Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. Ingram Micro said it was operational across all countries and regions where it does business by 9:50 p.m. PT on July 9, 2025, after ransomware disrupted some internal systems. Order processing and shipping had resumed earlier that day through EDI, phone, and email.

What happened to Ingram Micro?

On July 5, 2025, Ingram Micro disclosed that it had identified ransomware on certain internal systems. The company took systems offline, began an investigation with cybersecurity experts, notified law enforcement, and worked to restore order processing and shipping. Ingram Micro’s July 5 statement

When did Ingram Micro restore orders and operations?

Date and time What Ingram Micro reported
July 8, 2025 The company said it believed unauthorized access was contained and affected systems remediated. Ingram Micro update
July 9, 2025, 10:00 a.m. PT Teams could process and ship orders received by EDI, phone, or email across all business regions. Ingram Micro update
July 9, 2025, 9:50 p.m. PT Ingram Micro said it was operational across all countries and regions where it transacted business. Ingram Micro update
July 10, 2025 Dark Reading reported that the company’s websites were operational globally and that customers had initially been unable to place online orders. Dark Reading report

How did Ingram Micro recover its systems?

In its later annual-report filing, Ingram Micro said it activated incident-response and business-continuity protocols, contained and remediated the issue, and restored impacted systems using backups. It also reported costs for investigation, remediation, system restoration, and cybersecurity-program enhancements. The filing did not provide a dollar figure for those costs. Annual-report filing

The same filing said the incident did not cause a material interruption of operations, while warning that future incidents could have material effects. That is the company’s reported assessment; it does not establish that the incident had no operational impact.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was SafePay responsible for the attack?

That attribution was not confirmed. Dark Reading reported that BleepingComputer had seen an alleged SafePay ransom note, but said it remained unclear which ransomware group was responsible. At the time of that report, the attacker had not mentioned Ingram Micro on its leak site. Dark Reading report

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is still unknown about the incident?

The cited company filing and reporting do not establish a ransom amount, the number of records affected, a quantified downtime duration, or a specific financial loss. Ingram Micro discussed incident-related costs qualitatively rather than publishing a dollar amount. Annual-report filing

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.