惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
IT之家
IT之家
H
Help Net Security
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
The GitHub Blog
The GitHub Blog
V
V2EX
M
MIT News - Artificial intelligence
Vercel News
Vercel News
WordPress大学
WordPress大学
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
阮一峰的网络日志
阮一峰的网络日志
B
Blog RSS Feed
D
Docker
V
Visual Studio Blog
博客园 - 叶小钗
美团技术团队
S
SegmentFault 最新的问题
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

The Register - Off-Prem: Channel

'Death sentence': EU cloud lobby drags Broadcom to Brussels Iran war wreaking havoc on cargo, global delays likely OpenAI asks consultants to help it push Frontier OpenAI asks consultants to help it push Frontier ICO wins battle in fight to fine tech retailer £500k Rising memory costs see vendors change terms and conditions Capgemini to sell biz that has a deal to help ICE Ingram Micro admits ransomware raid exposed staff records Hiring at India’s Big Four outsourcers stalls as AI bites Hiring at India’s Big Four outsourcers stalls as AI bites Accenture to buy Palantir rival, UK-based Faculty The ‘Palantir-ization’ of IT services is upon us Amazon straps AI smart specs to delivery drivers Microsoft pivots to copyright claim in ValueLicensing case Client defended engineer boss lied about dodgy dealings Client defended engineer boss lied about dodgy dealings Node4 awarded £2.4M in damages after Tisski takeover Trump tariff turmoil toys with PC sales, economy not helping Everyone needs an AI phone. No, don't hang up, it's true Microsoft software reselling dispute heads back to UK court KPMG wrote 100-page prompt to build agentic TaxBot Google admits anticompetitive conduct in Australia Foxconn now making more from servers than iPhones Stock in the Channel pulls website amid cyberattack Ebuyer website bought by Fraser Group plc Ingram Micro attackers threaten 3.5 TB data leak this week India, not China, manufactures most US smartphones now India, not China, manufactures most US smartphones now Microsoft exec admits it 'cannot guarantee' data sovereignty Infosec firm Adarma confirms it will enter administration
Ingram Micro restarts orders – for some – following ranso...
2025-07-09 · via The Register - Off-Prem: Channel

Ingram Micro says it is gradually reactivating customer's ordering capabilities across the world, region by region, now its ransomware attack is thought to be "contained".

The distie's update on Tuesday confirmed that three days after pulling systems offline to handle its ransomware attack: "we believe the unauthorized access to our systems in connection with the incident is contained and the affected systems remediated."

"We have implemented additional safeguards and monitoring measures to protect our network environment as we bring our systems back online," it added.

While investigations into the scope of the attack remain ongoing, customers are waking up to the news that they can once again start placing orders for subscriptions and other products via phone and email.

Ingram said it was making strides with restoring its transactional business, although regional limitations were in place.

However, new territories are having their ordering capabilities restored each day.

Global availability of subscription orders, renewals, and modifications is now in place, and these are being managed by its support organization, Unified Support.

New orders can also be placed via phone and email in select countries: the UK, US, Germany, France, Italy, Spain, Austria, Canada, Singapore, the Nordics, Brazil, India, and China. 

Hardware and other technology orders remain limited, but these limitations will be communicated as customer orders are placed, it said in a revised statement yesterday.

The business turns over around $190 million each working day, so those "limitations" are of concern. Each day of downtime equates to a wad of money, some of it potentially lost to rivals. The distie reported revenues of $12.28 billion in its most recent quarter ended March 29.

Sources speaking to The Register said Ingram Micro has not been communicating with customers directly, and they only knew where to look for updates after we pointed them to the right page.

They said on Tuesday that support remains patchy, with telephone hold queues so lengthy that they had to abandon efforts to increase a client's Dropbox license count for new starters.

Attempts to email customer support are met with automated responses that cite the ongoing disruption to systems and restoration struggles.

Both phone and email routes that are suggested to customers via Unified Support were attempted but were unsuccessful. The customer portal remains down.

Fears remain about data security with respect to customers and their clients, and Ingram Micro has yet to release any details about the potential impact on data caused by the attack.

"The lack of communication is poor," one customer said. "I get they might not want to reveal all, but some communication and reassurance would be appreciated."

The news follows a cyberattack which the company confirmed to involve ransomware over the weekend. Several customers contacted The Register last week to complain about a lengthy outage at the distie while left with no official comms to support them through the disruption.

Talk of foul play quickly grew feverish and customer fears were validated on Saturday, July 5, when the company attributed the issues to ransomware, after the SafePay group claimed responsibility for the attack.

The full extent of the intrusion is not yet known, although Ingram Micro's ordering process was down for hours, and it still remained hobbled yesterday.

For a company with a turnover the size of Ingram's, any disruption to key revenue streams such as orders and subscriptions could have a sizable impact on its bottom line.

According to financial results, the distrubtor's net sales totaled $48.0 billion in fiscal 2024 ended December 28.

While Ingram's recent sales were halted, some of those orders will have been held and some will continue to be placed with the distributor now and after the disruption subsides. 

However, it's entirely possible that a chunk of these sales – however big or small – will be placed with competitors, further compounding the significant costs associated with cleaning up a ransomware mess.

According to security shop Huntress, the average cost of recovering from a ransomware attack is now in excess of $4.5 million. The figure invariably rises and falls depending on the size of the company and their industry.

The average ransom demand alone stands at $2.5 million. 

Ransomware affiliates claim to analyze a victim's financials, where available, and make determinations based on that, although these analyses are frequently miscalculated or poorly estimated.

According to the ransom note left behind by the SafePay affiliate responsible for the intrusion, the distie had seven days from the time of receipt to pay their extortion demands or risk having its data posted online.

The affiliate allegedly broke into Ingram's network via its GlobalProtect VPN platform, but Palo Alto Networks told us that after looking into these claims has now determined this is "false".

"We can confirm that none of our products were either the source of the vulnerability or impacted by the breach." ®