Ingram Micro Investigates Ransomware Incident
In a recent announcement, Ingram Micro revealed that it has detected ransomware on some of its internal systems, prompting the company to launch a thorough investigation. The impacts of this breach have raised significant concerns within the cybersecurity community.
Detection of Ransomware
Ingram Micro disclosed on its official website that it identified ransomware affecting several of its internal systems. The company took immediate action to mitigate the situation. As soon as the issue was recognized, Ingram enacted protocols to secure the impacted environment. This involved taking certain systems offline and implementing additional measures to prevent further escalation.
Steps Taken Post-Incident
Following the discovery of the ransomware, Ingram Micro sought the expertise of leading cybersecurity professionals to assist in the investigation. Furthermore, the company notified law enforcement authorities to ensure proper handling of the incident. While the timeline for resolution remains unclear, proactive measures were taken to contain the breach.
Reports indicated that the "About Us" section of Ingram Micro’s website was temporarily unavailable, although the home page remained accessible at the time of writing. Additionally, the Australian branch of Ingram Micro issued warnings about interruptions resulting from this cyber incident.
Nature of the Threat
Though Ingram Micro has not publicly disclosed the identity of the attackers, cybersecurity publication BleepingComputer indicated that employee devices were targeted with a ransom note from a group claiming to be known as SafePay. This note stated, "Greetings! Your corporate network was attacked by SafePay team," and cited weaknesses in Ingram Micro’s network security that allowed unauthorized access.
The ransom note further claimed that due to network misconfigurations, the attackers could infiltrate the system and encrypt “all files of importance.” Specifically, they mentioned that data of high interest, including financial statements, intellectual property, and sensitive personnel and customer information, had been exfiltrated.
Ransom Demand
According to the ransom note, Ingram Micro has been given a time frame of seven days to meet the ransom demand. If payment is made, the attackers said they would delete the stolen data from their servers and assist in decrypting the data on Ingram Micro’s systems. However, experts have expressed skepticism regarding the accuracy of the data claimed to have been stolen, noting similarities to past ransom notes issued by the group.
Workforce Impact
In light of the breach, Ingram Micro issued directives for employees to work from home and refrain from using the company’s GlobalProtect VPN. It is believed that the VPN gateway may have been part of the entry point for the attackers. Security firm Palo Alto Networks emphasized that protecting customer security is their top priority and is currently investigating claims related to the incident.
Insights on SafePay
SafePay is a relatively new entity in the ransomware landscape, first observed in October 2024. The group has been linked to attacks on businesses across multiple countries including Australia, the UK, and the US, among others. Notably, SafePay has stated that it does not operate as a ransomware-as-a-service (RaaS) entity, distinguishing itself from many other ransomware groups.
Ingram Micro’s experience underscores the critical importance of robust cybersecurity measures and network configurations. As this situation unfolds, it will likely serve as a case study for other organizations facing similar cybersecurity threats.


