Ingram Micro, one of the world’s largest distributors of technology products and services, was hit by a major ransomware attack that caused widespread outages ahead of the 4th of July. The attack, said to be linked to the infamous SafePay, caused the immediate collapse of key infrastructure at the company, including its online ordering systems and official website. However, since the beginning of the week, Ingram Micro has begun restoring its systems and operations.

The company's response and recovery path
After confirming the incident on Saturday, Ingram Micro began the process of recovering critical business functions. By Monday, it had already restored phone and email in select countries, and on Tuesday it expanded to key markets, including the US, Canada, India and China.
See also: M&S: Confirms it was targeted by DragonForce ransomware
According to an official announcement from the company, subscription orders – such as renewals and modifications – are now available globally, while the ability to place orders via phone/email has been restored in countries such as the United Kingdom, Germany, France, Italy and Brazil. However, restrictions remain on the processing of physical products and technological equipment, with Ingram Micro noting that it will provide further clarification as the system stabilizes.
Enhanced security measures and access re‑initialization
In an effort to enhance security following the incident, the company has implemented a full password reset and multi-factor authentication (MFA) for all of its staff. At the same time, it has begun gradually restoring access to VPNs and internal systems, many of which are related to orders, logistics, and customer support.
Although Ingram Micro appears to be recovering quickly from the cyberattack, full recovery is still underway, with employees gradually returning to their physical offices and the company remaining on alert.
Unanswered questions and concerns about data leakage
So far, the company has not publicly confirmed whether there was a breach or data theft, and the SafePay ransomware group has not officially claimed responsibility. However, according to BleepingComputer – which first revealed the attack by the SafePay gang – the group in question has a history of extortion using the double threat method: encrypting and stealing data and threatening to make it public if a ransom is not paid.
See also: BERT Ransomware disables ESXi virtual machines
In the event that no agreement is reached between the two parties, a potential leak or sale of data could occur in the coming days or weeks, with unforeseen consequences for Ingram Micro customers, associates and business partners.

What does this mean for the market
The incident highlights once again the fragile nature of cybersecurity at critical links in the global technology supply chain. With giant companies like Ingram Micro being targeted, it highlights the need for more stringent security policies, risk management and disaster recovery plans.
See also: Automation and vulnerability exploitation are boosting ransomware
Ransomware protection
- Stay up to date on the latest ransomware trends and tactics used by attackers
- Implement multi-factor authentication (MFA) for all user accounts
- Enable firewall on all devices connected to your network
- Keep sensitive data encrypted
- Update all your devices and systems with the latest security patches
- Conduct regular security audits and penetration testing
- Use strong, unique passwords and change them regularly.
- Limit user access to only necessary systems and information
- Consider using email security solutions for additional protection against phishing attacks
- Have a recovery plan to quickly restore systems in the event of an attack
- Enable the display of file extensions
- Invest in advanced protection solutions
- Use sandboxing for email attachments
- Keep backup copies of your data
Source: www.bleepingcomputer.com
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
