Ingram Micro has confirmed a ransomware attack behind the global outage affecting internal and customer-facing systems.
Ransomware event linked to SafePay
BleepingComputer verified that the attack began early Thursday morning, with ransom notes appearing on employee devices. The group behind the attack is SafePay, a rapidly growing ransomware operation active since late 2024. Ingram Micro has not disclosed whether any data was exfiltrated, and SafePay’s standard ransom note includes generic claims that may not apply in this case.
Entry via VPN platform suspected
Sources believe attackers gained access through Ingram’s GlobalProtect VPN. Once discovered, employees were reportedly told not to use VPN services. Internal systems were taken offline across multiple sites. Employees in some regions were instructed to work from home.
While platforms like Xvantage and Impulse remain down, Microsoft 365 services (Teams, SharePoint) are reported to be functioning.
Scope of the outage
Some ordering systems, partner portals and internal tools remain unavailable. Customers and partners have reported failed API calls, nonfunctioning account tools, and stalled procurement processes. Company-wide advisories have so far described the situation only as “ongoing IT issues.”
Administrative access of Ingram
Ingram Micro holds administrative rights across many Microsoft 365 environments through GDAP (Granular Delegated Admin Privileges). This gives them elevated control over partner tenants. If these permissions were accessed or misused, downstream environments could be exposed.
MSPs have begun reviewing and revoking GDAP roles where possible. Others are unable to act while Ingram’s systems remain inaccessible.
What to do (Exposure checklist for MSPs & IT leads)
- Check if Ingram Micro retains any privileged access to your tenants. Revoke where appropriate.
- Confirm whether GlobalProtect or any external VPN platform is exposed with weak credentials.
- Check for unusual sign ins from Ingram linked accounts or IPs in the past 7 days.
- Brief customers on potential licensing or hardware delays and advise on continuity steps.
- Isolate any remaining tools or services dependent on Ingram Micro.
Unsure if your environment was affected? Our Digital Forensics & Incident Response team can help investigate potential exposure.



