An ongoing outage at Ingram Micro caused by a ransomware attack has led to supply chain problems affecting the IT and networking fields.
The IT distribution giant fell victim to an attack by ransomware group SafePay, which has seen the shutdown of its website, sales systems, and customer service channels.
Trouble began last week, with a global blackout first reported by The Register. Managed service providers (MSPs) reported being unable to manage their customers' services, while others weren’t able to place orders for hardware and critical software backup licenses.
Since then, Ingram Micro's partner portal has been unavailable, blocking the management of Microsoft 365 licenses, Dropbox licenses, hardware purchases, and more.
According to Bleeping Computer, Ingram employees found ransom notes created on their devices, with the attack claimed by a young but increasingly prolific ransomware group.
The site reports SafePay breached Ingram’s systems through its GlobalProtect VPN platform, in a stark reminder to network players to audit VPN security and add MFA/network segmentation to systems.
The group has given Ingram Micro seven days to pay up. According to cybersecurity firm Fortra, SafePay develops and deploys the ransomware themselves instead of relying on affiliates, thus claiming all the spoils.
A report from NCC Group meanwhile attributes SafePay to 70 attacks in May 2025, accounting for 18 percent of the total number of compromises measured in that month.
In a statement released Monday, Ingram Micro confirmed the attack, commenting:
“Ingram Micro recently identified ransomware on certain of its internal systems. Promptly after learning of the issue, the Company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.
“Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the Company apologizes for any disruption this issue is causing its customers, vendor partners, and others.”
The damage may have already been done, though, with CRN reporting that partners are already looking for alternative sources, with at least one S&P 500 company reaching out to Ingram rival TD Synnex for support with their procurement operations.
Comments