Wesco confirms security incident after ExfilSquad claims data theft

Wesco, a global giant in supply chain and distribution, has confirmed that it is investigating a cybersecurity incident after a notorious data extortion group claimed to have stolen sensitive information from its systems. The company’s cloud Customer Relationship Management (CRM) environment was allegedly compromised by ExfilSquad, which leaked the stolen data online.

The breach reportedly involves 2.6 million records containing customer and employee personally identifiable information (PII), as well as account and contact data, CRM user profiles, and other sensitive details. Wesco’s statement to BleepingComputer acknowledges that the company is working with its cloud CRM vendor to investigate the incident, but claims that there is no risk to sensitive data.

The investigation found no evidence of ransomware or other malicious software on Wesco’s IT systems, and operations continue as normal. However, this breach highlights the risks associated with cloud-based services, particularly when they are not properly configured. ExfilSquad has a history of targeting organizations that use Microsoft Power Pages, which may be relevant to Wesco given its potential use of Microsoft Dynamics 365.

ExfilSquad’s claims and subsequent data leak have raised concerns about the security posture of companies like Wesco, which relies heavily on cloud-based services for its operations. The breach also underscores the importance of robust cybersecurity measures and regular testing to identify vulnerabilities before they can be exploited by attackers. As researchers from Resecurity and VenariX have noted, ExfilSquad’s tactics often involve exploiting improperly configured data tables in Microsoft Power Pages.

Wesco employs over 21,000 people across more than 50 countries and generates around $24 billion in sales annually. The company’s customers and employees may be concerned about the potential risks associated with this breach. While Wesco has assured that there is no risk to sensitive customer or employee data, it is essential for organizations like Wesco to prioritize cybersecurity measures and regularly test their systems to prevent such incidents.

In the wake of this incident, companies should take a proactive approach to security by conducting regular penetration testing, vulnerability assessments, and breach and attack simulations. This can help identify potential vulnerabilities before attackers do, reducing the risk of successful attacks slipping through undetected. By prioritizing cybersecurity measures and staying vigilant, organizations can minimize the impact of such incidents and protect their customers’ sensitive information.


Source: Bleeping Computer — 2026-08-11