Ingram Micro Ransomware Attack: How Did It Happen

Key takeaways
- The Ingram Micro ransomware attack ran from July 2 to July 3, 2025, and took global order processing offline for roughly four business days. Full operations returned on July 9, 2025
- SafePay claimed the incident on its leak site 26 days after detection, and Ingram Micro has never named a threat actor or confirmed an initial access vector
- The company quantified the damage at 1% to 1.5% of third-quarter fiscal 2025 net sales, or roughly $126 million to $189 million
- Files taken during the intrusion contained the personal information of 42,521 employees and job applicants, which was disclosed in January 2026 and settled for $350,000
- Downtime carried far more cost than litigation, which reverses the usual case made for ransomware investment at enterprise scale
The Ingram Micro ransomware attack was a July 2025 intrusion at Ingram Micro Holding Corporation (NYSE: INGM), a global technology products and services distributor. The attack took order processing offline worldwide for roughly four business days.
Ingram Micro confirmed ransomware on its internal systems on July 5, 2025. The company filed a Form 8-K with the Securities and Exchange Commission on July 7, 2025, and reported that operations were restored across all countries and regions on July 9, 2025.
The SafePay ransomware group listed the company on its leak site, though Ingram Micro has never named a threat actor or confirmed how the cyberattackers got access.
The company later put the financial impact at 1% to 1.5% of third-quarter net sales. It notified 42,521 people that files taken on July 2 and July 3, 2025, held their personal information.
The tactics, economics, and defenses common to incidents of this kind are covered in Adaptive Security's 2026 ransomware guide for cybersecurity teams.

Ingram Micro Ransomware Attack Quick Facts Table
| Field | Detail |
|---|---|
| Incident | Ingram Micro ransomware attack, also searched as the Ingram Micro cybersecurity incident or data breach |
| Attack date | July 2 to July 3, 2025, detected July 3 |
| Publicly disclosed | Company statement July 5, 2025, then Form 8-K under Item 8.01 on July 7 |
| Status | Contained July 8, 2025. SafePay remains active, with 548 leak-site victims as of August 25, 2026 |
| Threat actor | SafePay, self-claimed. Ingram Micro has named no actor in any statement, filing, or breach notice |
| Operating model | Closed operation, not ransomware-as-a-service |
| Initial access vector | Not confirmed. Reported as GlobalProtect VPN credentials, with the gateway itself not exploited |
| Encryption | An AES key per file, wrapped with RSA, with partial encryption available |
| File extension and note | .safepay and readme_safepay.txt |
| Ransom demanded | Never disclosed. SafePay sizes demands at 1% to 3% of the victim's annual revenue |
| Ransom paid | Not disclosed. Data was published after an August 1, 2025 deadline, pointing toward non-payment |
| Systems affected | Xvantage, Impulse, the partner portal, the public website and online ordering. Microsoft 365, Teams and SharePoint stayed up |
| Data compromised | Confirmed: personal data of 42,521 employees and job applicants. Claimed: 3.5 TB, unverified |
| Downtime | 6 calendar days, roughly 4 business days |
| Estimated damage | 1% to 1.5% of Q3 FY25 net sales and $0.02 to $0.03 per diluted share, roughly $126 million to $189 million |
| Attribution | Self-claimed only. No #StopRansomware advisory covers SafePay |
| Free decryptor | No. No More Ransom lists no tool for .safepay |
What Happened in the Ingram Micro Ransomware Attack?
Ingram Micro Holding Corporation (NYSE: INGM) is a technology distributor, or, in channel shorthand, a tier-one distributor. It sits between the manufacturers that build hardware and software and the resellers that sell to end customers.
It reported $48.0 billion in net sales for fiscal 2024 and distributes to more than 165,000 resellers in 57 countries, serving about 1,500 vendors. An outage there can stop thousands of resellers from placing orders at once.
The intrusion itself lasted two days, and its consequences ran for more than a year. Files were accessed between July 2 and July 3, 2025. The company detected the incident on July 3 and took systems offline. Operations were restored in every country and region on July 9.
