The SafePay ransomware gang is threatening to leak 3.5TB of data belonging to tech giant Ingram Micro, which was allegedly stolen from compromised systems earlier this month.
See also: Ransomware – Why July and August are “hot” for hackers too

Ingram Micro is one of the largest B2B (business-to-business) service providers and technology distributors worldwide, offering a wide range of solutions to resellers and managed service providers, including hardware, software, cloud services, logistics and education.
Although BleepingComputer reported on July 5 that the SafePay ransomware gang was behind the attack, the perpetrators did not officially claim responsibility until earlier this week, when they added Ingram Micro to their dark web.
The SafePay gang, which operates privately and first appeared in September 2024, has added over 260 victims to its leak website — although the actual number may be higher, as only victims who do not pay ransom are posted.
Its tactics include stealing sensitive documents before encrypting victims' systems and threatening to leak this data to the dark web if a ransom is not paid.
See also: Hackers trick victims into installing Red Ransomware
Since the beginning of the year, the SafePay gang has grown into one of the most active ransomware groups, filling the gap left by LockBit and BlackCat (ALPHV).

As BleepingComputer reported earlier this month, Ingram Micro also suffered a global outage due to the SafePay ransomware attack, with employees being asked to work from home and the company's website and ordering systems being taken down.
BleepingComputer has since learned that the company is working to restore VPN access for its employees and has proceeded with a full password reset and company-wide multi-factor authentication (MFA) activation.
Ingram Micro responded quickly to the incident, restoring many of its internal systems and platforms within days, allowing employees to regain broader access to the ordering system. However, the company has yet to officially confirm that the SafePay ransomware was behind the breach, nor whether the attackers were able to steal data from its compromised systems.
See also: Hackers target SharePoint servers with Warlock ransomware
Such incidents once again highlight how vulnerable even leading global companies are to organized digital threats, as well as the importance of prevention and continuous surveillance.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
