
Ingram Micro Company Cyber Security Posture
ingrammicro.comIngram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to a highly diversified base of business-to-business technology experts. Through Ingram Micro Xvantageโข, our AI-powered digital platform, we offer what we believe to be the industryโs first comprehensive business-to-consumer-like experience, integrating hardware and cloud subscriptions, personalized recommendations, instant pricing, order tracking, and billing automation. We also provide a broad range of technology services, including financing, specialized marketing, and lifecycle management, as well as technical pre- and post-sales professional support. Learn more at www.ingrammicro.com.
Ingram Micro Company Details
ingram-micro
28454 employees
535241.0
541
IT Services and IT Consulting
ingrammicro.com
Scan still pending
ING_5511879
In-progress

Between 900 and 1000
This score is AI-generated and less favored by cyber insurers, who prefer the TPRM score.

.png)

Ingram Micro Company Scoring based on AI Models
Model Name | Date | Description | Current Score Difference | Score |
---|---|---|---|---|
AVERAGE-Industry | 03-12-2025 | This score represents the average cybersecurity rating of companies already scanned within the same industry. It provides a benchmark to compare an individual company's security posture against its industry peers. | N/A | Between 900 and 1000 |
Ingram Micro Company Cyber Security News & History
Entity | Type | Severity | Impact | Seen | Url ID | Details | View |
---|---|---|---|---|---|---|---|
Ingram Micro | Ransomware | 100 | 5 | 7/2025 | ING721070725 | Link | |
Rankiteo Explanation : Attack threatening the organization's existenceDescription: Ingram Micro, a global distributor of information technology (IT) products and services, has confirmed it suffered a ransomware attack which forced it to shut down parts of its infrastructure, preventing it from operating properly, and sent some of its employees to work from home. The attack, reportedly the work of SafePay, encrypted data and left ransom notes on employee devices. The company's AI-powered Xvantage distribution platform and Impulse license provisioning platform were impacted. | |||||||
Ingram Micro Holding Corporation | Ransomware | 100 | 7/2025 | ING857071225 | Link | ||
Rankiteo Explanation : Attack threatening the organizationโs existenceDescription: Ingram Micro Holding Corporation experienced a significant cybersecurity incident where a ransomware attack disrupted its global operations. The attack, identified on July 5, 2025, affected critical internal systems including order processing, inventory management, and customer relationship functions. The malware encrypted files and employed sophisticated evasion techniques, impacting millions of downstream customers. Ingram Micro responded swiftly, taking affected systems offline and implementing containment protocols to prevent further data encryption. The recovery process included system reimaging and enhanced monitoring solutions to mitigate future risks. |
Ingram Micro Company Subsidiaries

Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to a highly diversified base of business-to-business technology experts. Through Ingram Micro Xvantageโข, our AI-powered digital platform, we offer what we believe to be the industryโs first comprehensive business-to-consumer-like experience, integrating hardware and cloud subscriptions, personalized recommendations, instant pricing, order tracking, and billing automation. We also provide a broad range of technology services, including financing, specialized marketing, and lifecycle management, as well as technical pre- and post-sales professional support. Learn more at www.ingrammicro.com.
Access Data Using Our API

Get company history
.png)
Ingram Micro Cyber Security News
Ingram Micro Scrambling to Restore Systems After Ransomware Attack
Ingram Micro was forced to take IT systems offline on July 4, in response to a ransomware attack.
Ingram Micro hit by ransomware attack
Ingram Micro has revealed it has become the victim of a ransomware attack. The distributor shared an update over the weekend detailing theย ...
Ingram Micro confirms ransomware attack after days of downtime
Ingram Micro confirms ransomware attack after days of downtime ยท The multi-day outage has disrupted order processing, delayed shipments, andย ...
Everything we know about the Ingram Micro cyber attack so far
Ingram Micro has been hit by a cyber attack believed to have been carried out by the SafePay ransomware group. The attack, which took placeย ...
Ingram Micro investigating ransomware attack
Ingram Micro said Saturday that it is investigating a ransomware attack after discovering suspicious activity on its internal network.
Ingram Micro Working Through Ransomware Attack by SafePay Group
Giant IT services distributor Ingram Micro appears to be the latest victim of SafePay, a fast-rising ransomware group that surfaced in 2024ย ...
Ingram Micro confirms ransomware attack, internal systems affected and shut down
Ingram Micro confirms ransomware attack, internal systems affected and shut down ยท Ingram Micro tells some employees to work from home as itย ...
Ingram Micro struggles to restore services after ransomware breach
Ingram Micro is recovering from a ransomware attack that disrupted services. ยท Service restoration is ongoing.
SafePay ransomware attack behind Ingram Micro disruption
Ingram Micro's disclosure comes after its employees' devices were reported to have been injected with ransom notes linked to the SafePayย ...