SafePay claimed the Ingram Micro ransomware attack four weeks later, and the chief executive confirmed the data theft in August 2025. Ingram Micro then notified 42,521 employees and job applicants on January 16, 2026, without ever naming a threat actor or an entry point.
What Was the Timeline of the Ingram Micro Ransomware Attack?
| Date | Event |
|---|---|
| July 2 to July 3, 2025 | Cyberattackers access files holding personal information, per the breach notice |
| July 3, 2025 | Ingram Micro detects the incident, takes systems offline and tells employees to work from home |
| July 4, 2025 | Bulgaria service center staff are sent home with laptops disconnected |
| July 5, 2025 | Ingram Micro publicly confirms ransomware |
| July 7, 2025 | Ingram Micro files a Form 8-K under Item 8.01 |
| July 7 to July 9, 2025 | Ordering resumes in stages, with full global operations back at 9:50 p.m. PT on July 9 |
| July 29, 2025 | SafePay lists Ingram Micro, claims 3.5 TB and sets an August 1 deadline |
| August 6, 2025 | Paul Bay confirms on the Q2 call that data was exfiltrated |
| October 30, 2025 | Mike Zilis quantifies the impact on the Q3 call |
| January 16, 2026 | Ingram Micro notifies 42,521 employees and job applicants |
| February 12, 2026 | A Florida court preliminarily approves a $350,000 settlement |
| June 3, 2026 | The final approval hearing is scheduled |
Four dates get compressed into one in most accounts of the Ingram Micro ransomware attack. The attack began July 2, 2025, and Ingram Micro detected it July 3, disclosed it July 5 and filed with the SEC July 7.
SafePay claimed the attack July 29, which is 26 days after detection and 20 days after operations were restored. Leak sites therefore work poorly as an early-warning source, since the listing appeared only after the operational damage had been absorbed. The litigation was still awaiting approval as of August 25, 2026.
How the Ingram Micro Ransomware Attack Worked
Ingram Micro has never published a technical account of its ransomware attack. The account below is reconstructed from its timestamped status log, its SEC filings, its breach notices, two earnings calls, and contemporaneous reporting.
The incident spanned four phases of very different lengths: intrusion over two days, restoration within a week, extortion over four weeks, and data-protection consequences unresolved more than a year later.
Ingram Micro Ransomware Attack Intrusion and Detection
Employees found ransom notes on their devices early on Thursday, July 3, 2025. The notes used generic language common to SafePay, including claims that the reporting may not have been accurate. The company took systems offline the same day and told employees in several locations to work from home and to stop using the GlobalProtect VPN.
Public-facing systems went dark before anyone mentioned ransomware. The outage began around 20:00 UTC on July 3 and had run more than 14 hours by the next morning. The websites showed only a holding message: "We are currently experiencing technical difficulties." Phone lines appeared disconnected, and emails to account managers bounced, so the fallback channels failed alongside the portal.
What went down were the systems resellers transact through, including Xvantage, the distribution and ordering platform, and Impulse, the license provisioning system. What stayed up was Microsoft 365, Teams, and SharePoint, which left the response team with working email, chat, and documents throughout.
Ingram Micro Ransomware Attack Containment and Restoration
Ingram Micro restored the business by transaction type and region. Subscription orders returned globally first on July 7, 2025, alongside phone and email ordering in nine countries; hardware ordering followed on July 8, and EDI came back last on July 9.
EDI, or electronic data interchange, is the automated link resellers use to submit orders without human involvement. Reopening it last fits a plan that restored the least system-dependent paths first.
The company declared the access restored at 4:30 p.m. PT on July 8. Ordering had already resumed in more than a dozen markets by that point, so restoration ran in parallel with the investigation.
Ingram Micro Ransomware Attack Extortion and Disclosure
Ingram Micro disclosed under Item 8.01 of Form 8-K, the catch-all Other Events item, instead of Item 1.05, the item created for incidents a company has determined to be material. That choice follows SEC staff guidance.
The Division of Corporation Finance stated in May 2024 that a company disclosing an incident "for which it has not yet made a materiality determination" is encouraged to file under a different item, "for example, Item 8.01".
