modifications are available globally; phone and email ordering is available in specified regions, while hardware and other technology orders remain limited. See the incident updates. |
| July 9, 2025, 10:00 a.m. PT | Ingram Micro reports EDI, phone, and email order processing available across its business regions, subject to remaining limitations. |
| July 9, 2025, 9:50 p.m. PT | The company announces that operations are restored globally in the countries and regions where it transacts business. |
| December 26, 2025 | The Maine notice lists this as the date the breach was discovered. |
| January 16, 2026 | Consumer notifications are dated this day in the Maine filing. |
| March 3, 2026 | Ingram Micro’s fiscal 2025 Form 10-K discloses backup restoration, response costs, notifications, and its materiality assessment. |
“Operational globally” was a broad status statement, not a technical inventory proving that every portal, API, warehouse workflow, invoice, inventory feed, or partner integration returned simultaneously.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How customers and channel partners were affected
The incident affected transactional systems, not merely the public website. Ingram Micro specifically warned about order processing and shipping. During restoration, subscription transactions returned before all hardware and technology orders.
For a reseller or vendor, a short outage can create practical problems even if it does not meet the company’s accounting definition of a material interruption:
- Orders or renewals may have been submitted twice after services returned.
- EDI or API queues may require reconciliation.
- Inventory, pricing, tax, fulfillment, invoice, return, credit, or tracking records may have lagged.
- Customer commitments can be delayed even when the distributor’s overall business remains solvent and operational.
In its 2026 10-K, Ingram Micro said the event did not cause a material interruption of operations or a material adverse effect on its financial condition or reputation. That is a securities-reporting and accounting assessment; it does not mean customers experienced no disruption.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Was personal data stolen?
A later Maine Attorney General notice records an external-system hacking breach affecting 42,521 people, including five Maine residents. It says notifications were sent January 16, 2026, and that affected individuals were offered 24 months of Experian credit monitoring and identity-protection services.
The filing refers to “persons affected,” not necessarily Ingram Micro customers or employees. The accessible notice does not establish one universal set of compromised data elements. Anyone relying on the disclosure should use the actual notification letter and Ingram Micro’s verified instructions rather than infer exposure from the ransomware event alone.
Who was responsible?
Security reporting and leak-site coverage attributed the incident to the SafePay ransomware operation. The Record reported that attribution, but Ingram Micro’s official disclosures did not name a threat actor. Reports that approximately 3.5 TB of data was stolen came from external reporting or threat-actor claims, including TechRadar’s account; the volume has not been independently established in the cited company filings.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What did the incident cost?
Ingram Micro’s fiscal 2025 10-K records $6.168 million for external services and other expenses related to the ransomware response. This is a disclosed fiscal-year accounting amount, not necessarily the event’s lifetime cost. It may not include all internal labor, lost sales, insurance recoveries, legal exposure, notification costs, or future remediation.
The filing also warns that claims, regulatory inquiries, and additional costs could arise. The company says impacted systems were restored using backups and that it notified authorities, customers, and partners.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What changed afterward?
Ingram Micro reports that it continued standardizing its disaster-recovery program, conducting penetration tests, testing backup and recovery procedures, auditing its data-security program, and maintaining active data-security certifications. These are company-reported controls, not independent proof that every control is effective.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Why a distributor outage matters to the technology supply chain
Ingram Micro connects manufacturers, cloud and software providers, resellers, managed service providers, and business customers. A disruption can therefore affect organizations that were not directly compromised through:
- Hardware fulfillment and inventory visibility.
- Cloud, licensing, and subscription renewals.
- EDI, ERP, warehouse, and billing dependencies.
- Reseller cash flow and delivery commitments.
- Vendor channel reporting and partner communications.
A separate technology company’s 2025 annual report identified Ingram Micro as a channel partner whose ransomware-related operational failure could disrupt orders and distribution. That supports the supply-chain significance, but does not prove a particular company suffered a measured loss.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What customers, resellers, and individuals should do
Customers and resellers
- Review orders, renewals, licenses, and shipments placed during July 2–9, 2025.
- Reconcile EDI and API queues and check for duplicate submissions.
- Confirm inventory, pricing, tax, fulfillment, invoice, credit, return, and tracking records.
- Contact Ingram Micro through a known account representative or trusted support channel.
- Do not click unsolicited incident-update links or provide credentials to callers or email senders claiming to represent the company.
People who received a breach notification
- Verify the notice using a known-good Ingram Micro or provider website.
- Enroll in the offered monitoring service through the verified instructions.
- Change passwords reused on other services and enable multifactor authentication.
- Monitor financial, tax, email, and identity accounts for suspicious activity.
- Expect follow-up phishing; credit monitoring does not prevent identity theft.
Security and IT leaders
- Segment identity, transactional, public-facing, and warehouse systems.
- Use offline or immutable backups and test clean restoration regularly.
- Deploy endpoint detection and response, managed monitoring, privileged-access controls, and phishing-resistant MFA.
- Design EDI/API failover and reconciliation procedures before an outage.
- Set explicit criteria for taking systems offline and prepare partner communications.
- Assess concentration risk when one distributor supports critical ordering and fulfillment.
Confirmed, externally reported, and still unknown
| Confirmed in company or regulatory filings | Reported externally | Not publicly established in the cited sources |
|---|---|---|
| Ransomware on certain internal systems | SafePay attribution | Initial access vector |
| Systems taken offline and order-processing disruption | Alleged 3.5 TB data theft | Whether a ransom was paid |
| Investigation and law-enforcement notification | Threat-actor leak claims | Complete data categories for all affected people |
| Restoration using backups | Whether every alleged stolen file was genuine | |
| 42,521 people listed in a later breach notice | Full lifetime cost and all downstream losses | |
| $6.168 million in fiscal 2025 response expenses |
Frequently Asked Questions
Did Ingram Micro pay a ransom?
No verified source cited here says whether a ransom was demanded, negotiated, or paid. The company documented recovery using backups, which does not answer that question.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Does the 42,521 figure mean 42,521 Ingram Micro customers were hacked?
No. The Maine notice lists 42,521 affected people. It does not establish that all were customers or employees, nor does the accessible filing provide a universal list of compromised data elements.
Was the entire Ingram Micro business shut down?
No. Certain internal systems were taken offline and ordering and shipping were disrupted. Ingram Micro announced global operational restoration on July 9, 2025, and later said the event did not materially interrupt operations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




