惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
博客园 - 叶小钗
WordPress大学
WordPress大学
N
Netflix TechBlog - Medium
M
MIT News - Artificial intelligence
美团技术团队
aimingoo的专栏
aimingoo的专栏
博客园_首页
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
Last Week in AI
Last Week in AI
The GitHub Blog
The GitHub Blog
小众软件
小众软件
T
Tailwind CSS Blog
Martin Fowler
Martin Fowler
B
Blog RSS Feed
月光博客
月光博客
量子位
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
Y
Y Combinator Blog
B
Blog
MyScale Blog
MyScale Blog

The Register - Off-Prem: Channel

'Death sentence': EU cloud lobby drags Broadcom to Brussels Iran war wreaking havoc on cargo, global delays likely OpenAI asks consultants to help it push Frontier OpenAI asks consultants to help it push Frontier ICO wins battle in fight to fine tech retailer £500k Rising memory costs see vendors change terms and conditions Capgemini to sell biz that has a deal to help ICE Ingram Micro admits ransomware raid exposed staff records Hiring at India’s Big Four outsourcers stalls as AI bites Hiring at India’s Big Four outsourcers stalls as AI bites Accenture to buy Palantir rival, UK-based Faculty The ‘Palantir-ization’ of IT services is upon us Amazon straps AI smart specs to delivery drivers Microsoft pivots to copyright claim in ValueLicensing case Client defended engineer boss lied about dodgy dealings Client defended engineer boss lied about dodgy dealings Node4 awarded £2.4M in damages after Tisski takeover Trump tariff turmoil toys with PC sales, economy not helping Everyone needs an AI phone. No, don't hang up, it's true Microsoft software reselling dispute heads back to UK court KPMG wrote 100-page prompt to build agentic TaxBot Google admits anticompetitive conduct in Australia Foxconn now making more from servers than iPhones Stock in the Channel pulls website amid cyberattack Ebuyer website bought by Fraser Group plc Ingram Micro attackers threaten 3.5 TB data leak this week India, not China, manufactures most US smartphones now India, not China, manufactures most US smartphones now Microsoft exec admits it 'cannot guarantee' data sovereignty Infosec firm Adarma confirms it will enter administration
Ingram Micro confirms ransomware behind multi-day outage
2025-07-06 · via The Register - Off-Prem: Channel

Updated Ingram Micro, one of the world's largest distributors, has confirmed it is trying to restore systems following a ransomware attack.

As exclusively revealed, troubles began on July 3 when trade customers – resellers and managed service providers – complained they were no longer able place orders after systems and phone lines went down.

Messages dispatched by The Register to contact company execs and its press relations department went unanswered. Ingram Micro finally broke its silence yesterday at around 3pm UTC amid an "ongoing system outage."

The distributor said: "Ingram Micro recently identified ransomware on certain of its internal systems. Promptly after learning of the issue, the company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.

"Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the company apologizes for any disruption this issue is causing its customers, vendor partners, and others."

Orders for physical products could not be placed and Ingram was also unable to manage Microsoft 365 and Dropbox licenses. A source told us staff at Ingram's Bulgaria-based service center were sent home on July 4 and asked to keep their laptops disconnected as systems were turned off.

Ingram turns over hundreds of millions of dollars a day in sales so disruption to service even for a day is a big deal. It generated revenues of $48 billion in its prior financial year ended December 28, 2024, and recorded a profit of $262.2 million, selling a range of hardware, software, cloud services, IT asset disposition, third-party logistics, dropship and returns management, and remarketing.

The SafePay ransomware crew has taken responsibility for the attack, according to Bleeping Computer, which published a ransom note from the criminals. In it, SafePay claims it exploited "a number of mistakes" Ingram made "in setting up the security of your corporate network, so we were able to spend quite a long time in it and compromise you."

"It was the misconfiguration of your network that allowed our experts to attack you, so treat this situation as simply as a paid training session for your system administrators."

The note claims the intruders accessed "sensitive and confidential information" including documents pertaining to financials statements, intellectual property, accounting records, lawsuits and complaints, personal and customer files, bank details, transactions, and more.

It adds that "all files of importance have been encrypted" and vital data stored on a secure server for "further exploitation and publication on the web with an open access." It further claims SafePay blocked Ingram's servers and will "unlock" them when an agreement is reached.

"WE ARE THE ONES WHO CAN CORRECTLY DECRYPT YOUR DATA AND RESTORE YOUR INFRASTRUCTURE IN A SHORT TIME," the ransom note claims in capped letters.

This is not a politically motivated attack and the crew "want nothing more than money." Ingram has seven days to negotiate.

As always, readers should treat the claims with some suspicion until independently verified.

The SafePay crew may have entered Ingram's systems via its GlobalProtect VPN platform, sources told Bleeping Computer. This remains unconfirmed.

SafePay was the most active ransomware crew in the world in May, according to threat intelligence service Fortra, with 70 attacks alone linked to the gang and its affiliates that month. Microlise was a high-profile victim attacked in October last year.

Graham Cluley, Fortra's cybercrime researcher, said last month: "SafePay is known for breaking into organizations by using stolen VPN or RDP credentials. It has not been reported to have used phishing techniques frequently seen in many other ransomware attacks. Therefore, organizations that worry they might be targeted would be wise to enforce multi-factor authentication on all remote access points, disable unused RDP or VPN access entirely, and use IP allowlists or geofencing where possible."

The Register has asked Ingram Micro to comment. ®

Updated at 16.43 on July 7, 2025, to add:

Following publication of this article, a spokesperson at Palo Alto Networks got in touch to tell us it is probing claims that GlobalProtect VPN is the entry point in the intrusion at Ingram Micro.

"We are aware of a cybersecurity incident impacting Ingram Micro and reports that mention Palo Alto Networks’ GlobalProtect VPN. We are currently investigating these claims. Threat actors routinely attempt to exploit stolen credentials or network misconfigurations to gain access through VPN gateways."