The filing is short, with no materiality statement, no financial estimate, and no description of the data, and the Form 10-Q for the same quarter mentions the incident nowhere.
Extortion began three weeks after that filing. SafePay listed the company on July 29, 2025, claimed 3.5 TB and set an August 1 deadline. When the deadline passed, the group said it had published the data, though the download link did not work.
With hindsight, the Item 8.01 route looks defensible. The impact eventually reported was confined to part of one quarter, and the decision was made on July 7, 2025 while the scope of the stolen data was still unknown.
Ingram Micro Ransomware Attack Notification and Litigation
The slowest phase of the incident was document review. Restoring the business was completed in the first week of July 2025, while determining whose personal information was contained in the stolen files continued until the following winter.
Ingram Micro filed breach notices with regulators including the Vermont Attorney General and the Massachusetts Office of Consumer Affairs and Business Regulation. Containment works against a known target, where systems and accounts can be counted and progress measured in hours.
Document review works against unstructured data. Reviewers must open the files, identify everyone named inside them, and apply the notification standard of each jurisdiction involved.
Litigation followed within weeks. Rodden v. Ingram Micro Americas, Inc. was filed in the Circuit Court for Broward County, Florida, and the settlement class includes every living United States resident who received a notice. That ties the legal exposure to the notification list instead of to the volume of data taken.
Document review is a workstream with its own duration, budget, and staffing. An incident response plan that treats it as a step inside remediation will underestimate both the calendar and the cost.
Ingram Micro Ransomware Attack: Supply Chain Dependency vs. Supply Chain Compromise
Two very different problems get filed under supply chain risk. In the first, cyberattackers use the vendor as a doorway into its customers.
SolarWinds is the standard example because cyberattackers gained covert access to the build process and a backdoor was shipped in legitimate Orion updates. Customers were compromised by installing an update they had every reason to trust. In the second problem, the vendor simply stops working, and its customers lose the service they depend on, even as no cyberattacker reaches them.
The Ingram Micro ransomware attack was the second kind. Resellers lost the ability to place orders and provision licenses for several days, and no evidence has been published that SafePay used Ingram Micro to reach a partner or customer network. The stolen data was the company's own employee records, not reseller, vendor, or customer data.
| Incident | Date | What kind of failure |
|---|---|---|
| SolarWinds Orion | December 2020 | Compromise through the vendor. A backdoor shipped inside legitimate releases |
| Kaseya VSA and REvil | July 2021 | Compromise through the vendor. Fewer than 60 direct customers exploited and fewer than 1,500 downstream businesses impacted |
| SYNNEX | July 2021 | Attempted compromise through the vendor. Outside actors "attempted to gain access, through SYNNEX, to customer applications within the Microsoft cloud environment" |
| CDW and LockBit | October 2023 | Extortion of the vendor. LockBit demanded $80 million, and CDW said the servers were isolated from its network |
| Microlise and SafePay | October 2024 | The vendor stopped working and customers felt it. Tracking and panic alarms in prison vans and courier vehicles failed at Serco and DHL |
| Ingram Micro and SafePay | July 2025 | The vendor stopped working. Resellers lost the ability to transact, and no partner or customer environment has been reported as compromised |
The two problems call for different defenses. Guarding against compromise through a vendor means limiting what that vendor can reach and being able to switch it off quickly.
Guarding against a vendor going dark means lining up a second supplier, which the channel calls going multi-distribution. It also means holding contractual service levels and knowing which customer commitments rest on a single upstream supplier.
SYNNEX, now TD SYNNEX, is the precedent above where cyberattackers actually tried to use a distributor's access to reach customers, making it a closer comparison than SolarWinds. Other major ransomware attack examples show the same split between dependency and compromise.
Who Was Behind the Ingram Micro Ransomware Attack?
SafePay is a ransomware operation that first appeared in 2024 and operates as a closed group rather than a ransomware-as-a-service scheme. The same people handle the break-in, the encryption, and the extortion, and the malware is never rented to affiliates.
It applies double extortion, stealing data before encrypting files so it can threaten publication as well as withhold the key.
