Wesco probes breach claims after ExfilSquad leak
Wesco confirms a cybersecurity incident after ExfilSquad claims theft of 2.6M records from its CRM environment.
Global supply chain and distribution giant Wesco is investigating a cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen sensitive information from the company and published it on its leak site. The company, which reported roughly $24 billion in sales last year, has confirmed the incident in a statement but says it found no evidence of ransomware and does not believe sensitive data is at risk.
Cloud CRM environment targeted
Jennifer Sniderman, Vice President of Corporate Communications at Wesco, told BleepingComputer that the incident involves the company’s cloud CRM environment. “Wesco is aware of a claim of CRM data exfiltration by a third party,” Sniderman said. “We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.”
The company representative added that Wesco has not experienced any business disruption, and all operations continue as normal. Wesco said the incident was detected quickly, and its subsequent investigation found no evidence of ransomware or other malicious software on its IT systems.
No sensitive data at risk, company says
“We do not believe that payment card information, financial account information or other sensitive customer or employee data is at risk,” stated the firm. The statement emphasizes that the company’s investigation has not turned up signs of malware, suggesting the attack may have relied on other means, possibly involving misconfigured cloud services.
Wesco is a Fortune 500 company that distributes electrical, electronic, communications, security, utility, and broadband products while providing logistics and supply chain services to businesses. The company employs approximately 21,000 people and operates more than 700 distribution centers, fulfillment centers, and sales offices across roughly 50 countries.
Threat group with a recent track record
ExfilSquad, the group claiming responsibility, has been linked to recent data breaches at Analog Devices, the U.K.'s Police National Legal Database, and Newcastle University. The group’s modus operandi appears to involve large-scale data theft, often followed by publication on its leak site if ransom demands are not met.
According to researchers at cybersecurity companies Resecurity and VenariX, ExfilSquad has previously targeted improperly configured Microsoft Power Pages data tables. This technical detail has fueled speculation about how the group gained access to Wesco’s CRM environment, though Wesco has not shared how the threat actor breached its network.
Stolen data details
The threat actor claimed to have stolen 2.6 million records containing customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. After the hacker's deadline for the company to enter ransom payment negotiations expired, ExfilSquad published the data allegedly exfiltrated from Wesco's systems.
- 2.6 million records allegedly stolen
- Data includes customer and employee PII, account and contact data
- CRM user profiles, credit and business identifiers, authentication metadata
- Access information included in the leak
Response and investigation
BleepingComputer asked Wesco to confirm ExfilSquad’s claims, but the publication did not receive a response to its additional questions. Meanwhile, publicly available information indicates that Wesco may be using Microsoft Dynamics 365, a platform that, if left misconfigured, could expose data tables to the public.
The company’s rapid detection and reassurance of normal operations suggest the incident was contained, but the absence of a detailed technical explanation leaves questions about the attack vector unanswered.
Why it matters
For a company of Wesco’s scale, with operations spanning dozens of countries and hundreds of distribution centers, even a contained CRM data leak carries significant reputational and regulatory implications. The claim of 2.6 million records, if accurate, could expose customers and employees to phishing and identity fraud, despite the company’s assurances. This incident also highlights the growing risk that cloud misconfigurations pose to enterprises, especially when threat actors like ExfilSquad appear to specialize in exploiting such weaknesses. As the investigation unfolds, the broader industry should note that a rapid response and clear communication, while crucial, cannot fully mitigate the consequences of a data breach.
Sources
- BleepingComputer Original source
Continue Reading
Ransomware Group Hardens Infrastructure via Smart Contracts
DeadLock uses Polygon smart contracts to make extortion infrastructure harder to disrupt, Microsoft reports.
Deepfake glitch exposes Spanish certificate fraud suspect
A momentary face-swap failure helped Spanish police identify a man accused of obtaining digital certificates under stolen identities.
Ceva Breach Reverberates Through Client Ecosystem
A Ceva Logistics data breach affecting European clients shows how supply chain attacks ripple outward.