Ingram Micro Cyberattack Triggers Multi-Day IT Outage and Major Revenue Losses
Ingram Micro, a global technology distributor and IT services company, suffered a cyberattack resulting in global outage and employees working from home. The attack knocked key IT systems offline — including ordering platforms like Xvantage and license management tools — which meant that customers and partners could not place, track or manage orders for IT products and services during the outage. The company restored many of the internal systems and platforms impacted by the attack within days and performed a company-wide password and Multi-Factor Authentication (MFA) reset to restore operations.
The SafePay ransomware gang threatened to leak 3.5TB of data on July 30, 2025.
Incident Date
July 3, 2025
Location
Estimated Cost
Est. >$136 million in lost revenue per day. Systems went down July 3 and fully returned to service July 10.
References
- Inside the Ingram Micro Ransomware Attack: Lessons in Zero Trust
- The Ingram Micro Ransomware Attack: Lessons Learned
- Ransomware Attack At IT Distributor
- SafePay ransomware threatens to leak 3.5TB of Ingram Micro data
- Ingram Micro starts restoring systems after ransomware attack
- Ingram Micro outage caused by SafePay ransomware attack
Impacts
OT IT Privacy
