Ingram Micro Holding Corp

Jul 2025 · Graded Verified · Wholesale and Distribution · Government record

Incident summary

Ingram Micro Holding CorpJul 2025
$6.17M
Spent responding & recovering
Direct expense
The intrusion came through Ingram Micro's GlobalProtect VPN, reached with valid credentials because a gateway that trusts a password is the entire perimeter, and SafePay moved from there across a distributor wired into thousands of vendors and resellers. About 42,521 people lost names, Social Security numbers, and passport data; the group claims 3.5 terabytes and published the files, which is what a refused ransom looks like. A VPN login is a front door, not a boundary.
Verified: the linked document states this figure.
Wholesale and Distribution
SEC 8-K, Item 8.01
Initial attack type compromised credentials confirmed · Impact data theft confirmed + data extortion · Actor SafePay
Quantified 239 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
2026-03-03$6.17MVVerifiedSEC 10-K ↗
2026-07-30$3.17MVVerifiedSEC 10-Q ↗
2026-07-30$1.12MVVerifiedSEC 10-Q ↗

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index