Wesco, a Fortune 500 supply chain and distribution company, has confirmed it is investigating a cybersecurity incident affecting its cloud CRM environment. This confirmation follows claims by the data extortion group ExfilSquad that it stole sensitive information from Wesco and subsequently leaked it online.
ExfilSquad, a group known for previous data breaches, asserted that it exfiltrated 2.6 million records from Wesco. These records allegedly include customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. The group published the data after Wesco did not engage in ransom negotiations.
Wesco stated that it worked with its cloud CRM vendor and does not believe sensitive data, such as payment card information, financial account information, or other sensitive customer or employee data, is at risk. The company also reported no business disruption and confirmed that all operations continue as normal. Wesco detected the incident quickly and found no evidence of ransomware or other malicious software on its IT systems during its investigation.
ExfilSquad has a history of targeting organizations, including Analog Devices, the U.K.'s Police National Legal Database, and Newcastle University. Cybersecurity researchers have indicated that the group has previously exploited improperly configured Microsoft Power Pages data tables.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Wesco, a global supply chain and distribution company, confirmed it is investigating a cybersecurity incident involving its cloud CRM environment after the ExfilSquad data extortion group claimed to have stolen 2.6 million records and published them. Wesco states it found no evidence of ransomware or malicious software and believes sensitive customer or employee data is not at risk, despite the group's claims of PII exfiltration.