Two pieces of evidence connect the group to the Ingram Micro ransomware attack, and both come from the cyberattacker. The first is a ransom note matching its template, and the second is the leak-site listing four weeks later. The note is the stronger of the two, because it was found inside the environment while the incident was happening.
SafePay's Documented Initial-Access Playbook
SafePay gets in through credentials and people. The group targets VPN gateways using compromised credentials or password spraying, the practice of trying a single common password across multiple accounts to avoid lockouts. It also builds password guesses from login data and employee names gathered using open-source intelligence tools.
The second route targets the help desk. The group floods a target with spam while calling through Microsoft Teams posing as the IT department, a combination of email bombing and voice phishing.
Cyberattackers posing as third-party IT vendors then request a system review "using legitimate tools, such as Microsoft Quick Assist for remote control." Infosecurity Magazine also reports that the group drops a PowerShell script and can stay on the network for up to a week. It then uses Rclone, a legitimate cloud storage tool, to move data out.
The route reported at Ingram Micro fits that pattern exactly, which is one reason it spread so fast. However, consistency with a known playbook is not confirmation.
SafePay Origins, Scale and Victimology
Published accounts place SafePay's emergence in October 2024, and the group went from unknown to prolific inside a year. NCC Group found it to be the most active ransomware group in May 2025, accounting for 18% of all attacks that month.
Its own code points away from Russian-speaking countries, since samples check the system language and stop if they find Russian, Ukrainian, Belarusian, Tajik, Armenian, Azerbaijani or Georgian.
SafePay's documented victim profile runs small, and Ingram Micro sits far outside it. An analysis of 500 SafePay leak-site records published in January 2026 found that more than 90% of victims were small and medium-sized businesses, and only 8% were multinationals.
The pricing formula breaks down at enterprise scale too, because SafePay sizes demand at 1% to 3% of annual revenue, with typical demand between $500,000 and $1 million. The same formula applied to $48.0 billion in fiscal 2024 net sales yields $480 million to $1.44 billion, and no demand associated with this incident has ever surfaced.
Why There Is Still No CISA Advisory for SafePay
No United States government advisory names SafePay. As of August 25, 2026, the joint #StopRansomware series run by CISA and the FBI covers Play, RansomHub, Interlock and Gunra but not SafePay, and the absence is verifiable through CISA's advisory index.
Advisories are produced when agencies hold incident data and the capacity to publish, so the gap reflects availability. Security teams that treat government advisories as their primary source will find no federal material on the group implicated in the Ingram Micro ransomware attack.
Ingram Micro Ransomware Attack: Data Breached and Incident Cost
The most widely repeated cost estimate for the Ingram Micro ransomware attack put the figure at $136 million per day, and that number measures sales.
It comes from dividing Ingram Micro's first-quarter 2025 net sales of $12.28 billion across the days in the quarter, producing more than $136 million in sales for each day the company could not fulfill orders, and the original wording described what the company stood to lose.
The same number appeared on the same day as an estimate that the firm lost around $136 million per day, with the conditional and the word "sales" both dropped.
Multiplying daily sales by the number of days of downtime does not capture what a distributor loses. Orders that could not be placed were largely deferred instead of canceled, because a reseller that cannot buy on Thursday buys the following week.
Revenue is also not margin. Ingram Micro reported $3.4 billion of gross profit on $48.0 billion of fiscal 2024 net sales, or about 7.2%. A full day of genuinely lost sales would therefore represent less than $10 million in gross profit.
What Data Was Compromised in the Ingram Micro Ransomware Attack?
The attack caused two kinds of damage that affected different people. The business damage was availability, felt by resellers who could not transact. The privacy breach involved human resources data, affecting the company's current, former, and prospective employees.
| Claimed by SafePay | Confirmed by Ingram Micro |
|---|---|
| 3.5 TB exfiltrated | Files holding the personal information of 42,521 employees and job applicants |
| No data types listed, no verified sample, and a download link that did not work | Name, contact information, date of birth, Social Security number, driver's license number, passport number, and other government-issued identification numbers |
| No ransom demand published | Medical or health insurance information held in employment records, and employment information such as work evaluations |
The notification letter offered two years of Experian IdentityWorks at no charge, including credit monitoring, identity restoration and $1 million in identity theft insurance. Two items on the confirmed list outlast that offer, because Social Security numbers are not routinely reissued and passport numbers stay valid for years.
