Ingram Micro cyber attack: IT distributor says system restoration underway – but some customers might have to wait for a return to normality
While there are still limitations on some orders, says the company, most regions are pretty much back to normal
Ingram Micro is gradually getting back on its feet after a recent cyber attack severely disrupted systems.
In an update, the company said that it's been recovering systems and implementing new security protocols and processes in the wake of the incident.
The firm revealed it can now receive and process orders once again in most regions of the world, although in some countries there are still limitations when it comes to hardware and other technology orders.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
"Ingram Micro is pleased to report that we are now operational across all countries and regions where we transact business. Our teams continue to perform at a swift pace to serve and support our customers and vendor partners," the company said in a statement.
"Our teams are now able to process and ship orders received via EDI, or electronically, as well as by phone or email across all of our business regions."
The latest regions to get back to normal are Austria, Canada, Singapore, and the Nordics, as well as the countries supported by its Miami Export business.
The company was already able to process orders for customers in Brazil, China, France, Germany, India, Italy, Portugal, Spain and the UK, albeit with limitations on hardware purchases.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
As for subscription orders, the company said customers should contact Unified Support.
Since the attack, the company has been taking some systems offline and implementing other mitigation measures.
"Based on these measures and the assistance of third-party cybersecurity experts, we believe the unauthorized access to our systems in connection with the incident is contained and the affected systems remediated," it said.
"Our investigation into the scope of the incident and affected data is ongoing."
What happened with the Ingram Micro cyber attack?
Ingram Micro first revealed it had been hit by a cyber incident last week, with responsibility for the attack claimed by the SafePay ransomware group.
SafePay is believed to have breached the IT distributor via its GlobalProtect virtual private network (VPN) platform, according to reports.
The ransomware group is an up-and-coming outfit that’s been making waves in the industry for some time now. SafePay employs a ‘double extortion’ model, encrypting systems while exfiltrating sensitive data.
This technique is used largely to increase the attacker's leverage through the threat of public exposure and operational disruption.
Research from Halcyon found that SafePay has been using a modified version of LockBit's late-2022 code.
It uses a wide range of tactics, techniques, and procedures, including exploiting known vulnerabilities in widely used enterprise software to gain initial access. It then exploits legitimate remote management tools for persistence combined with credential-harvesting tools such as Mimikatz.
Halcyon’s investigation into SafePay noted that, despite its newcomer status in the ransomware scene, the group “demonstrates a surprising level of technical maturity and operational discipline”.
This, the company added, suggests it “may be run by experienced threat actors”.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Ransomware attacks carry huge financial impacts
- Developers face a torrent of malware threats as malicious open source packages surge 188%
- A major ransomware hosting provider just got hit US with sanctions
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
The UK AI revolution: navigating the future of the intelligent enterpriseAs AI reshapes industries and societies, decision-makers in the UK face a critical choice: build a sovereign future or merely import it.
-
Turning the UK AI revolution into a sovereign realityThe UK AI Revolution documentary series posed difficult questions about AI’s hype, control, and future. Now, IT leaders must find the architectural answers
-
There’s a dangerous new ransomware variant on the block – and cyber experts warn it’s flying under the radarNews The new DeadLock ransomware family is taking off in the wild, researchers warn
-
Supply chain and AI security in the spotlight for cyber leaders in 2026News Organizations are sharpening their focus on supply chain security and shoring up AI systems
-
Veeam patches Backup & Replication vulnerabilities, urges users to updateNews The vulnerabilities affect Veeam Backup & Replication 13.0.1.180 and all earlier version 13 builds – but not previous versions.
-
NHS supplier DXS International confirms cyber attack – here’s what we know so farNews The NHS supplier says front-line clinical services are unaffected
-
LastPass hit with ICO fine after 2022 data breach exposed 1.6 million users – here’s how the incident unfoldedNews The impact of the LastPass breach was felt by customers as late as December 2024
-
Researchers claim Salt Typhoon masterminds learned their trade at Cisco Network AcademyNews The Salt Typhoon hacker group has targeted telecoms operators and US National Guard networks in recent years
-
Trend Micro issues warning over rise of 'vibe crime' as cyber criminals turn to agentic AI to automate attacksNews Trend Micro is warning of a boom in 'vibe crime' - the use of agentic AI to support fully-automated cyber criminal operations and accelerate attacks.
-
Cyber budget cuts are slowing down, but that doesn't mean there's light on the horizon for security teamsNews A new ISC2 survey indicates that both layoffs and budget cuts are on the decline

