Ingram Micro cyber attack: IT distributor says system restoration underway – but some customers might have to wait for a return to normality
While there are still limitations on some orders, says the company, most regions are pretty much back to normal
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
Ingram Micro is gradually getting back on its feet after a recent cyber attack severely disrupted systems.
In an update, the company said that it's been recovering systems and implementing new security protocols and processes in the wake of the incident.
The firm revealed it can now receive and process orders once again in most regions of the world, although in some countries there are still limitations when it comes to hardware and other technology orders.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
"Ingram Micro is pleased to report that we are now operational across all countries and regions where we transact business. Our teams continue to perform at a swift pace to serve and support our customers and vendor partners," the company said in a statement.
"Our teams are now able to process and ship orders received via EDI, or electronically, as well as by phone or email across all of our business regions."
The latest regions to get back to normal are Austria, Canada, Singapore, and the Nordics, as well as the countries supported by its Miami Export business.
The company was already able to process orders for customers in Brazil, China, France, Germany, India, Italy, Portugal, Spain and the UK, albeit with limitations on hardware purchases.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
As for subscription orders, the company said customers should contact Unified Support.
Since the attack, the company has been taking some systems offline and implementing other mitigation measures.
"Based on these measures and the assistance of third-party cybersecurity experts, we believe the unauthorized access to our systems in connection with the incident is contained and the affected systems remediated," it said.
"Our investigation into the scope of the incident and affected data is ongoing."
What happened with the Ingram Micro cyber attack?
Ingram Micro first revealed it had been hit by a cyber incident last week, with responsibility for the attack claimed by the SafePay ransomware group.
SafePay is believed to have breached the IT distributor via its GlobalProtect virtual private network (VPN) platform, according to reports.
The ransomware group is an up-and-coming outfit that’s been making waves in the industry for some time now. SafePay employs a ‘double extortion’ model, encrypting systems while exfiltrating sensitive data.
This technique is used largely to increase the attacker's leverage through the threat of public exposure and operational disruption.
Research from Halcyon found that SafePay has been using a modified version of LockBit's late-2022 code.
It uses a wide range of tactics, techniques, and procedures, including exploiting known vulnerabilities in widely used enterprise software to gain initial access. It then exploits legitimate remote management tools for persistence combined with credential-harvesting tools such as Mimikatz.
Halcyon’s investigation into SafePay noted that, despite its newcomer status in the ransomware scene, the group “demonstrates a surprising level of technical maturity and operational discipline”.
This, the company added, suggests it “may be run by experienced threat actors”.
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Ransomware attacks carry huge financial impacts
- Developers face a torrent of malware threats as malicious open source packages surge 188%
- A major ransomware hosting provider just got hit US with sanctions
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
ITPro Best of Show NAB 2026 awards now open for entriesThe awards are a fantastic opportunity for companies to stand out at one of the industry's most attended shows
-
Mistral CEO Arthur Mensch thinks 50% of SaaS solutions could be supplanted by AINews Mensch’s comments come amidst rising concerns about the impact of AI on traditional software
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
-
LastPass issues alert as customers targeted in new phishing campaignNews LastPass has urged customers to be on the alert for phishing emails amidst an ongoing scam campaign that encourages users to backup vaults.

