Ingram Micro Company Cyber Security Posture

ingrammicro.com

Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to a highly diversified base of business-to-business technology experts. Through Ingram Micro Xvantageโ„ข, our AI-powered digital platform, we offer what we believe to be the industryโ€™s first comprehensive business-to-consumer-like experience, integrating hardware and cloud subscriptions, personalized recommendations, instant pricing, order tracking, and billing automation. We also provide a broad range of technology services, including financing, specialized marketing, and lifecycle management, as well as technical pre- and post-sales professional support. Learn more at www.ingrammicro.com.

Ingram Micro Company Details

Linkedin ID:

ingram-micro

Employees number:

28454 employees

Number of followers:

535241.0

NAICS:

541

Industry Type:

IT Services and IT Consulting

Homepage:

ingrammicro.com

IP Addresses:

Scan still pending

Company ID:

ING_5511879

Scan Status:

In-progress

AI scoreIngram Micro Risk Score (AI oriented)

Between 900 and 1000

This score is AI-generated and less favored by cyber insurers, who prefer the TPRM score.

globalscoreIngram Micro Global Score
blurone
Ailogo

Ingram Micro Company Scoring based on AI Models

Model NameDateDescriptionCurrent Score DifferenceScore
AVERAGE-Industry03-12-2025

This score represents the average cybersecurity rating of companies already scanned within the same industry. It provides a benchmark to compare an individual company's security posture against its industry peers.

N/A

Between 900 and 1000

Ingram Micro Company Cyber Security News & History

Past Incidents
2
Attack Types
1
EntityTypeSeverityImpactSeenUrl IDDetailsView
Ingram MicroRansomware10057/2025ING721070725Link
Rankiteo Explanation :
Attack threatening the organization's existence

Description: Ingram Micro, a global distributor of information technology (IT) products and services, has confirmed it suffered a ransomware attack which forced it to shut down parts of its infrastructure, preventing it from operating properly, and sent some of its employees to work from home. The attack, reportedly the work of SafePay, encrypted data and left ransom notes on employee devices. The company's AI-powered Xvantage distribution platform and Impulse license provisioning platform were impacted.

Ingram Micro Holding CorporationRansomware1007/2025ING857071225Link
Rankiteo Explanation :
Attack threatening the organizationโ€™s existence

Description: Ingram Micro Holding Corporation experienced a significant cybersecurity incident where a ransomware attack disrupted its global operations. The attack, identified on July 5, 2025, affected critical internal systems including order processing, inventory management, and customer relationship functions. The malware encrypted files and employed sophisticated evasion techniques, impacting millions of downstream customers. Ingram Micro responded swiftly, taking affected systems offline and implementing containment protocols to prevent further data encryption. The recovery process included system reimaging and enhanced monitoring solutions to mitigate future risks.

Ingram Micro Company Subsidiaries

SubsidiaryImage

Ingram Micro is a leading technology company for the global information technology ecosystem. With the ability to reach nearly 90% of the global population, we play a vital role in the worldwide IT sales channel, bringing products and services from technology manufacturers and cloud providers to a highly diversified base of business-to-business technology experts. Through Ingram Micro Xvantageโ„ข, our AI-powered digital platform, we offer what we believe to be the industryโ€™s first comprehensive business-to-consumer-like experience, integrating hardware and cloud subscriptions, personalized recommendations, instant pricing, order tracking, and billing automation. We also provide a broad range of technology services, including financing, specialized marketing, and lifecycle management, as well as technical pre- and post-sales professional support. Learn more at www.ingrammicro.com.

Loading...

Access Data Using Our API

SubsidiaryImage

Get company history

curl -i -X GET 'https://api.rankiteo.com/underwriter-getcompany-history?linkedin_id=ingram-micro' -H 'apikey: YOUR_API_KEY_HERE'
newsone

Ingram Micro Cyber Security News

2025-07-07T12:50:42.000Z
Ingram Micro Scrambling to Restore Systems After Ransomware Attack

Ingram Micro was forced to take IT systems offline on July 4, in response to a ransomware attack.

2025-07-07T12:15:07.000Z
Ingram Micro hit by ransomware attack

Ingram Micro has revealed it has become the victim of a ransomware attack. The distributor shared an update over the weekend detailing theย ...

2025-07-07T11:45:31.000Z
Ingram Micro confirms ransomware attack after days of downtime

Ingram Micro confirms ransomware attack after days of downtime ยท The multi-day outage has disrupted order processing, delayed shipments, andย ...

2025-07-07T10:03:14.000Z
Everything we know about the Ingram Micro cyber attack so far

Ingram Micro has been hit by a cyber attack believed to have been carried out by the SafePay ransomware group. The attack, which took placeย ...

2025-07-07T15:39:30.000Z
Ingram Micro investigating ransomware attack

Ingram Micro said Saturday that it is investigating a ransomware attack after discovering suspicious activity on its internal network.

2025-07-07T13:57:38.000Z
Ingram Micro Working Through Ransomware Attack by SafePay Group

Giant IT services distributor Ingram Micro appears to be the latest victim of SafePay, a fast-rising ransomware group that surfaced in 2024ย ...

