SYS::ONLINE
Wasteland.
Briefs2302
Issues25
SinceFeb 2026
LIVE
█ Ransomware INGRAM-MICRO-SAFEP 2026-08-28

Ingram Micro: SafePay Ransomware Freezes Global Order Processing

"Ingram Micro Holding Corporation (NYSE: INGM), a technology distributor with roughly $48 billion in annual net sales, was hit by ransomware on July 2 and 3, 2025, in an intrusion that took order processing offline…"

Ingram Micro Holding Corporation (NYSE: INGM), a technology distributor with roughly $48 billion in annual net sales, was hit by ransomware on July 2 and 3, 2025, in an intrusion that took order processing offline worldwide for roughly four business days. The company confirmed ransomware on internal systems on July 5, 2025, filed a Form 8-K with the SEC on July 7, and reported operations restored across all countries and regions on July 9. Ingram Micro later quantified the damage at 1% to 1.5% of third-quarter fiscal 2025 net sales, or roughly $126 million to $189 million, and in January 2026 notified 42,521 employees, former employees, and job applicants that their personal data was in files taken during the two-day window. The SafePay ransomware group listed Ingram Micro on its leak site. Note that every source available for this brief is secondary or aggregator-tier reporting, not the company's own statement or filing text, so the attribution and access-vector details below should be read as reported rather than confirmed.

What Happened

Accounts converge on a compressed intrusion window of July 2 to July 3, 2025, with unauthorized access to internal file repositories during that period. Adaptive Security reports that systems began failing around 8 a.m. Eastern on July 3, with ransom notes appearing on employee screens. Two platforms that resellers and MSPs depend on daily went down: Xvantage, used for quotes and orders, and Impulse, used for software license activation. The public website went offline and staff were pushed to remote work.

Ingram Micro publicly confirmed a cybersecurity incident on July 5 and stated it had proactively taken certain systems offline as a containment measure. The 8-K followed on July 7. Recovery was staged rather than instantaneous: reporting describes the website returning first, subscription orders resuming July 8, and full global restoration on July 9.

Accounts differ on precisely when the company can be said to have been "hit." One Adaptive Security piece dates the attack to July 3, 2025; its companion piece and the Maine notification data both anchor the file-access window at July 2 to 3. The distinction is likely detonation date versus intrusion window rather than a genuine factual conflict, but it is worth flagging.

Attribution is reported, not company-confirmed. Multiple sources state that BleepingComputer first tied the outage to SafePay and that the group later listed Ingram Micro on its leak site, with one Adaptive Security account noting the leak-site claim came 26 days after detection. Sources disagree on whether Ingram Micro ever acknowledged the actor: one aggregator states the SafePay involvement "was only confirmed by Ingram Micro later," while another states the company "hasn't confirmed SafePay's involvement," and Adaptive Security states flatly that Ingram Micro has never named a threat actor. The weight of reporting favors the latter reading: no company confirmation of the actor.

What Was Taken

The firmest number in the entire record is the notification count. In a January 20, 2026 filing with the Maine Attorney General, Ingram Micro reported that 42,521 current employees, former employees, and job applicants had personal information exposed. Lower-precision sources round this to "approximately 42,000" or "42,000+"; treat 42,521 as the filed figure and the rounded numbers as restatements of it, not as an independent count.

The exposed data categories are consistent across sources and are severe for an employee population: names, contact details, dates of birth, Social Security numbers, driver's license and passport numbers, and employment records. This is a full identity-theft package, not a marketing-list leak.

Exfiltration volume is where the sourcing thins out considerably. One aggregator reports that SafePay itself boasted of stealing 3.5TB of documents, which is an actor claim relayed through a low-tier source and should be treated as unverified. Separately, Comparitech researcher Rebecca Moody is quoted as having tracked 238 SafePay attacks over several months with an average of 111 gigabytes stolen per victim. The 3.5TB claim sits roughly 30 times above that group average, which is the kind of gap that usually signals actor inflation, a genuinely outsized haul at a very large enterprise, or different counting methodology. No source reconciles the two.

Notably, no source in this set alleges compromise of reseller or customer data. The disclosed exposure is employee and applicant records; the customer-side damage was operational.

Why It Matters

The economics of this incident invert the usual argument for ransomware spend. Ingram Micro's own quantified impact of roughly $126 million to $189 million in lost third-quarter net sales dwarfs the $350,000 reported settlement of the resulting data-breach litigation by a factor of several hundred. For enterprises at this scale, the case for ransomware investment is a business-continuity case, not a privacy-liability case. Boards that model ransomware risk primarily as regulatory and class-action exposure are modeling the wrong tail.

The second lesson is supply-chain concentration. Ingram Micro sits upstream of tens of thousands of resellers and MSPs; reporting cites more than 161,000 customers and over 23,500 employees. When Xvantage and Impulse went dark, downstream partners could not quote, order, or activate software licenses. Adaptive Security estimates that at $48 billion in annual sales, Ingram Micro moves roughly $130 million of business on an average day. Four business days of frozen order processing is therefore a supply-chain event, not merely a victim-company event, and every partner that treated the distributor's portal as always-available inherited the outage without any compromise of their own.

