Editorial draft v2 · Evidence reader R2 · Evidence cutoff: March 3, 2026

Disclosures covered: A July 5, 2025 statement on an issuer wrapper posted July 7, and the fiscal-2025 annual report posted March 3, 2026. Fiscal 2025 ended December 27, 2025.

Ingram Micro reported ransomware on certain internal systems during a July 2025 outage. Its initial statement described mitigation and work to restore order processing and shipping; the later annual report said systems had been restored using backups and identified a specific Corporate response-cost amount. The later assessment of materiality did not erase the initial operational disruption. July statement · Annual report

The initial response and later restoration account

The statement is dated July 5, while its issuer-hosted wrapper says it was published July 7. Ingram said it secured the relevant environment, proactively took certain systems offline, launched an investigation with cybersecurity experts, and notified law enforcement. It was working to restore systems so it could process and ship orders, and apologized for disruption to customers and vendor partners. The selected passage does not establish the exact intrusion or discovery date. July statement

In the annual report, Ingram described the July incident as affecting certain systems in its global environment. It said it activated response and business-continuity protocols, contained and remediated the issue, restored affected systems using backups, and notified appropriate authorities and certain customers and partners. Costs covered investigation, remediation, restoration, and security-program enhancements. Annual report

The company said the incident had not caused a material interruption of operations or otherwise materially and adversely affected its business, financial condition, or reputation. Its broader reporting also said threats and incidents had not materially affected it during the covered periods. These are scoped company assessments. The annual report acknowledged that related claims or regulatory inquiries could produce further costs or risks and did not guarantee that response or security improvements would prevent future incidents. Annual report

The cost amount and its units

The annual report's Management's Discussion and Analysis states that financial data are in thousands, unless otherwise indicated. Within Corporate, it reported $6,168 thousand—USD 6.168 million—in fiscal-2025 costs for external services and other expenses responding to the July ransomware incident. This is the supported amount and scope in the selected passage, not an enterprise-wide lifetime incident total. Annual report

The same paragraph lists $3,676 thousand in retention bonuses primarily tied to the CloudBlue sale and $1,408 thousand for other initiatives. Those are unrelated categories, not extra ransomware-response components. Its fiscal-2024 figures likewise concern other expenses. The selected disclosure does not establish an insurance recovery, ransom payment, confidentiality finding, or quantified affected population. Annual report

Editorial interpretation: the sequence moves from an outage and restoration in progress to a later account of restoration and a defined fiscal-year response cost. It supports that progression without substituting a larger, unsupported loss figure or treating qualified nonmateriality language as proof that no incident occurred. July statement · Annual report

Sources

  • Initial statement — July 5 dateline / July 7, 2025 wrapper publication.

  • Annual report — March 3, 2026 posting; fiscal year ended December 27, 2025.

Disclosure history

Article draft version 2 · Evidence reader revision 2 · Evidence cutoff Mar 3, 2026, 12:00 AM UTC

The narrative has editorial wording approval. The evaluations below apply to retained extractive disclosure readers, not to the narrative wording.

Disclosure sources and provenance

  • Ingram Micro Publisher posted July 7, 2025Statement/document date: July 5, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:47 PM UTC · Retained Oct 7, 2026, 7:47 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.
  • Ingram Micro Publisher posted March 3, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:49 PM UTC · Retained Oct 7, 2026, 7:49 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.