2025-07-07T14:05:00.000Z
Ingram Micro confirms ransomware attack, internal systems affected and shut down

Ingram Micro confirms ransomware attack, internal systems affected and shut down ยท Ingram Micro tells some employees to work from home as itย ...

2025-07-07T09:20:48.000Z
Ingram Micro struggles to restore services after ransomware breach

Ingram Micro is recovering from a ransomware attack that disrupted services. ยท Service restoration is ongoing.

2025-07-07T12:19:32.000Z
SafePay ransomware attack behind Ingram Micro disruption

Ingram Micro's disclosure comes after its employees' devices were reported to have been injected with ransom notes linked to the SafePayย ...

similarCompanies

Ingram Micro Similar Companies

Bring teams together, reimagine workspaces, engage new audiences, and delight your customers โ€“โ€“ all on the Zoom AI-first work platform you know and love. ๐Ÿ’™ Zoomies help people stay connected so they can get more done together. We set out on a mission to make video communications frictionless and se

Sopra Steria, a major Tech player in Europe with 51,000 employees in nearly 30 countries, is recognised for its consulting, digital services and solutions. It helps its clients drive their digital transformation and obtain tangible and sustainable benefits. The Group provides end-to-end solutions to

Experis Brasil

Talent and solutions to drive innovation. When it comes to IT, having the right talent and focus means you can harness the power of technology to make smarter, faster decisions; connect more strongly with your customers; and drive innovation in your marketplace. At Experis IT, our prowess in pro

Insights you can act on to achieve trusted outcomes. We are insights-driven and outcomes-focused to help accelerate returns on your investments. Across 21 industry sectors and 400 locations worldwide, we provide comprehensive, scalable and sustainable IT and business consulting services that are in

Wipro

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading technology services and consulting company focused on building innovative solutions that address clientsโ€™ most complex digital transformation needs. Leveraging our holistic portfolio of capabilities in consulting, design, engineering, a

Coforge

Coforge is a global digital services and solutions provider, that leverages emerging technologies and deep domain expertise to deliver real-world business impact for its clients. A focus on select industries, a deep domain understanding of the underlying processes of those industries and partners

faq

Frequently Asked Questions

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.

Ingram Micro CyberSecurity History Information

How many cyber incidents has Ingram Micro faced?

Total Incidents: According to Rankiteo, Ingram Micro has faced 2 incidents in the past.

What types of cybersecurity incidents have occurred at Ingram Micro?

Incident Types: The types of cybersecurity incidents that have occurred incidents Ransomware.

How does Ingram Micro detect and respond to cybersecurity incidents?

Detection and Response: The company detects and responds to cybersecurity incidents through containment measures with Taking affected systems offline, Preventing lateral movement and remediation measures with Comprehensive system reimaging, Backup restoration and recovery measures with Implementation of enhanced monitoring solutions and enhanced monitoring with Implementation of enhanced monitoring solutions and third party assistance with Third-party cybersecurity experts and law enforcement notified with Yes and containment measures with Systems taken offline, Employees sent to work from home and remediation measures with Mitigation measures implemented and recovery measures with Restoring affected systems and communication strategy with Press release published.

Incident Details

Can you provide details on each incident?

Incident : Ransomware

Title: Ransomware Attack on Ingram Micro Holding Corporation

Description: Ingram Micro Holding Corporation suffered a significant ransomware attack that disrupted its global operations and affected millions of downstream customers. The attack targeted critical internal systems, and the company took immediate containment measures to prevent further data encryption.

Date Detected: 2025-07-05

Type: Ransomware

Attack Vector: Undisclosed attack vectors, DLL side-loading techniques, Process hollowing techniques

Motivation: Financial gain

Incident : Ransomware

Title: Ingram Micro Ransomware Attack

Description: Ingram Micro, a global distributor of IT products and services, suffered a ransomware attack which forced it to shut down parts of its infrastructure and sent some employees to work from home.

Type: Ransomware

Attack Vector: GlobalProtect VPN platform

Threat Actor: SafePay

Motivation: Financial gain, Data theft

What are the most common types of attacks the company has faced?

Common Attack Types: The most common types of attacks the company has faced is Ransomware.

How does the company identify the attack vectors used in incidents?

Identification of Attack Vectors: The company identifies the attack vectors used in incidents through GlobalProtect VPN platform.

Impact of the Incidents

What was the impact of each incident?

Incident : Ransomware ING857071225

Systems Affected: Order processing, Inventory management, Customer relationship functions

Downtime: ['Four days']

Operational Impact: Global operations disruption

Incident : Ransomware ING721070725

Systems Affected: AI-powered Xvantage distribution platform, Impulse license provisioning platform

Operational Impact: Disruption in processing and shipping orders

Which entities were affected by each incident?

