Wesco said it is investigating a cybersecurity incident after the extortion group ExfilSquad claimed to have stolen and leaked company data. The company said the incident was limited to its cloud CRM environment, was detected quickly, caused no business disruption, and showed no evidence of ransomware or other malware on internal IT systems. Wesco also said it does not believe sensitive customer or employee information, including payment card and financial account data, is at risk.
ExfilSquad claimed it exfiltrated 2.6 million records and released the data after ransom negotiations did not take place. The group said the leak includes customer and employee PII, account and contact records, CRM user profiles, credit and business identifiers, authentication metadata, and access-related information, and researchers have previously linked ExfilSquad intrusions to improperly configured Microsoft Power Pages data tables. Public reporting noted that Wesco may use Microsoft Dynamics 365, suggesting the incident may involve exposed cloud CRM components rather than malware-driven network compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Resecurity reported that ExfilSquad was targeting additional victims and distributing stolen data through torrents, adding technical and operational detail about the group's extortion activity.
Wesco said it is investigating a cybersecurity incident involving its cloud CRM environment after becoming aware of a third-party claim of CRM data exfiltration. The company said it detected the issue quickly, found no evidence of ransomware or other malware on its IT systems, and saw no business disruption.
ExfilSquad claimed it stole 2.6 million Wesco records, including customer and employee PII, CRM user profiles, and authentication-related data. The group said it published the data after ransom negotiation deadlines expired.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceresecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.