HomeSecuritySafePay ransomware threatens to leak Ingram Micro data

SafePay ransomware threatens to leak Ingram Micro data

The SafePay ransomware gang is threatening to leak 3.5TB of data belonging to tech giant Ingram Micro, which was allegedly stolen from compromised systems earlier this month.

See also: Ransomware – Why July and August are “hot” for hackers too

SafePay Ingram Micro ransomware

Ingram Micro is one of the largest B2B (business-to-business) service providers and technology distributors worldwide, offering a wide range of solutions to resellers and managed service providers, including hardware, software, cloud services, logistics and education.

Although BleepingComputer reported on July 5 that the SafePay ransomware gang was behind the attack, the perpetrators did not officially claim responsibility until earlier this week, when they added Ingram Micro to their dark web.

The SafePay gang, which operates privately and first appeared in September 2024, has added over 260 victims to its leak website — although the actual number may be higher, as only victims who do not pay ransom are posted.

Its tactics include stealing sensitive documents before encrypting victims' systems and threatening to leak this data to the dark web if a ransom is not paid.

See also: Hackers trick victims into installing Red Ransomware

Since the beginning of the year, the SafePay gang has grown into one of the most active ransomware groups, filling the gap left by LockBit and BlackCat (ALPHV).

SafePay ransomware threatens to leak Ingram Micro data

As BleepingComputer reported earlier this month, Ingram Micro also suffered a global outage due to the SafePay ransomware attack, with employees being asked to work from home and the company's website and ordering systems being taken down.

BleepingComputer has since learned that the company is working to restore VPN access for its employees and has proceeded with a full password reset and company-wide multi-factor authentication (MFA) activation.

Ingram Micro responded quickly to the incident, restoring many of its internal systems and platforms within days, allowing employees to regain broader access to the ordering system. However, the company has yet to officially confirm that the SafePay ransomware was behind the breach, nor whether the attackers were able to steal data from its compromised systems.

See also: Hackers target SharePoint servers with Warlock ransomware

Such incidents once again highlight how vulnerable even leading global companies are to organized digital threats, as well as the importance of prevention and continuous surveillance.

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS