Irvine, USA – Mumbai, India: Global IT distribution company Ingram Micro confirms ransomware attack led to outage of its global operations, according to an issued statement. The company has officially confirmed it was the victim of a ransomware attack that has caused widespread outages across its systems and disrupted partner and customer services globally.
The incident began on Thursday, July 3, when key portals and online ordering systems became unavailable, leaving many of Ingram’s global partners in the dark for over 24 hours. In an official statement issued over the weekend, the company acknowledged the disruption was the result of a ransomware infection on internal systems.
Ingram Micro confirms ransomware attack
“Ingram Micro recently identified ransomware on certain of its internal systems,” the company confirmed in an issued statement on cyber incident.
Following this ransomware attack, the company has taken security measure as well as initiated an investigation.
“Promptly after learning of the issue, the company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement,” the statement said.
In response to the ransomware attack, the company said it is working diligently to restore the affected systems.
“Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the company apologizes for any disruption this issue is causing its customers, vendor partners, and others,” the statement concluded.
Suspected threat actor
A few media reports and cybersecurity analysts suggest the SafePay ransomware group may be behind the attack, citing encrypted employee workstations and interference with systems such as GlobalProtect VPN, used internally for remote access.
Ingram’s AI-powered Xvantage platform and the Impulse license provisioning platform, are among the internal systems that are impacted by the ransomware, reported Bleeping Computer.
However, the company has not confirmed the group responsible or the potential ransom demands.
Operational impact
The attack triggered significant service outages, especially for managed service providers (MSPs) and resellers who depend on Ingram Micro’s systems for order processing, license renewals, and supply chain logistics.
Multiple partners across North America, Europe, and the Middle East reported similar challenges. Ingram’s regional operations in the Middle East and North Africa (MENA), where it plays a key role in enterprise digital transformation, are under particular scrutiny.
Ingram Micro had recently partnered with cybersecurity firm Alvaka to provide ransomware response services for its MSP network — a move that now appears increasingly prescient.
Industry implications
This incident highlights the rising cybersecurity threats facing IT distributors and the potential for ripple effects across global supply chains. Analysts warn that attacks targeting large infrastructure providers could stall government, healthcare, and enterprise technology initiatives.
Readers Note:
Ingram Micro Global PR Office – No additional statements beyond public release.
SafePay – No claim of responsibility has yet been posted on known leak sites as of publication.
