Ingram Micro disclosed that a July 2025 ransomware attack resulted in the theft of files from internal repositories and a subsequent data breach affecting ~42,000 people (reported as 42,521 in filings). The company said an unauthorized party accessed and exfiltrated certain files between July 2–3, 2025, and that it detected the incident on July 3, after which it took systems offline and began containment and remediation with external cybersecurity experts and law enforcement notification.
The compromised data primarily involved employee and job applicant records, including names, contact details, dates of birth, and government-issued identification numbers such as Social Security, driver’s license, and passport numbers, as well as some employment-related information (e.g., work-related evaluations). The incident also caused significant operational disruption, including outages impacting internal systems and customer-facing operations; reporting noted that SafePay claimed responsibility and alleged theft of ~3.5 TB of data, though Ingram Micro has not publicly attributed the intrusion to a specific threat group while confirming ransomware was deployed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In January 2026, Ingram Micro disclosed in a filing with the Maine attorney general that the July 2025 ransomware attack exposed personal data belonging to 42,521 people, including employees and job applicants. The company said the compromised information included identifiers such as names, dates of birth, Social Security numbers, other government ID numbers, and employment-related records, and it offered two years of credit monitoring and identity protection.
After the ransom deadline passed, SafePay claimed it had published the stolen data on its Tor leak site, indicating negotiations had failed. One report said the download link provided by the group did not work.
SafePay set a July 31, 2025 deadline for ransom payment in connection with the attack. The group used the deadline as part of its double-extortion pressure campaign against Ingram Micro.
After the incident became public, the SafePay ransomware group claimed responsibility on its leak site and said it had stolen 3.5 TB of data from Ingram Micro. The claim aligned with reports that ransomware had been deployed, though Ingram Micro did not publicly attribute the attack to a specific group.
Within about a week of the attack, Ingram Micro restored affected systems and resumed global operations. Reporting says recovery was largely complete by July 9, 2025, after logistics and service management had been disrupted for roughly a week.
On July 3, 2025, Ingram Micro detected the ransomware incident, engaged external cybersecurity experts, notified law enforcement, and shut down some systems to contain and remediate the attack. The outage disrupted internal systems, the website, and operations, with some employees told to work from home or sent home.
An unauthorized third party began exfiltrating files from Ingram Micro's internal repositories on July 2, 2025. The stolen data later proved to include employee and job applicant records containing sensitive personal information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcebleepingcomputer.com
Open sourcego.theregister.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.