ScanSource confirmed ransomware attack behind multi-day outages
- Organization
- ScanSource
- Exploit
- Ransomware
- Industry
- Technology Distribution
Technology distributor ScanSource said a ransomware attack discovered on May 14, 2023 had disrupted its systems, business operations and customer-facing portals.
Customers began reporting that they could not reach the company's portals and websites around May 15. ScanSource confirmed the cause in a public statement, saying it had activated its incident response plan, notified law enforcement and engaged outside forensic and cybersecurity specialists to investigate and assist with recovery.
The company warned that customers and suppliers in North America and Brazil should expect delays while systems were brought back online. It did not identify the ransomware operation involved, and at the time of the initial reporting it was not known whether any data had been stolen. No group had publicly claimed the attack.
ScanSource said in a follow-up statement that its core systems were restored and that operations resumed on Friday, May 26, describing the business as fully operational across all areas and geographies. Chief executive Mike Baur credited employees and outside specialists with the recovery and thanked customers and suppliers for their patience.
The South Carolina company distributes hardware, software and connectivity services through a reseller network, so the outage fell mainly on partners that depended on its ordering and support portals rather than on end consumers.