Ingram Micro Ransomware Attack Settlement: $350,000 for 42,521 Social Security Numbers
The legal exposure settled well below the operational cost. A class settlement of $350,000 covering 42,521 people works out to $8.23 per person before any deduction.
| Settlement term | Detail |
|---|---|
| Fund | $350,000 |
| Documented losses | Up to $1,500 per claimant |
| Payment without documentation | About $50, pro rata from a $100,000 portion |
| Identity protection | Two years of CyEx Financial Shield Complete with $1 million in fraud insurance |
| Class counsel fees requested | Up to $200,000 |
| Service awards | $1,500 each to five class representatives |
| Class definition | All living United States residents sent a notice about the incident |
The operational cost dwarfed the legal one. The net sales impact reported for a single quarter was 360 to 540 times the entire settlement fund. Against the global average cost of a data breach of $4.99 million, the fund amounts to about 7%.
That inverts the usual case for ransomware investment, which leads with litigation and regulatory exposure. For an enterprise of this size the number that justifies the spending is downtime.
Two limits apply. The settlement had not received final approval as of August 25, 2026, and a $350,000 outcome in one Florida court does not set the price elsewhere.
Ingram Micro Ransomware Attack Recovery and Decryption
No free decryptor exists for SafePay. The No More Ransom Project lists no tool for SafePay or for files with the .safepay extension, as of August 25, 2026, with no partial coverage and no variant-specific tool.
The encryption design explains why, since SafePay generates a separate AES key for each file and encrypts that key with RSA. The per-file keys cannot be reconstructed without the cyberattacker's private key.
Recovery therefore rests on backups the cyberattacker could not reach, on rebuilding systems, or on the key itself. Only the first two sit within a victim's control.
A search for a SafePay decryptor returns paid recovery services instead of a free tool. The No More Ransom catalogue is the authoritative place to recheck, since tools are added when law enforcement seizes keys or researchers find a flaw.
What Went Right and What Went Wrong in the Ingram Micro Ransomware Attack Recovery
The recovery from the Ingram Micro ransomware attack is mixed. The operational response was better than average, and the communications response was worse.
Full global operations returned six calendar days after detection, which is fast for an outage that reached ordering, license provisioning and shipping across 57 countries, and the blast radius stayed narrow.
Ingram Micro credited its own architecture, with Chief Executive Officer Paul Bay telling the August 2025 earnings webcast that "Our Xvantage digital experience platform played a critical role in accelerating our recovery". The company also published a timestamped status log with region-by-region updates.
The communications failed at the start. Ingram Micro said nothing about ransomware for roughly 48 hours after detection, which left partners with no basis to judge their own exposure at the moment they most needed one.
The entry point was then never confirmed, so reporting filled the space and an unsourced claim about missing multi-factor authentication attached itself to the record. Notification took until January 16, 2026, which is defensible on forensic grounds and still meant people learned the following winter that their Social Security numbers had been taken in July.
Is SafePay Ransomware Still Active in 2026?
Yes. The group behind the Ingram Micro ransomware attack was still posting victims in August 2026. Its leak site listed 548 victims as of August 25, 2026, with the most recent added the previous day and no recorded period of inactivity.
Continued activity does not mean continued interest in enterprises, because the victim profile documented through January 2026 was overwhelmingly small and medium businesses. The organizations most exposed remain smaller firms and the managed service providers that support them, with Ingram Micro standing as the exception.

What Can Security Teams Learn From the Ingram Micro Ransomware Attack?
The lessons the Ingram Micro ransomware attack supports are narrower than most accounts suggest, because the company never confirmed how the cyberattackers got in. Anything presented as a fix for the specific entry point is inference.
Three bodies of evidence survive that limit: SafePay's documented behavior against other victims, what the incident showed about architecture and recovery, and what partners did while the outage ran.
