Ingram Micro: The Ransomware Attack That Ran Through One Login

Key takeaways
- Ingram Micro, a $48 billion-a-year technology distributor, was hit by ransomware on July 3, 2025 after SafePay accessed its network through Palo Alto Networks GlobalProtect using a valid VPN username and password rather than exploiting a software flaw.
- Researchers said the intrusion likely came from stolen, guessed, weak, or reused credentials; the article notes SafePay emerged in late 2024 and had already used similar access against more than 220 other organizations, often targeting remote access systems without multi-factor authentication.
- Systems began failing around 8 a.m. Eastern on July 3, ransom notes appeared on employee screens, and key platforms including Xvantage for quotes and orders and Impulse for software license activation went offline; Ingram Micro publicly confirmed the attack on July 5 and filed with the SEC on July 7.
- Recovery was staged over roughly a week: the website returned first, subscription orders resumed on July 8, and global operations were reported fully restored within about a week; based on $48 billion in annual sales, the article estimates Ingram Micro moves about $130 million of business on an average day.
- Halcyon researcher Anthony Freed said SafePay uses double extortion, combining encryption with data theft, and Comparitech researcher Rebecca Moody said her team tracked 238 SafePay attacks over several months with an average of 111 gigabytes stolen per victim.
- In a January 20, 2026 filing with the Maine Attorney General, Ingram Micro said 42,521 current employees, former employees, and job applicants had personal information exposed, including names, contact details, dates of birth, Social Security numbers, driver’s license and passport numbers, and employment records.
How a single stolen VPN credential froze the order and licensing systems one of the world's largest technology distributors runs on.
An Adaptive Security series on the ransomware attacks that shaped modern cyber defense. Hub: A History of Notable Ransomware Attacks. Previously: Fairlife.
Ingram Micro moves $48 billion a year in hardware, software, and licensing deals, all of it funneled through the resellers, retailers, and IT service providers who put that gear in front of businesses and shoppers. On July 3, 2025, ransom notes started popping up on employee screens inside the company's network. Within hours, the ordering and licensing platforms that thousands of other businesses run on had gone dark.
One Working Login, No Broken Lock Required
Investigators traced the break-in to GlobalProtect, the remote access system Palo Alto Networks built so employees can log into a company network securely from outside the office. A group calling itself SafePay used a valid username and password to get in. Multiple researchers who reviewed the incident pointed to theft or simple guesswork as the likely source of those credentials, the same kind of access the group had already used against more than 220 other organizations before it ever reached Ingram Micro.
SafePay built its business on exactly this kind of access. The group surfaced in late 2024 and grew quickly by targeting remote login systems that lacked multi-factor authentication, the extra verification step that would have required more than a password alone to get through the door.
Three Days Offline
Ingram Micro’s systems began failing around 8 a.m. Eastern time on July 3. Employees found ransom notes waiting on their screens where their usual desktops should have been. Two of the company’s core platforms went down within hours: Xvantage, the AI-powered system that processes quotes and orders, and Impulse, the platform resellers use to activate and manage software licenses. The company sent employees home, took additional systems offline as a precaution, and issued a public statement on July 5 confirming a ransomware attack. Its formal filing with the Securities and Exchange Commission followed on July 7.
Restoration happened in stages. Ingram Micro’s website came back first, subscription orders followed on July 8, and the company reported its global operations fully restored within about a week. Divide Ingram Micro’s $48 billion in annual sales by the days in a year, and the company moves something like $130 million worth of business on an average day. For most of a week, almost none of that business could move through its usual channels, and the resellers and service providers who depend on Ingram Micro’s ordering system felt that delay just as directly as Ingram Micro did.
The Group Behind the Note
The note SafePay left behind read like a taunt. “Your corporate network was attacked by Safepay team,” it said. “You IT specialists made a number of mistakes setting up the security of your corporate network, so we were able to spend quite a long period of time in it and compromise you.” The group claimed to have pulled financial statements, intellectual property, accounting records, legal documents, and employee and customer files out of Ingram Micro's network.
Anthony Freed, a researcher at the cybersecurity firm Halcyon who has tracked SafePay’s activity, has described the strategy behind that kind of note. “SafePay consistently applies a double extortion model, encrypting systems while exfiltrating sensitive data to increase leverage through the threat of public exposure and sustained operational disruption,” he said. Around the same time, Comparitech researcher Rebecca Moody said her team had tracked SafePay through 238 attacks over the previous several months, stealing an average of 111 gigabytes of data from each victim.
What the Company Confirmed, Months Later
SafePay posted a claim on its dark web site that it had pulled 3.5 terabytes of documents out of Ingram Micro’s network, a figure no outside researcher could confirm independently. A clearer picture came seven months later. In a January 20, 2026 filing with the Maine Attorney General's office, Ingram Micro confirmed that 42,521 current employees, former employees, and job applicants had personal information exposed in the breach, including names, contact information, dates of birth, Social Security numbers, driver's license and passport numbers, and employment records such as performance evaluations.
The path SafePay took into Ingram Micro fits a trend researchers have tracked across the industry. Alexander Leslie, a threat intelligence analyst at Recorded Future, has pointed to what that trend means for defenders. “The core takeaway is that identity has become the primary attack surface, and attackers are no longer breaking in but systematically logging in using stolen credentials at scale,” he said.
A Weak Link Felt Far Beyond One Company
Ingram Micro sits in the middle of a chain most of its own customers never think about. Resellers, retailers, and managed service providers around the world route their orders and license activations through its platforms, so one compromised login inside Ingram Micro’s network became a problem for thousands of businesses that never had any direct relationship with SafePay.
Santiago Torres-Arias, an assistant professor of electrical and computer engineering at Purdue University who studies software supply chains, has made a similar point about a different kind of chain, one built from code rather than companies. “A system is only as strong as its weakest link,” he said. “Hackers will search to find that one program in a chain of software that is vulnerable and hack it.” Ingram Micro’s chain ran through business relationships, the resellers and service providers connected to one distributor. The same underlying math applied. The weak link SafePay found sitting inside it was a login someone had already been using for months.
That login had to come from somewhere before SafePay ever used it. Researchers who track the group have pointed to weak or reused passwords, guessed through automated attempts, as often as outright theft, the kind of gap that opens when a password is short, common, or borrowed from some other account. Adaptive Security studies this history because training a workforce to build stronger password habits and recognize the moment someone is trying to steal one remains one of the most direct ways to keep a login like that one from ever working for a buyer like SafePay.
This is the final post in Adaptive Security’s series on the ransomware attacks that shaped modern cyber defense. Read the story from the beginning at the hub: A History of Notable Ransomware Attacks.
Get started with Adaptive Security
Get started