Ingram Micro says ransomware attack affected 42,000 people
嗯,用户让我帮忙总结一篇文章,控制在100字以内,而且不需要用“文章内容总结”之类的开头。好的,首先我得仔细阅读这篇文章,抓住主要内容。 文章讲的是Ingram Micro这个IT巨头在2025年7月遭受了勒索软件攻击,导致数据泄露,影响了超过42,000人。他们泄露了个人信息,包括社保号。攻击还导致系统瘫痪,员工被迫在家工作。虽然公司还没确认具体是哪个威胁集团,但BleepingComputer报道说可能是SafePay团伙,他们还声称窃取了3.5TB的数据,并把Ingram Micro添加到他们的暗网泄露网站上。 好的,现在要总结这些内容。控制在100字以内的话,需要简洁明了。先点出Ingram Micro遭受勒索软件攻击的时间和影响人数。然后提到数据泄露的内容和系统瘫痪的情况。最后提到可能的威胁团伙和数据量。 确保语言流畅,不使用复杂的术语,直接传达关键信息。检查一下字数是否符合要求。 </think> IT巨头Ingram Micro于2025年7月遭遇勒索软件攻击,导致42,000余人数据泄露,涉及社保号等敏感信息。攻击引发系统瘫痪,员工被迫远程办公。尽管尚未明确责任方,但安全媒体BleepingComputer报道称可能是SafePay团伙所为,并声称窃取3.5TB数据。 2026-1-19 13:45:22 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Ingram Micro

​Information technology giant Ingram Micro has revealed that a ransomware attack on its systems in July 2025 led to a data breach affecting over 42,000 individuals.

Ingram Micro, one of the world's largest business-to-business service providers and technology distributors, has over 23,500 associates, more than 161,000 customers, and reported net sales of $48 billion in 2024.

In data breach notification letters filed with Maine's Attorney General and sent to those affected by the incident, the company said the attackers stole documents containing a wide range of personal information, including Social Security numbers.

Wiz

"On July 3, 2025, we detected a cybersecurity incident involving some of our internal systems. We quickly launched an investigation into the nature and scope of the issue. Based on our investigation, we determined that an unauthorized third party took certain files from some of our internal file repositories between July 2 and 3, 2025," the IT giant revealed.

"The affected files include employment and job applicant records that contain personal information such as name, contact information, date of birth, government-issued identification numbers (for example, Social Security, driver's license and passport numbers), and certain employment-related information (such as work-related evaluations)."

The July 2025 attack also triggered a massive outage that took down Ingram Micro's internal systems and website, which prompted the company to ask employees to work from home.

While Ingram Micro has yet to link the breach to a specific threat group, it confirmed that the attackers deployed ransomware on its systems after BleepingComputer first reported on July 5 that the SafePay ransomware gang was behind the attack.

The cybercrime group also claimed responsibility three weeks later, adding the tech giant to its dark web leak portal and stating that it had stolen 3.5TB of documents.

Ingram Micro on SafePay's leak site
Ingram Micro entry on SafePay's leak site (BleepingComputer)

​SafePay surfaced in September 2024 as a private operation and has since added hundreds of victims to its leak site. However, the actual number of victims is likely larger, seeing that only those who don't pay are listed.

This ransomware operation is also known for its double-extortion tactics, stealing sensitive documents before encrypting victims' systems and threatening to leak the stolen files online if a ransom is not paid.

Since the start of 2025, SafePay has slowly filled the gap left by LockBit and BlackCat (ALPHV) ransomware, becoming one of the most active ransomware groups.

An Ingram Micro spokesperson has yet to reply after BleepingComputer reached out for more details on the attack and to confirm that SafePay ransomware was behind the breach.

Wiz

The 2026 CISO Budget Benchmark

It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.


文章来源: https://www.bleepingcomputer.com/news/security/ingram-micro-says-ransomware-attack-affected-42-000-people/
如有侵权请联系:admin#unsafe.sh