INGRAM MICRO INC.
bd_eee1ae1379bcb815 · schema v1 · pii pii-v1
Full breach record for INGRAM MICRO INC. →Ingram Micro Inc. notified the New Hampshire Attorney General of a cybersecurity incident detected on July 3, 2025. An unauthorized party accessed internal file repositories between July 2 and 3, 2025, exfiltrating employment and job applicant records. Affected data included names, contact info, SSNs, driver's licenses, passport numbers, and health/insurance information. Approximately 40 New Hampshire residents (current/former employees and applicants) were notified. Ingram Micro engaged forensic experts, notified law enforcement, took systems offline, and offers two years of credit monitoring.
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_7837f481c3fe62e8Texas State AGfiled 2026-01-21(2d gap)Verified
- bd_0c948d47559f2f84California State AGfiled 2026-01-16(7d gap)Candidate
- bd_1b20f97ec00dda79Vermont State AGfiled 2026-01-16(7d gap)Verified
- bd_2d49c4f0e0bc40fcMaine State AGfiled 2026-01-16(7d gap)Verified
Show 1 more filing ↓Show fewer ↑up to 7d gap
- bd_6eb764c414006739Indiana State AGfiled 2026-01-16(7d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/ingram-micro-20260123.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 23, 2026
- Raw hash
- 062aa782435341f1c6c904edc44c8fe35e677fd287d1ed1f3660407671da2b94
Reporting entity
- Name
- Hunton Andrews Kurth LLPnorm: hunton andrews kurth
Victim entity
- Name
- INGRAM MICRO INC.norm: ingram micro
Incident
- Discovered
- Jul 3, 2025
- Materiality determined
- —
- Notification sent
- Jan 16, 2026
- Affected individuals
- 40
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENTHEALTH_BASICEMPLOYMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1119 Automated Collection
- Threat actor
- External
- Regulator citations
- Notified New Hampshire Attorney General's Office
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 weeks(204 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.