Ingram Micro outage caused by SafePay ransomware attack

Ingram Micro Faces Disruption Due to SafePay Ransomware Attack
Photo: BleepingComputer

Ingram Micro Faces Disruption Due to SafePay Ransomware Attack

Ingram Micro, a leading global technology distributor, is currently experiencing an ongoing outage caused by a SafePay ransomware attack. Since Thursday, the company’s website and online ordering systems have been down, though the cause was not disclosed initially. Internal systems were shut down after employees discovered ransom notes on their devices, linking the attack to the SafePay ransomware operation. This group, active since November 2024, is known for breaching corporate networks through VPN gateways using compromised credentials. It is still unclear whether any data was stolen or if devices were encrypted during the attack. The ransomware gang claims to have stolen a range of sensitive information, but this is standard rhetoric and may not apply in this case. Sources suggest the breach may have occurred via the company’s GlobalProtect VPN platform. As a result, employees were advised to work from home and avoid using VPN access. Ingram Micro has yet to make an official statement, continuing to issue internal advisories regarding the IT disruption. SafePay has already breached over 220 companies since its emergence. Despite the breach, some internal services, including Microsoft 365, Teams, and SharePoint, are still operational. This attack highlights the growing sophistication of ransomware operations targeting large enterprises.

Leave a Reply

Your email address will not be published. Required fields are marked *