Ingram Micro 2025 Data Breach

Ingram Micro Global Technology Distributor Breach (2025): 23.5 Million Records Including SSN & Home Address Exposed via Ransomware

Company · Technology distribution and supply chain · IT distribution network · Global

Ingram Micro Global Technology Distributor Breach (2025): 23.5 Million Records Including SSN & Home Address Exposed via Ransomware

Global technology distributor and IT services company.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
83/100
Lower riskHigher risk
High and current: recent, valuable data circulating on the dark web now.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
23.5MRecords
2025Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
SSNSocial Security Number
AddressPhysical address
Classification Tags
SafePayRansomware / ExtortionLogistics & Supply ChainLogisticsCustomer Direct; Employee2025

Breach Summary

Ingram Micro, one of the world's largest technology distributors, suffered a ransomware attack over the July 4, 2025 weekend after the SafePay ransomware group gained access through the company's GlobalProtect VPN using stolen credentials. Ingram took affected systems offline, engaged outside cybersecurity experts, and notified law enforcement. Core operations were disrupted for approximately one week, with the outage estimated to have cost as much as $136 million in daily revenue. SafePay claimed to have stolen roughly 3.5 terabytes of data and set a deadline to begin publishing it, a double-extortion tactic designed to maintain pressure even after systems are restored. The exposed data includes Social Security numbers, email addresses, phone numbers, and home addresses. Analysts parsing archives tied to the incident tallied roughly 800,000 unique email addresses and 23.5 million unique phone numbers. Formal breach notifications reported impact to more than 42,000 individuals, with Social Security numbers and government-issued identification among the confirmed exposures. For affected individuals, the combination of contact details and Social Security numbers creates serious risk of identity theft, financial fraud, and account takeover. Ingram Micro filed formal breach notifications and engaged a third-party firm to assess the full scope of exfiltrated data, with that investigation ongoing as of the time of reporting. The company's role as a distributor connecting hardware makers, software publishers, and cloud providers with resellers and enterprise customers worldwide means the exposed data may also help attackers map corporate purchasing relationships, enabling targeted invoice scams, procurement fraud, and business impersonation. Affected individuals should monitor their credit, consider placing a credit freeze, and watch for phishing attempts using their personal or professional details.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

23.5M records analyzed

About Ingram Micro

Ingram Micro is one of the world's largest technology distributors, connecting hardware manufacturers, software publishers, and cloud service providers with resellers, managed service providers, and enterprise customers globally. The company is publicly traded on the NYSE under the ticker INGM and serves markets in over 60 countries. Its AI-powered commerce platform, Xvantage, underpins much of its digital transaction processing. Ingram operates at a scale where disruption to its systems can cascade across the broader technology supply chain.

Why They Hold Your Data

Technology distribution networks collect customer, vendor, reseller, procurement, logistics, and account records across large-scale IT supply-chain operations.

Recent Developments

Ingram Micro completed an IPO on the NYSE in October 2024, returning to public markets after a period of private ownership. The company has positioned Xvantage as a core strategic differentiator, enabling automated procurement and licensing transactions at scale. It has continued expanding distribution partnerships and services capabilities globally. The July 2025 ransomware attack was the defining operational event of its first year as a public company.

Data Points Exposed

4 verified field types
Email Address
Phone Number
Physical address High
Social Security Number Critical

Breach Impact

On July 5, 2025, Ingram Micro announced it had identified ransomware on certain internal systems and proactively took affected systems offline to contain the threat. The company engaged third-party cybersecurity experts, notified law enforcement, and issued regular public updates on a dedicated status page. The SafePay ransomware group was identified as responsible, with initial access reportedly gained through Ingram's GlobalProtect VPN using stolen credentials. Systems were down for approximately one week. Ingram Micro achieved full global operational recovery within a week. SafePay subsequently threatened to leak 3.5TB of allegedly stolen data, escalating extortion pressure after system restoration was complete. Formal breach notifications were filed reporting impact to more than 42,000 individuals, with exposed data including Social Security numbers and government-issued identification. Analysts estimated the operational disruption cost the company as much as $136 million in daily revenue during the outage window.

Exploitation & Downstream Threats

• Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure

Principal Risk Advisory

What this means for a principal

A consumer-service breach: contact and account data supports phishing, account takeover and profile enrichment. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  4. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
S
Threat Actor: SafePayConfidence: High
Ransomware group

Motivation: Financial extortion
A ransomware group identified in late 2024 that became highly active in 2025. Reporting describes it as a double-extortion group using LockBit 3.0-derived tooling, with a strong victim concentration in North America.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation