Ingram Micro Holding Corp
Jul 2025 · Graded Verified · Wholesale and Distribution · Government record
Incident summary
Ingram Micro Holding CorpJul 2025
$6.17M
Spent responding & recovering
Direct expense
The intrusion came through Ingram Micro's GlobalProtect VPN, reached with valid credentials because a gateway that trusts a password is the entire perimeter, and SafePay moved from there across a distributor wired into thousands of vendors and resellers. About 42,521 people lost names, Social Security numbers, and passport data; the group claims 3.5 terabytes and published the files, which is what a refused ransom looks like. A VPN login is a front door, not a boundary.
Verified: the linked document states this figure.
SEC 8-K, Item 8.01
Initial attack type compromised credentials confirmed · Impact data theft confirmed + data extortion · Actor SafePay
Quantified 239 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.