Wesco Confirms Cyber Incident Amidst ExfilSquad Data Theft Claims
Global supply chain and distribution leader **Wesco** has acknowledged a cybersecurity incident affecting its cloud CRM environment, following claims by the **ExfilSquad** data extortion group that it exfiltrated 2.6 million records. While **Wesco** asserts no sensitive data is at risk and operations remain unaffected, **ExfilSquad** has published data allegedly stolen from the company's systems.
Global supply chain and distribution giant **Wesco** has confirmed it is investigating a cybersecurity incident. This statement comes after the data extortion group **ExfilSquad** claimed to have stolen sensitive information and subsequently leaked it on their data leak site.
**Jennifer Sniderman**, Vice President of Corporate Communications at **Wesco**, stated that the incident involves the company's cloud CRM environment.
β**Wesco** is aware of a claim of CRM data exfiltration by a third party,β Sniderman told BleepingComputer. βWe have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.β
**Wesco** emphasized that the incident has not caused any business disruption, and all operations continue as normal. The company detected the incident quickly, and its investigation found no evidence of ransomware or other malicious software on its IT systems.
βWe do not believe that payment card information, financial account information or other sensitive customer or employee data is at risk,β the firm stated.
**Wesco** is a Fortune 500 company, distributing electrical, electronic, communications, security, utility, and broadband products, alongside providing logistics and supply chain services. The company employs approximately 21,000 people and operates over 700 distribution centers across roughly 50 countries, generating about $24 billion in sales last year.
### ExfilSquad's Claims and Track Record
The **ExfilSquad** data extortion group, known for previous breaches at **Analog Devices**, the **U.K.'s Police National Legal Database**, and **Newcastle University**, claimed a significant breach at **Wesco**. The threat actor alleged to have stolen 2.6 million records, including customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.
After **Wesco** reportedly failed to engage in ransom payment negotiations by **ExfilSquad**'s deadline, the group published the allegedly exfiltrated data.

### Potential Attack Vector
While **Wesco** has not disclosed the method of breach, cybersecurity researchers from **Resecurity** and **VenariX** have noted **ExfilSquad**'s past targeting of improperly configured **Microsoft Power Pages** data tables. Publicly available information suggests that **Wesco** may utilize **Microsoft Dynamics 365**, potentially indicating a vulnerability in its associated **Microsoft Power Pages** or CRM configuration.