Ingram Micro Ransomware Attack Lessons: Identity and Remote Access
Phishing-resistant multi-factor authentication on every remote-access path is the control that answers SafePay's documented entry method. Phishing-resistant means a hardware security key or a passkey bound to the site instead of a code from an app or a text message. A code can be relayed by a cyberattacker in real time, while a bound credential cannot.
Coverage matters more than strength, since password spraying succeeds against whatever account sits outside the policy. Service accounts and legacy VPN profiles are the usual exceptions worth auditing first.
Credentials that leak elsewhere become the entry point here, and stolen credentials often reach criminal markets long before anyone uses them. Prior compromise was the initial infection vector in 30% of ransomware operations in 2025, double the 15% recorded in 2024.
Monitoring infostealer logs and credential marketplaces for corporate domains turns that interval into a warning. Authentication succeeding is also not evidence of a legitimate user, and the route reported at Ingram Micro was a valid session on a working VPN. Only impossible-travel checks, unfamiliar device flags and alerts on sessions outside a user's established pattern could have caught it.
Ingram Micro Ransomware Attack Lessons: The Human Layer SafePay Targets
Out-of-band verification for any inbound contact claiming to be IT support is the control that breaks SafePay's social engineering chain. Verification means the employee ends the call and reaches the help desk through a number the organization publishes, never one the caller supplies.
The chain works because every step arrives through trusted software, and none of it looks like an attack to a filter because none of it is malicious code.
Microsoft recommends blocking or uninstalling Quick Assist and comparable remote monitoring and management tools where they are not in use, and allowing a connection only when the employee initiated contact with support.
Microsoft also describes the mail flood as link listing, in which a target's address is signed up to many subscription services at once so legitimate mail is buried. A spike in subscription confirmations to one mailbox is therefore a detection signal.
Voice phishing accounted for 11% of initial infection vectors in 2025 and became the second most commonly observed route, ahead of email phishing at 6%. Simulation should therefore span voice phishing, text messages and pretexts assisted by synthetic audio instead of links alone.
Ingram Micro Ransomware Attack Lessons: Detection Engineering
Indicator lists age badly and behaviors do not. The most detailed public technical analysis of SafePay was published in July 2025, so its file hashes and cyberattacker infrastructure are unlikely to match a current sample.
The behaviors that analysis describes are structural to how the group works, which makes them the durable half of any detection package built against SafePay.
| Behavior to detect | Why it matters | MITRE ATT&CK |
|---|---|---|
| A DLL loaded through regsvr32.exe or rundll32.exe | The payload is a DLL that needs a system utility to run it | T1218.010 |
| Execution of ShareFinder.ps1 to list network shares | Share discovery ran before exfiltration in observed intrusions | T1059.001, T1135 |
| FileZilla or Rclone appearing on a server and moving data outbound | Both have staged and moved stolen data ahead of encryption | T1048 |
| Abuse of the CMSTPLUA COM interface to gain elevated permissions | User Account Control bypass before destructive actions | T1548.002 |
| Deletion of volume shadow copies through vssadmin or wmic | Removes the local restore points that would undo encryption | T1490 |
| Termination of security, backup, database and mail services | Unlocks held files and closes recovery paths | T1489, T1562.001 |
The sequence carries more signal than any single row, because each behavior has legitimate uses on its own. Share enumeration followed by a transfer tool arriving and then services being stopped is not a coincidence.
Mapping each MITRE ATT&CK technique identifier against existing coverage usually shows most of the chain is already visible, with only one or two links missing.
Ingram Micro Ransomware Attack Lessons: Backups and Recovery Architecture
Network segmentation is the lesson this incident demonstrates most clearly. The productivity estate stayed available while the transactional estate was down. An architecture where the two fail together removes the tooling needed to coordinate a recovery at the moment it is needed most.
Backups have to sit beyond the cyberattacker's reach because SafePay deletes shadow copies and stops backup, database and mail services before encrypting. Any copy reachable from a compromised host sits inside the blast radius.
Immutable backups, meaning copies that cannot be altered or deleted for a fixed retention period, are what survive that. A recovery time objective means nothing until a restore has been run against it and measured, which is the step most plans for recovering from a ransomware attack leave untested.