Third, the disclosure lag drew criticism. The intrusion occurred in July 2025; individual notifications went out in January 2026, roughly six months later. Multiple sources frame this as the controversy of the case.

The Attack Technique

Ingram Micro has not publicly disclosed the initial access vector. That is the baseline fact, and one source explicitly carries a clarification to that effect.

The most detailed reported account comes from Adaptive Security, which states that SafePay accessed the network through Palo Alto Networks GlobalProtect using a valid VPN username and password rather than exploiting a software flaw, with researchers attributing the credential to theft, guessing, weakness, or reuse. The same source notes that SafePay has used similar access against more than 220 other organizations, frequently targeting remote-access systems lacking multi-factor authentication. A second source references the "reported credential-based access path" while explicitly declining to confirm it, and notes that Palo Alto Networks issued its own statement on the matter, though the text of that statement is truncated in the available material.

This sits in tension with a separate SafePay threat profile published in August 2026, which characterizes the group's initial access as historically favoring perimeter device exploitation of VPNs and firewalls plus compromised RMM tooling, with recent intelligence indicating a heavy pivot toward exploiting CVEs in edge appliances. Both paths point at the same asset class, the internet-facing remote-access edge, but they imply different controls. Valid-credential abuse is defeated by MFA and conditional access; CVE exploitation is defeated by patch velocity. For the Ingram Micro case specifically, the credential-abuse account is the one with named-researcher sourcing behind it, but it remains uncorroborated by the victim.

On the actor itself, the sources agree on the core profile. SafePay emerged in late 2024, with one source dating it to September 2024. It runs strict double extortion, encrypting systems while exfiltrating data and threatening publication, a model Halcyon researcher Anthony Freed is quoted describing. The August 2026 profile characterizes SafePay as a ransomware-as-a-service operation with an affiliate network, ransom demands typically between $500,000 and $5 million scaled to victim revenue, publication deadlines of roughly three to seven days past the payment window, and an average dwell time of only three to five days between breach and encryption. That short dwell time matches what happened here: a two-day file-access window followed immediately by detonation. Sources also position SafePay as absorbing volume left behind by LockBit and BlackCat/ALPHV, and caution that leak-site victim counts undercount reality because only non-paying victims are ever posted.

What Organizations Should Do

  1. Enforce phishing-resistant MFA on every remote-access path, with no exceptions. The reported vector here was a valid credential against a GlobalProtect gateway. Inventory every VPN, SSL-VPN, RDP gateway, and RMM console; any that authenticates on a password alone should be treated as already compromised. Prefer FIDO2 or certificate-based authentication over push or OTP, which SafePay-class actors defeat with fatigue and relay techniques.

  2. Patch and harden the internet-facing edge on a compressed cycle. Because the SafePay profile also describes a pivot to CVE exploitation in edge appliances, MFA alone does not close this class. Treat VPN and firewall firmware as tier-zero patching, subscribe to the vendor advisories for every edge appliance you run, and remove management interfaces from public exposure entirely.

  3. Assume three to five days of dwell time and instrument for it. That window is your entire detection budget. Alert on anomalous VPN logins by geography, impossible travel, and first-time device, and specifically on large outbound transfers from file repositories. At an average of 111GB per victim by Comparitech's count, exfiltration at this scale is visible in egress telemetry if anyone is watching it.

  4. Rehearse the manual fallback for revenue-critical platforms. Ingram Micro's outage hurt because quoting, ordering, and license activation had no offline path. Identify the two or three systems that stop money moving when they stop, and build and test a degraded-mode process for each. Four business days is a long time to discover you do not have one.

  5. Segment and monitor the file repositories holding HR and applicant data. The exposed records here were employee and job-applicant files, including SSNs, passport and driver's license numbers. These repositories are rarely business-critical for daily operations, which makes them good candidates for aggressive access restriction, encryption at rest with separated key custody, and retention purges of applicant data that no longer needs to exist.

  6. Treat your distributors and upstream suppliers as part of your own continuity plan. If a single distributor's portal outage would stop your ability to quote or fulfill, that is your risk to mitigate, not theirs. Establish secondary sourcing, keep offline copies of license and entitlement records, and put supplier-outage scenarios into your tabletop rotation.

  7. Pre-decide your disclosure timeline. The six-month gap between incident and individual notification generated a meaningful share of the reputational damage in this case, independent of the technical facts. Know your regulatory clocks and your forensic dependencies before you need them.

Sources: Ingram Micro Ransomware Attack: How Did It Happen | Ingram Micro: The Ransomware Attack That Ran Through One Login Ada... | Ingram Micro: Ransomware Hit A $48B Supply Chain Kyle Lowry (duqCAO... | Ingram Micro Ransomware Attack: 42,000+ People Affected Cyber Secu... | Ransomware Attack: Ingram Micro's Massive Breach Affects 42,000 Peo... | Ingram Micro Outage Caused By Safepay Ransomware Attack | Form 8-K - Current report | SAFEPAY Ransomware: Global Manufacturing & Tech Targeted — Critical...