Disclosures and evidence

Revision 2 of 2 · Evidence cutoff Mar 3, 2026, 12:00 AM UTC

10 prior statements preserved · 12 statements added. Attributed source statements retain the source’s qualifications.

What the company disclosed

  1. Ingram Micro stated: “Ingram Micro recently identified ransomware on certain of its internal systems. Promptly after learning of the issue, the Company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.”

  2. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

Affected organizations and relationships

  1. Ingram Micro stated: “Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the Company apologizes for any disruption this issue is causing its customers, vendor partners, and others.”

  2. Ingram Micro stated: “Unless otherwise noted in this Annual Report on Form 10-K, the use of the terms “Ingram Micro,” “we,” “us,” “our” and the “Company” refers to Ingram Micro Holding Corporation and its subsidiaries. The use of the term “Platinum” means Platinum Equity, LLC together with its affiliated investment vehicles.”

Operational impact

  1. Ingram Micro stated: “Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the Company apologizes for any disruption this issue is causing its customers, vendor partners, and others.”

  2. Ingram Micro stated: “IRVINE, Calif.—July 5, 2025 -- Ingram Micro Holding Corporation (NYSE: INGM) (“Ingram Micro” or the “Company”) today issued the following statement with respect to an ongoing system outage:”

  3. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

Financial impact, scope and period

  1. Ingram Micro stated: “In Fiscal Year 2025, Corporate included $6,168 of costs incurred for external services and other expenses in response to the July 2025 ransomware incident, $3,676 of costs associated with retention bonuses related primarily to the sale of our CloudBlue operation and $1,408 related to investments in certain initiatives to accelerate our growth and profitability and optimize our operations. In Fiscal Year 2024, Corporate included $20,380 of advisory fees paid to Platinum Advisors, which we no longer incur subsequent to the IPO, $17,269 related to investments in certain initiatives to accelerate our growth and profitability and optimize our operations, as well as $9,945 of stranded costs resulting from the termination of certain operations and IT services under the transition services agreement with CMA CGM Group as part of the CLS Sale, which were fully transitioned and completed at the end of 2024.” Unit declaration: “All financial data included in this Management’s Discussion and Analysis of Financial Condition and Results of Operations section are in thousands, except as otherwise indicated.”

Response

  1. Ingram Micro stated: “Ingram Micro recently identified ransomware on certain of its internal systems. Promptly after learning of the issue, the Company took steps to secure the relevant environment, including proactively taking certain systems offline and implementing other mitigation measures. The Company also launched an investigation with the assistance of leading cybersecurity experts and notified law enforcement.”

  2. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

Recovery updates

  1. Ingram Micro stated: “Ingram Micro is working diligently to restore the affected systems so that it can process and ship orders, and the Company apologizes for any disruption this issue is causing its customers, vendor partners, and others.”

  2. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

Dates and disclosures

  1. Ingram Micro stated: “IRVINE, Calif.—July 5, 2025 -- Ingram Micro Holding Corporation (NYSE: INGM) (“Ingram Micro” or the “Company”) today issued the following statement with respect to an ongoing system outage:”

  2. Ingram Micro stated: “Published on July 7, 2025”

  3. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

  4. Ingram Micro stated: “For the fiscal year ended December 27 , 2025”

  5. Ingram Micro stated: “Published on March 3, 2026”

  6. Ingram Micro stated: “Our Fiscal Year is a 52- or 53-week period ending on the Saturday nearest to December 31. All references herein to “Fiscal Year 2025”, “Fiscal Year 2024”, and “Fiscal Year 2023” represent the fiscal years ended December 27, 2025 (52 weeks), December 28, 2024 (52 weeks), and December 30, 2023 (52 weeks), respectively. This section of this Annual Report on Form 10-K generally discusses fiscal years 2025 and 2024 items and year-over-year comparisons between fiscal years 2025 and 2024. Discussions of Fiscal Year 2023 items and year-over-year comparisons between Fiscal Year 2024 and Fiscal Year 2023 that are not included in this Annual Report on Form 10-K can be found in “Management’s Discussion and Analysis of Financial Condition and Results of Operations” of our Annual Report on Form 10-K filed with the SEC on March 5, 2025. All financial data included in this Management’s Discussion and Analysis of Financial Condition and Results of Operations section are in thousands, except as otherwise indicated.”

Disclosure evolution

  1. Ingram Micro stated: “Ingram Micro Issues Statement Regarding Cybersecurity Incident”

  2. Ingram Micro stated: “While we, along with our customers, vendors, suppliers, and service providers, are regularly exposed to malicious technology-related events and threats, none of these threats or incidents, either individually or in the aggregate, has materially affected the Company during the periods covered by this report. See Item 1A, “Risk Factors”, for more information on the cybersecurity threats facing our Company.”

Qualifications and uncertainty

  1. Ingram Micro stated: “IRVINE, Calif.—July 5, 2025 -- Ingram Micro Holding Corporation (NYSE: INGM) (“Ingram Micro” or the “Company”) today issued the following statement with respect to an ongoing system outage:”

  2. Ingram Micro stated: “In July 2025, we experienced a ransomware incident that affected certain systems within our global environment. We activated our incident response and business continuity protocols, took steps to contain and remediate the issue, and restored impacted systems using backups. We also notified appropriate governmental authorities and certain customers and partners, and we incurred costs related to investigation, remediation, system restoration, and enhancements to our cybersecurity program. Although this incident did not cause a material interruption of our operations, or otherwise materially and adversely affect our business, financial condition or reputation, the incident underscored the evolving nature of these threats, and additional costs or risks could arise from related claims, regulatory inquiries, or future similar events. There can be no assurance that our response efforts or other ongoing steps to enhance our security controls will be successful in preventing future incidents or mitigating their impacts.”

Disclosure sources and provenance

  • Ingram Micro Publisher posted July 7, 2025Statement/document date: July 5, 2025Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:47 PM UTC · Retained Oct 7, 2026, 7:47 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.
  • Ingram Micro Publisher posted March 3, 2026Document form: PUBLIC_DISCLOSUREPublisher HTTPS source · Retrieved Oct 7, 2026, 7:49 PM UTC · Retained Oct 7, 2026, 7:49 PM UTC
    • Current issuer-published representation; historical exact bytes are unknown.
    • Independent publisher HTTPS origin; not native SEC acquisition, no EDGAR byte-equivalence established.
    • Frozen issuer CIK is subject association only; SEC filing/accession fields remain unavailable on this public-source record.

Evidence limitations

  • Attributed publisher/researcher reports establish what was reported, not independent verification of criminal activity or unique affected humans.
  • Current captured representations support controlled retrospective disclosure views; actual historical byte snapshots are unknown.
  • BaitaPhish source coverage: No supported data-impact assertion was selected in this frozen evidence slice. Confidentiality impact, including data access or exfiltration, is not established by this reader; containment or recovery is not proof of no data compromise.