Exfiltration is the part backups do not solve at all, since the data leaves before encryption. Egress monitoring and data-loss detection are what turn it into something visible while it happens.
Ingram Micro Ransomware Attack Lessons: The First 24 Hours After a Supplier Breach
One managed service provider acted within a day. An executive at an Ingram Micro customer was removing third-party privileged access to the firm's Microsoft tenant during the outage, out of concern that cyberattackers could use Ingram Micro platforms to reach its own network. That response was sound even though the concern turned out to be unfounded, because nobody could know that on July 5, 2025.
- Inventory every privileged and delegated access path the supplier holds, including tenant-level administrative rights, cloud solution provider relationships, API keys and VPN accounts
- Revoke or suspend any of those paths not needed for the next 72 hours
- Rotate every shared or federated credential the relationship depends on
- Hunt for unusual authentication from supplier-associated identities and address ranges
- Identify which customer commitments depend on that supplier before customers ask about them
- Activate alternate sourcing, and confirm the alternate does not draw on the same upstream provider
- Log every action taken, since a notification decision may rest on that record months later
Every step is reversible, which is what makes running it affordable. Access suspended for 72 hours can be restored in minutes, while access left open during an unresolved incident cannot be withdrawn retroactively.
The exercise also tends to show how far a long-standing supplier relationship has drifted from least privilege, which is third-party risk management working at the speed an incident actually moves.
The Ingram Micro ransomware attack cost far more in downtime than in litigation. Restoring the business took days and cost between $126 million and $189 million of quarterly net sales, while the legal exposure for the personal data of 42,521 people settled at $350,000.
Neither figure was set by the encryptor, and both trace back to credentials and to the people who hold them. Adaptive Security builds its training against those entry points, which are the same ones that ran through every stage of the incident.
Ingram Micro Ransomware Attack: Frequently Asked Questions
How Did the Attackers Get Into Ingram Micro?
Ingram Micro has never confirmed how the cyberattackers got in. Reporting identified compromised credentials on the company's GlobalProtect VPN, and the same reporting states the gateway itself was not compromised or exploited. Palo Alto Networks said none of its products were the source of the vulnerability. No company statement, SEC filing or breach notice names a vector for the Ingram Micro ransomware attack.
Did Ingram Micro Pay the Ransom?
Ingram Micro has never addressed whether a ransom was paid. SafePay listed the company on its leak site on July 29, 2025 and set an August 1, 2025 deadline. The group then claimed to have published the stolen data, which points toward non-payment without establishing it. No demand figure has ever been made public.
What Did the Ingram Micro Ransomware Attack Cost?
Ingram Micro put the impact at 1% to 1.5% of third-quarter fiscal 2025 net sales and $0.02 to $0.03 per diluted share. Against net sales of $12.604 billion, that equals roughly $126 million to $189 million. Remediation, forensics, legal spend, and insurance recovery were never quantified, so the published figure is not a total cost of the incident.
What Is SafePay Ransomware?
SafePay is a ransomware group that first appeared in 2024 and operates as a closed team, not a ransomware-as-a-service scheme. Its operators exfiltrate files first and encrypt afterwards, which gives them two levers: a leaked-data threat and a withheld decryption key. The group appends the .safepay extension and leaves a note named readme_safepay.txt.
Is SafePay Still Active?
SafePay was still active in August 2026. Its leak site listed 548 victims as of August 25, 2026, with the most recent added the previous day and no recorded period of inactivity. No United States government advisory covers the group, and no free decryptor has been released for the .safepay extension.
As experts in cybersecurity insights and AI threat analysis, the Adaptive Security Team is sharing its expertise with organizations.
Get started with Adaptive Security
Related articles

Business Email Compromise Examples: 9 Real-World BEC Scams, Warning Signs, and Prevention Lessons That Reduce Risk

Adaptive Email Security: Why it's Our Fastest-Growing Product

The Complete History of CryptorBit Ransomware (HowDecrypt): Mechanism, Timeline, and Recovery
Get started