Editorial draft v2 · Evidence reader R2 · Evidence cutoff: March 3, 2026
Disclosures covered: A July 5, 2025 statement on an issuer wrapper posted July 7, and the fiscal-2025 annual report posted March 3, 2026. Fiscal 2025 ended December 27, 2025.
Ingram Micro reported ransomware on certain internal systems during a July 2025 outage. Its initial statement described mitigation and work to restore order processing and shipping; the later annual report said systems had been restored using backups and identified a specific Corporate response-cost amount. The later assessment of materiality did not erase the initial operational disruption. July statement · Annual report
The initial response and later restoration account
The statement is dated July 5, while its issuer-hosted wrapper says it was published July 7. Ingram said it secured the relevant environment, proactively took certain systems offline, launched an investigation with cybersecurity experts, and notified law enforcement. It was working to restore systems so it could process and ship orders, and apologized for disruption to customers and vendor partners. The selected passage does not establish the exact intrusion or discovery date. July statement
In the annual report, Ingram described the July incident as affecting certain systems in its global environment. It said it activated response and business-continuity protocols, contained and remediated the issue, restored affected systems using backups, and notified appropriate authorities and certain customers and partners. Costs covered investigation, remediation, restoration, and security-program enhancements. Annual report
The company said the incident had not caused a material interruption of operations or otherwise materially and adversely affected its business, financial condition, or reputation. Its broader reporting also said threats and incidents had not materially affected it during the covered periods. These are scoped company assessments. The annual report acknowledged that related claims or regulatory inquiries could produce further costs or risks and did not guarantee that response or security improvements would prevent future incidents. Annual report
The cost amount and its units
The annual report's Management's Discussion and Analysis states that financial data are in thousands, unless otherwise indicated. Within Corporate, it reported $6,168 thousand—USD 6.168 million—in fiscal-2025 costs for external services and other expenses responding to the July ransomware incident. This is the supported amount and scope in the selected passage, not an enterprise-wide lifetime incident total. Annual report
The same paragraph lists $3,676 thousand in retention bonuses primarily tied to the CloudBlue sale and $1,408 thousand for other initiatives. Those are unrelated categories, not extra ransomware-response components. Its fiscal-2024 figures likewise concern other expenses. The selected disclosure does not establish an insurance recovery, ransom payment, confidentiality finding, or quantified affected population. Annual report
Editorial interpretation: the sequence moves from an outage and restoration in progress to a later account of restoration and a defined fiscal-year response cost. It supports that progression without substituting a larger, unsupported loss figure or treating qualified nonmateriality language as proof that no incident occurred. July statement · Annual report
Sources
Initial statement — July 5 dateline / July 7, 2025 wrapper publication.
Annual report — March 3, 2026 posting; fiscal year ended December 27, 2025.