Ingram Micro Similar Companies

Zoom
Bring teams together, reimagine workspaces, engage new audiences, and delight your customers โโ all on the Zoom AI-first work platform you know and love. ๐ Zoomies help people stay connected so they can get more done together. We set out on a mission to make video communications frictionless and se

Sopra Steria
Sopra Steria, a major Tech player in Europe with 51,000 employees in nearly 30 countries, is recognised for its consulting, digital services and solutions. It helps its clients drive their digital transformation and obtain tangible and sustainable benefits. The Group provides end-to-end solutions to

Experis Brasil
Talent and solutions to drive innovation. When it comes to IT, having the right talent and focus means you can harness the power of technology to make smarter, faster decisions; connect more strongly with your customers; and drive innovation in your marketplace. At Experis IT, our prowess in pro

CGI
Insights you can act on to achieve trusted outcomes. We are insights-driven and outcomes-focused to help accelerate returns on your investments. Across 21 industry sectors and 400 locations worldwide, we provide comprehensive, scalable and sustainable IT and business consulting services that are in

Wipro
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clientsโ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, a

Coforge
Coforge is a global digital services and solutions provider, that leverages emerging technologies and deep domain expertise to deliver real-world business impact for its clients. A focus on select industries, a deep domain understanding of the underlying processes of those industries and partners

Frequently Asked Questions
Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
Ingram Micro CyberSecurity History Information
How many cyber incidents has Ingram Micro faced?
Total Incidents: According to Rankiteo, Ingram Micro has faced 2 incidents in the past.
What types of cybersecurity incidents have occurred at Ingram Micro?
Incident Types: The types of cybersecurity incidents that have occurred incidents Ransomware.
How does Ingram Micro detect and respond to cybersecurity incidents?
Detection and Response: The company detects and responds to cybersecurity incidents through containment measures with Taking affected systems offline, Preventing lateral movement and remediation measures with Comprehensive system reimaging, Backup restoration and recovery measures with Implementation of enhanced monitoring solutions and enhanced monitoring with Implementation of enhanced monitoring solutions and third party assistance with Third-party cybersecurity experts and law enforcement notified with Yes and containment measures with Systems taken offline, Employees sent to work from home and remediation measures with Mitigation measures implemented and recovery measures with Restoring affected systems and communication strategy with Press release published.
Incident Details
Can you provide details on each incident?

Incident : Ransomware
Title: Ransomware Attack on Ingram Micro Holding Corporation
Description: Ingram Micro Holding Corporation suffered a significant ransomware attack that disrupted its global operations and affected millions of downstream customers. The attack targeted critical internal systems, and the company took immediate containment measures to prevent further data encryption.
Date Detected: 2025-07-05
Type: Ransomware
Attack Vector: Undisclosed attack vectors, DLL side-loading techniques, Process hollowing techniques
Motivation: Financial gain

Incident : Ransomware
Title: Ingram Micro Ransomware Attack
Description: Ingram Micro, a global distributor of IT products and services, suffered a ransomware attack which forced it to shut down parts of its infrastructure and sent some employees to work from home.
Type: Ransomware
Attack Vector: GlobalProtect VPN platform
Threat Actor: SafePay
Motivation: Financial gain, Data theft
What are the most common types of attacks the company has faced?
Common Attack Types: The most common types of attacks the company has faced is Ransomware.
How does the company identify the attack vectors used in incidents?
Identification of Attack Vectors: The company identifies the attack vectors used in incidents through GlobalProtect VPN platform.
Impact of the Incidents
What was the impact of each incident?

