October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run ScanOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Ingram Micro Confirms July 2025 Ransomware Attack, Restores Order Processing

Ingram Micro confirmed ransomware on July 5, 2025, disrupting internal systems and order fulfillment. Later updates showed staged recovery, while company filings disclosed continuing incident-related costs.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ingram Micro confirmed on July 5, 2025, that ransomware had affected certain internal systems, forcing the technology distributor to take systems offline and disrupt ordering, licensing, logistics, and fulfillment workflows. The company said it was working to restore the systems needed to “process and ship orders.”

Operations were restored in stages, with orders later accepted through EDI, phone, and email. Subsequent filings disclosed millions of dollars in investigation, remediation, restoration, and cybersecurity costs. However, the initial outage should not be confused with proof that every customer system or Microsoft 365 tenant was compromised.

What Ingram Micro officially confirmed

Ingram Micro’s July 5, 2025 statement said the company had identified ransomware on “certain” internal systems. It said it had:

  • Taken affected systems offline.
  • Implemented mitigation measures.
  • Engaged outside cybersecurity experts.
  • Notified law enforcement.
  • Begun restoring systems required to process and ship orders.

The company apologized to customers, vendor partners, and other affected parties. Its initial announcement did not identify the attackers, disclose the initial access method, say whether a ransom was paid, or establish the full scope of any data theft.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the outage and recovery

Date What happened
July 3, 2025 Ingram Micro later said it detected a cybersecurity incident involving some internal systems.
July 4, 2025 Reporting described a global outage affecting public websites and internal systems.
July 5, 2025 Ingram Micro publicly confirmed the ransomware incident, system shutdown, investigation, law-enforcement notification, and recovery effort. The company’s SEC filing documented the disclosure.
July 7–9, 2025 Some ordering functions returned through phone and email. Subscription orders, including renewals and modifications, were processed centrally through support channels.
By July 11, 2025 Reporting based on company updates said orders received through EDI, phone, and email could be processed and shipped across the company’s regions. Ingram Micro also said it believed unauthorized access had been contained and affected systems remediated.
2026 filings Incident-related external-service, remediation, restoration, and cybersecurity-enhancement costs continued to appear in company filings.

Recovery was staged. The return of one ordering channel did not necessarily mean that every portal, licensing platform, warehouse workflow, or internal system was restored at the same time.

Which Ingram Micro services were disrupted?

Contemporary reporting described disruption to Ingram Micro’s public websites, internal systems, ordering processes, and logistics workflows. Reports also identified the Xvantage distribution platform and the Impulse licensing platform as affected or inaccessible.

The practical distinction matters:

  • System unavailability: A portal or application cannot be accessed.
  • Operational disruption: A quote, order, renewal, shipment, or fulfillment task cannot proceed normally.
  • Data compromise: Information was accessed or exfiltrated.
  • Credential compromise: Passwords, tokens, or other authentication material may have been exposed.

These are not interchangeable. An outage can prevent customers from placing or checking orders without proving that customer data was stolen.

Why the outage had supply-chain consequences

Ingram Micro is a technology distributor and intermediary connecting hardware manufacturers, software and cloud providers, resellers, managed service providers, and business customers. Its systems support more than simple online purchasing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

A disruption can delay quotes and special pricing, hardware procurement, vendor-direct shipments, subscription renewals, license modifications, deployment schedules, and customer support. Even when a manufacturer or cloud service remains online, a reseller may be unable to complete the commercial or fulfillment steps needed to deliver that service.

Who was behind the attack?

BleepingComputer reported that the incident was associated with the SafePay ransomware operation and that the group later claimed responsibility. Ingram Micro did not name SafePay in its initial official statement, so the attribution should be treated as reported cybersecurity intelligence rather than an initial company-confirmed fact.

There were also reports that attackers may have entered through Palo Alto Networks’ GlobalProtect VPN. That access theory was not established as a proven product vulnerability or vendor-caused breach in the reviewed record. Ingram Micro has not publicly confirmed that explanation in the sources cited here.

Was customer or employee data stolen?

The July 5 announcement confirmed ransomware and system isolation, but it did not provide a complete public account of data access or exfiltration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Later reporting said approximately 42,000 individuals were affected. That figure should remain attributed to subsequent reporting unless readers are directed to a later official breach notification or regulatory record establishing the details. The available record does not establish that customer Microsoft 365 tenants were compromised merely because many managed service providers used Ingram Micro for Microsoft cloud licensing or delegated administration.

Readers should also avoid assuming that “systems remediated” means every service was fully restored or that no information was accessed. Those questions require the latest official notification applicable to the affected organization.

What customers, MSPs, and resellers should do

  1. Use verified contact channels. Follow contact details published in official Ingram Micro communications or use a known account representative. Do not trust links in unexpected order-status messages.
  2. Verify urgent requests independently. Confirm payment-routing changes, emergency orders, and bank-account updates through a previously known phone number or representative.
  3. Limit sensitive information in manual orders. Do not send passwords, payment details, API keys, or unnecessary customer data by unverified email.
  4. Reconcile manually submitted orders. Compare email, phone, and EDI submissions with restored portal records to identify duplicates, changed pricing, missing renewals, or delayed shipments.
  5. Review cloud and administrator activity. Organizations using Ingram Micro-linked licensing or delegated administration should review relevant logs and privileged-account activity.
  6. Ask about notification status. Contact Ingram Micro through an authenticated channel to determine whether your organization or its data was included in a later breach notification.
  7. Reset credentials deliberately. Rotate passwords or tokens when supported by documented incident-response guidance. Indiscriminate resets during an outage can create additional service failures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Financial impact disclosed by Ingram Micro

Ingram Micro’s 2025 Form 10-K disclosed $6.168 million in incident-related external-service and other costs for fiscal 2025. The company’s 2026 Form 10-Q disclosed an additional $1.122 million in related costs for the 13 weeks ended June 27, 2026.

These figures should not automatically be presented as the final lifetime cost. They represent amounts disclosed for the specified reporting periods and primarily covered external services and other incident-related expenses.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In its annual-report disclosures, Ingram Micro said the incident did not materially interrupt operations or materially and adversely affect its business, financial condition, or reputation. That is the company’s financial-reporting characterization, not a claim that customers experienced no disruption or that the incident carried no continuing risk.

Current status

Based on the record through August 18, 2026, Ingram Micro had moved beyond the initial global outage and restored core order-processing capabilities through multiple channels. Incident-related remediation and cybersecurity costs continued to appear in filings.

The full data-impact picture should be based on the latest official notice available for the relevant organization. The record does not support claims that a ransom was paid, that every Ingram Micro system was compromised, or that all customer cloud tenants were accessed.

What the incident means for business continuity

The event illustrates why distributors and other intermediaries are high-impact ransomware targets. A single compromise can interrupt the commercial links between many businesses without directly encrypting each customer’s network.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

MSPs and resellers should maintain alternate procurement routes for critical hardware, preserve offline or independently accessible records of open orders and entitlements, segment distributor integrations, restrict delegated cloud administration, and establish authenticated out-of-band contacts for emergencies. Backups should be isolated, protected from ordinary domain credentials, and tested through actual restoration exercises.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$62.31
SaleBestseller No. 3

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.