Skip to content

Ingram Micro

Disclosed Jul 5, 20251 year ago42,521 affectedConfirmed

Official notice

SafePay ransomware attack shuts down Ingram Micro, exposes 42,000 people

Ingram Micro said a ransomware attack that began July 3, 2025 caused a global outage of its ordering and licensing systems; the SafePay gang claimed it and threatened to leak 3.5TB of data. Ingram Micro later told Maine's attorney general that files with employee and job applicant data, including SSNs and ID numbers, of over 42,000 people were taken.

What is known

People affected42,521 (as reported by the organization)
DisclosedJul 5, 2025
DiscoveredJul 3, 2025
HappenedJul 2, 2025
AttackRansomware
Data exposedInternal documents, Names, Dates of birth, Social Security numbers, Government IDs, Employment, Health, Insurance, Addresses
SectorTech · US
StatusConfirmed

Sources

Notices filed

WhereFiledPeople
ResearchtotalJul 5, 202542,000
California AGresidents of CAJan 16
Vermont AGresidents of VTJan 16
Indiana AGresidents of INJan 164,136
Texas AGresidents of TXJan 213,079
History of this record
  • 2026-09-25 · source: empty to https://www.in.gov/attorneygeneral/consumer-protection-division/id-theft-prevention/files/DB-Year-to-Date-Report-7_2026.pdf · backfill source
  • 2026-09-25 · source: empty to https://ago.vermont.gov/document/2026-01-16-ingram-micro-data-breach-notice-consumers · backfill source
  • 2026-09-25 · data_types: ["internal-docs","names","dob","ssn","government-id","employment"] to ["internal-docs","names","dob","ssn","government-id","employment","health","insurance","addresses"] · backfill source
  • 2026-09-25 · records: 42000 to 42521 · backfill source
  • 2026-09-25 · sector: other to tech · seed source
  • 2026-09-25 · attack: unknown to ransomware · seed source
  • 2026-09-25 · data_types: [] to ["internal-docs","names","dob","ssn","government-id","employment"] · seed source
  • 2026-09-25 · records_basis: empty to organization · seed source
  • 2026-09-25 · records: empty to 42000 · seed source
  • 2026-09-25 · disclosed: 2026-01-16 to 2025-07-05 · seed source
  • 2026-09-25 · discovered: empty to 2025-07-03 · seed source
  • 2026-09-25 · summary: empty to Ingram Micro said a ransomware attack that began July 3, 2025 caused a global outage of its ordering and licensing systems; the SafePay gang claimed it and threatened to leak 3.5TB of data. Ingram Micro later told Maine's attorney general t · seed source
  • 2026-09-25 · title: empty to SafePay ransomware attack shuts down Ingram Micro, exposes 42,000 people · seed source
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (California AG), confirmed by California AG. Record counts are as reported. Not legal advice.

Everything about Ingram Micro

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.