Sunday, July 6, 2025
Google search engine
HomeTechnologyCyber SecurityIngram Micro outage attributable to SafePay ransomware assault

Ingram Micro outage attributable to SafePay ransomware assault


An ongoing outage at IT large Ingram Micro is attributable to a SafePay ransomware assault that led to the shutdown of inside techniques, BleepingComputer has discovered.

Ingram Micro is without doubt one of the world’s largest business-to-business know-how distributors and repair suppliers, providing a spread of options together with {hardware}, software program, cloud companies, logistics, and coaching to resellers and managed service suppliers worldwide.

Since Thursday, Ingram Micro’s web site and on-line ordering techniques have been down, with the corporate not disclosing the reason for the problems.

BleepingComputer has now discovered that the outages are attributable to a cyberattack that occurred early Thursday morning, with workers immediately discovering ransom notes created on their gadgets.

The ransom notice, seen by BleepingComputer, is related to the SafePay ransomware operation, which has change into one of many extra energetic operations in 2025. It’s unclear if gadgets had been truly encrypted within the assault.

It ought to be famous that whereas the ransom notice claims to have stolen all kinds of knowledge, that is generic language utilized in all SafePay ransom notes and is probably not true for the Ingram Micro assault.

SafePay ransom notice discovered on Ingram Micro gadgets
Supply: BleepingComputer

Do you have got details about this or one other cyberattack? If you wish to share the data, you may contact us securely and confidentially on Sign at LawrenceA.11, by way of e mail at lawrence.abrams@bleepingcomputer.com, or by utilizing our suggestions kind.

Sources have informed BleepingComputer that it’s believed the risk actors breached Ingram Micro via its GlobalProtect VPN platform.

As soon as the assault was found, workers in some places had been informed to do business from home. The corporate additionally shut down inside techniques, telling workers to not use the corporate’s GlobalProtect VPN entry, which was stated to be impacted by the IT outage.

Methods which might be impacted in lots of places embody the corporate’s AI-powered Xvantage distribution platform and the Impulse license provisioning platform. Nevertheless, BleepingComputer was informed that different inside companies, similar to Microsoft 365, Groups, and SharePoint, proceed to function as regular.

As of yesterday, Ingram Micro has not disclosed the assault publicly or to its workers, solely stating there are ongoing IT points, as indicated by company-wide advisories shared with BleepingComputer.

The SafePay ransomware gang is a comparatively new operation that was first seen in November 2024, accumulating over 220 victims since then.

The ransomware operation has been beforehand noticed breaching company networks via VPN gateways utilizing compromised credentials and password spray assaults.

BleepingComputer contacted Ingram Micro yesterday and as we speak in regards to the outages and ransomware assault, however didn’t obtain a response to our emails.


Tines Needle

Whereas cloud assaults could also be rising extra refined, attackers nonetheless succeed with surprisingly easy methods.

Drawing from Wiz’s detections throughout 1000’s of organizations, this report reveals 8 key methods utilized by cloud-fluent risk actors.

Get the Report



Supply hyperlink

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -
Google search engine

Most Popular

Recent Comments