Incident : Ransomware ING857071225

Entity Type: Technology distribution company

Industry: Technology

Location: Global

Customers Affected: Millions of downstream customers

Incident : Ransomware ING721070725

Entity Type: IT products and services distributor

Industry: Information Technology

Location: Global

Size: Large (servicing over 160,000 customers globally)

Response to the Incidents

What measures were taken in response to each incident?

Incident : Ransomware ING857071225

Containment Measures: Taking affected systems offline, Preventing lateral movement

Remediation Measures: Comprehensive system reimaging, Backup restoration

Recovery Measures: Implementation of enhanced monitoring solutions

Enhanced Monitoring: Implementation of enhanced monitoring solutions

Incident : Ransomware ING721070725

Third Party Assistance: Third-party cybersecurity experts

Law Enforcement Notified: Yes

Containment Measures: Systems taken offline, Employees sent to work from home

Remediation Measures: Mitigation measures implemented

Recovery Measures: Restoring affected systems

Communication Strategy: Press release published

How does the company involve third-party assistance in incident response?

Third-Party Assistance: The company involves third-party assistance in incident response through Third-party cybersecurity experts.

Data Breach Information

What type of data was compromised in each breach?

Incident : Ransomware ING857071225

Data Encryption: ['Files encryption across certain internal systems']

What measures does the company take to prevent data exfiltration?

Prevention of Data Exfiltration: The company takes the following measures to prevent data exfiltration: Comprehensive system reimaging, Backup restoration, Mitigation measures implemented.

How does the company handle incidents involving personally identifiable information (PII)?

Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through were Taking affected systems offline, Preventing lateral movement, Systems taken offline and Employees sent to work from home.

Ransomware Information

Was ransomware involved in any of the incidents?

Incident : Ransomware ING857071225

Data Encryption: ['Files encryption across certain internal systems']

Incident : Ransomware ING721070725

Ransomware Strain: SafePay

How does the company recover data encrypted by ransomware?

Data Recovery from Ransomware: The company recovers data encrypted by ransomware through Restoring affected systems.

References

Where can I find more information about each incident?

Incident : Ransomware ING721070725

Source: TechRadar

Where can stakeholders find additional resources on cybersecurity best practices?

Additional Resources: Stakeholders can find additional resources on cybersecurity best practices at and Source: TechRadar.

Investigation Status

What is the current status of the investigation for each incident?

Incident : Ransomware ING721070725

Investigation Status: Ongoing

How does the company communicate the status of incident investigations to stakeholders?

Communication of Investigation Status: The company communicates the status of incident investigations to stakeholders through was Press release published.

Initial Access Broker

How did the initial access broker gain entry for each incident?

Incident : Ransomware ING857071225

High Value Targets: Order processing, Inventory management, Customer relationship functions

Data Sold on Dark Web: Order processing, Inventory management, Customer relationship functions

Incident : Ransomware ING721070725

Entry Point: GlobalProtect VPN platform

Post-Incident Analysis

What is the company's process for conducting post-incident analysis?

Post-Incident Analysis Process: The company's process for conducting post-incident analysis is described as Implementation of enhanced monitoring solutions, Third-party cybersecurity experts.

Additional Questions

General Information

Who was the attacking group in the last incident?

Last Attacking Group: The attacking group in the last incident was an SafePay.

Incident Details

What was the most recent incident detected?

Most Recent Incident Detected: The most recent incident detected was on 2025-07-05.

Impact of the Incidents

What was the most significant system affected in an incident?

Most Significant System Affected: The most significant system affected in an incident were Order processing, Inventory management, Customer relationship functions and AI-powered Xvantage distribution platform, Impulse license provisioning platform.

Response to the Incidents

What third-party assistance was involved in the most recent incident?

Third-Party Assistance in Most Recent Incident: The third-party assistance involved in the most recent incident was Third-party cybersecurity experts.

What containment measures were taken in the most recent incident?

Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Taking affected systems offline, Preventing lateral movement, Systems taken offline and Employees sent to work from home.

References

What is the most recent source of information about an incident?

Most Recent Source: The most recent source of information about an incident is TechRadar.

Investigation Status

What is the current status of the most recent investigation?

Current Status of Most Recent Investigation: The current status of the most recent investigation is Ongoing.

Initial Access Broker

What was the most recent entry point used by an initial access broker?

Most Recent Entry Point: The most recent entry point used by an initial access broker was an GlobalProtect VPN platform.

What Do We Measure?

revertimgrevertimgrevertimgrevertimg
Incident
revertimgrevertimgrevertimgrevertimg
Finding
revertimgrevertimgrevertimgrevertimg
Grade
revertimgrevertimgrevertimgrevertimg
Digital Assets

Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.

These are some of the factors we use to calculate the overall score:

Network Security

Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.

SBOM (Software Bill of Materials)

Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.

CMDB (Configuration Management Database)

Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.

Threat Intelligence

Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.

Top LeftTop RightBottom LeftBottom Right
Rankiteo is a unified scoring and risk platform that analyzes billions of signals weekly to help organizations gain faster, more actionable insights into emerging threats. Empowering teams to outpace adversaries and reduce exposure.
Users Love Us Badge