Free tools Windows power users keep installed
One-click scans. No signup required.
Ingram Micro confirmed that ransomware was found on certain internal systems on July 5, 2025. The company took some systems offline, brought in cybersecurity specialists, and notified law enforcement. It did not confirm that SafePay was responsible. Ingram Micro restored order processing in stages and said on July 9 that it was operational across all regions where it transacts business. A later news report attributed a 42,521-person impact figure to a company filing with Maine regulators; that figure and the reported record categories should be treated as attributed reporting, not independently verified here.
What Ingram Micro confirmed
In a July 5, 2025 statement, Ingram Micro Holding Corporation said it had identified ransomware on “certain of its internal systems.” The company said it proactively took some systems offline, began an investigation with external cybersecurity experts, and notified law enforcement. Ingram Micro’s incident updates and its SEC-filed statement establish the company’s own account of the initial response.
SafePay was reported as the group behind the incident, but Ingram Micro’s public statements and later filing do not identify SafePay as the perpetrator. The company’s confirmation is that ransomware was discovered—not that the reported attribution or any claims of stolen data were verified.
Incident and recovery timeline
| Date | What Ingram Micro reported |
|---|---|
| July 5, 2025 | Ransomware on certain internal systems; some systems taken offline; investigation launched with external experts; law enforcement notified. |
| July 7, 2025 | Subscription orders were available globally. The company described phone and email order processing in multiple countries, with limitations on some hardware and technology orders. |
| July 8, 2025 | The company said it believed unauthorized access was contained and affected systems remediated, while its investigation into scope and affected data continued. Order-processing options had expanded. |
| July 9, 2025 | Ingram Micro said it could process and ship orders received electronically, by phone, or by email across its business regions, and reported it was operational across all countries and regions where it transacts business. |
| 2026 annual-report filing | The company described response and restoration costs and its assessment of the incident’s effect on operations and the business. |
| January 20, 2026 | TechRadar reported a personal-data impact figure and employment-related record categories, attributing them to a company filing with Maine’s attorney general and notification letters. |
The July 8 update said: “Our investigation into the scope of the incident and affected data is ongoing.” The July 9 update marked a service-restoration milestone, not a public accounting of every system or data question.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What the company said about business impact
In its 2025 annual report, Ingram Micro said the incident affected certain systems and led to investigation, remediation, restoration, and cybersecurity-program enhancement costs. The company assessed that the incident did not materially interrupt operations or materially adversely affect its business, financial condition, or reputation. This is the company’s retrospective assessment; it does not mean there was no disruption or response cost.
What is known about affected personal information
On January 20, 2026, TechRadar reported that Ingram Micro’s filing with the Maine attorney general identified 42,521 affected individuals. The report described the affected files as involving employment and job-applicant records, citing the filing and notification letters. The underlying state filing was not independently reviewed here, so the count and categories are best stated with that attribution rather than as independently confirmed facts.
Rank #2
- SuperSpeed: A super-fast 64GB USB3.0 USB drive with read speed up to 150MB/S and write speed up to 80MB/S. It has super speed but DOESN'T overheat. Also available in a 128GB capacity. See the A+ comparison chart for details.
- Safety: It comes with A physical write-protect switch and can safely connect to any computer while the switch set to “Read-Only”. In the Protected mode, your data is safe from viruses, malware, data tampering and accidental deletion.
- High Endurance: This flash drive has higher performance and endurance/durability as it adopts A+ MLC memory chip compared with other USB flash drives which use TLC or QLC chips.
- Capacity: This listing is for the 64GB version. A 128GB option is also available. See the A+ comparison chart for details.
- Plug and Play: Simply plug the thumb drive into any USB port and then start data transfer and storage. It is compatible with USB 3.0/3.1 and USB 2.0 ports and works on Windows2000/XP/Vista/7/8/10/11/Server, Mac OS, and Linux. The default format is exFAT file system which allows individual files larger than 4 GB, but you can always re-format to FAT32.
The official July 8 update said the investigation into affected data was still ongoing. The reviewed official material does not provide a complete public inventory of information involved in the incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What remains unconfirmed
- SafePay attribution: The company did not name SafePay as the attacker in the statements and filing described above.
- Initial access: The reviewed company material does not establish how the attackers first gained access.
- Data-theft claims: No independent confirmation was established for claims that data was stolen or for any claimed volume.
- Ransom: No verified ransom demand or attacker financial gain was established in the cited material.
Ingram Micro said on July 8 that it believed unauthorized access had been contained and affected systems remediated. That statement addresses the company’s view of containment at that time; it does not resolve the unanswered questions about initial access or the extent of any data exposure.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Quick Recap
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Rank #4
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