Incident : Ransomware ING857071225
Systems Affected: Order processing, Inventory management, Customer relationship functions
Downtime: ['Four days']
Operational Impact: Global operations disruption

Incident : Ransomware ING721070725
Systems Affected: AI-powered Xvantage distribution platform, Impulse license provisioning platform
Operational Impact: Disruption in processing and shipping orders
Which entities were affected by each incident?

Incident : Ransomware ING857071225
Entity Type: Technology distribution company
Industry: Technology
Location: Global
Customers Affected: Millions of downstream customers

Incident : Ransomware ING721070725
Entity Type: IT products and services distributor
Industry: Information Technology
Location: Global
Size: Large (servicing over 160,000 customers globally)
Response to the Incidents
What measures were taken in response to each incident?

Incident : Ransomware ING857071225
Containment Measures: Taking affected systems offline, Preventing lateral movement
Remediation Measures: Comprehensive system reimaging, Backup restoration
Recovery Measures: Implementation of enhanced monitoring solutions
Enhanced Monitoring: Implementation of enhanced monitoring solutions

Incident : Ransomware ING721070725
Third Party Assistance: Third-party cybersecurity experts
Law Enforcement Notified: Yes
Containment Measures: Systems taken offline, Employees sent to work from home
Remediation Measures: Mitigation measures implemented
Recovery Measures: Restoring affected systems
Communication Strategy: Press release published
How does the company involve third-party assistance in incident response?
Third-Party Assistance: The company involves third-party assistance in incident response through Third-party cybersecurity experts.
Data Breach Information
What type of data was compromised in each breach?

Incident : Ransomware ING857071225
Data Encryption: ['Files encryption across certain internal systems']
What measures does the company take to prevent data exfiltration?
Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Comprehensive system reimaging, Backup restoration, Mitigation measures implemented.
How does the company handle incidents involving personally identifiable information (PII)?
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through were Taking affected systems offline, Preventing lateral movement, Systems taken offline and Employees sent to work from home.
Ransomware Information
Was ransomware involved in any of the incidents?

Incident : Ransomware ING857071225
Data Encryption: ['Files encryption across certain internal systems']

Incident : Ransomware ING721070725
Ransomware Strain: SafePay
How does the company recover data encrypted by ransomware?
Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Restoring affected systems.
References
Where can I find more information about each incident?

Incident : Ransomware ING721070725
Source: TechRadar
Where can stakeholders find additional resources on cybersecurity best practices?
Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: TechRadar.
Investigation Status
What is the current status of the investigation for each incident?

Incident : Ransomware ING721070725
Investigation Status: Ongoing
How does the company communicate the status of incident investigations to stakeholders?
Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through was Press release published.
Initial Access Broker
How did the initial access broker gain entry for each incident?

Incident : Ransomware ING857071225
High Value Targets: Order processing, Inventory management, Customer relationship functions
Data Sold on Dark Web: Order processing, Inventory management, Customer relationship functions

Incident : Ransomware ING721070725
Entry Point: GlobalProtect VPN platform
Post-Incident Analysis
What is the company's process for conducting post-incident analysis?
Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Implementation of enhanced monitoring solutions, Third-party cybersecurity experts.
Additional Questions
General Information
Who was the attacking group in the last incident?
Last Attacking Group: The attacking group in the last incident was an SafePay.
Incident Details
What was the most recent incident detected?
Most Recent Incident Detected: The most recent incident detected was on 2025-07-05.
Impact of the Incidents
What was the most significant system affected in an incident?
Most Significant System Affected: The most significant system affected in an incident were Order processing, Inventory management, Customer relationship functions and AI-powered Xvantage distribution platform, Impulse license provisioning platform.
Response to the Incidents
What third-party assistance was involved in the most recent incident?
Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Third-party cybersecurity experts.
What containment measures were taken in the most recent incident?
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Taking affected systems offline, Preventing lateral movement, Systems taken offline and Employees sent to work from home.
References
What is the most recent source of information about an incident?
Most Recent Source: The most recent source of information about an incident is TechRadar.
Investigation Status
What is the current status of the most recent investigation?
Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.
Initial Access Broker
What was the most recent entry point used by an initial access broker?
Most Recent Entry Point: The most recent entry point used by an initial access broker was an GlobalProtect VPN platform.
What Do We Measure?
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
These are some of the factors we use to calculate the overall score:
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.
