Wesco confirms security incident after ExfilSquad claims data theft

Wesco, a global supply chain and distribution giant, has confirmed that it is investigating a cybersecurity incident after threat actors claimed to have stolen sensitive information from its systems. The company’s cloud-based customer relationship management (CRM) environment appears to be at the center of the breach.

ExfilSquad, a notorious data extortion group, has been linked to several high-profile breaches in recent years, including those at Analog Devices, the U.K.’s Police National Legal Database, and Newcastle University. The group’s latest claim involves Wesco, alleging that it has stolen 2.6 million records containing sensitive information about customers and employees. This includes personal identifiable information (PII), account data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

Wesco has stated that it is working with its cloud CRM vendor to investigate the incident, but maintains that there is no risk to sensitive customer or employee data. The company’s representative also assured that operations continue as normal, and that no ransomware or other malicious software was detected on its IT systems. Wesco employs approximately 21,000 people and operates in over 50 countries, making it a significant player in the global supply chain and distribution industry.

The use of cloud-based CRM environments like Microsoft Dynamics 365 can provide numerous benefits to businesses, including increased scalability and flexibility. However, if not properly configured or secured, these systems can become vulnerable to attacks from threat actors like ExfilSquad. Researchers have noted that the group has targeted improperly configured Microsoft Power Pages data tables in the past, which may indicate a similar vulnerability at Wesco.

It’s worth noting that while Wesco maintains there is no risk to sensitive customer or employee data, this assertion may be difficult to verify without further investigation. The fact that ExfilSquad was able to claim a breach and publish allegedly stolen data raises questions about the company’s cybersecurity posture. Moreover, the group’s tactics of claiming breaches and extorting payment from companies have been linked to significant financial losses for businesses.

As consumers and organizations become increasingly reliant on cloud-based services, it’s essential that providers prioritize robust security measures to prevent similar incidents in the future. This includes regular software updates, secure configuration practices, and effective incident response planning. For Wesco and other affected companies, this may involve conducting thorough internal investigations, reviewing their cybersecurity protocols, and implementing additional safeguards to protect sensitive data.

In light of this incident, we urge businesses to review their cloud-based CRM environments and ensure that they are properly configured and secured. This includes regularly monitoring for suspicious activity, keeping software up-to-date, and educating employees about cybersecurity best practices. By taking proactive steps to prevent similar breaches, organizations can mitigate the risk of data theft and protect sensitive information from falling into the wrong hands.


Source: Bleeping Computer — 2026-08-11