29.9 C
New York
Sunday, July 6, 2025

Ingram Micro outage brought on by SafePay ransomware assault


Ingram Micro outage brought on by SafePay ransomware assault

An ongoing outage at IT big Ingram Micro is brought on by a SafePay ransomware assault that led to the shutdown of inside methods, BleepingComputer has realized.

Ingram Micro is without doubt one of the world’s largest business-to-business know-how distributors and repair suppliers, providing a variety of options together with {hardware}, software program, cloud providers, logistics, and coaching to resellers and managed service suppliers worldwide.

Since Thursday, Ingram Micro’s web site and on-line ordering methods have been down, with the corporate not disclosing the reason for the problems.

BleepingComputer has now realized that the outages are brought on by a cyberattack that occurred early Thursday morning, with workers all of the sudden discovering ransom notes created on their units.

The ransom word, seen by BleepingComputer, is related to the SafePay ransomware operation, which has turn into one of many extra lively operations in 2025. It’s unclear if units had been really encrypted within the assault.

It needs to be famous that whereas the ransom word claims to have stolen all kinds of knowledge, that is generic language utilized in all SafePay ransom notes and is probably not true for the Ingram Micro assault.

SafePay ransom word discovered on Ingram Micro units
Supply: BleepingComputer

Do you will have details about this or one other cyberattack? If you wish to share the data, you’ll be able to contact us securely and confidentially on Sign at LawrenceA.11, by way of e-mail at lawrence.abrams@bleepingcomputer.com, or through the use of our suggestions kind.

Sources have instructed BleepingComputer that it’s believed the risk actors breached Ingram Micro via its GlobalProtect VPN platform.

As soon as the assault was found, workers in some areas had been instructed to make money working from home. The corporate additionally shut down inside methods, telling workers to not use the corporate’s GlobalProtect VPN entry, which was stated to be impacted by the IT outage.

Techniques which can be impacted in lots of areas embody the corporate’s AI-powered Xvantage distribution platform and the Impulse license provisioning platform. Nonetheless, BleepingComputer was instructed that different inside providers, comparable to Microsoft 365, Groups, and SharePoint, proceed to function as standard.

As of yesterday, Ingram Micro has not disclosed the assault publicly or to its workers, solely stating there are ongoing IT points, as indicated by company-wide advisories shared with BleepingComputer.

The SafePay ransomware gang is a comparatively new operation that was first seen in November 2024, accumulating over 220 victims since then.

The ransomware operation has been beforehand noticed breaching company networks via VPN gateways utilizing compromised credentials and password spray assaults.

BleepingComputer contacted Ingram Micro yesterday and at the moment concerning the outages and ransomware assault, however didn’t obtain a response to our emails.

Whereas cloud assaults could also be rising extra subtle, attackers nonetheless succeed with surprisingly easy methods.

Drawing from Wiz’s detections throughout hundreds of organizations, this report reveals 8 key methods utilized by cloud-fluent risk actors.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles