ExfilSquad Targets Wesco in Major Data Theft Incident

ExfilSquad Targets Wesco in Major Data Theft Incident

First seen 12 Aug 2026, 08:06 UTC BleepingcomputerScworldRescanawww.resecurity.comsecurityarsenal.com+7 71.0

Article Content

Browse articles
ThreatCluster

On August 11, 2026, Wesco, a global supply chain company, confirmed a cybersecurity incident involving data theft by the group ExfilSquad. The group claimed to have stolen 2.6 million records from Wesco's cloud CRM environment, including sensitive customer and employee personally identifiable information (PII). Wesco stated that no ransomware or malware was detected and that operations were not disrupted. The attack method is consistent with ExfilSquad's historical tactics of data theft and extortion rather than ransomware. The group has previously targeted misconfigured Microsoft Power Pages data tables, suggesting a potential vulnerability in Wesco's systems. After failing to negotiate a ransom, ExfilSquad published the stolen data on their leak site. Wesco is currently investigating the incident and collaborating with their cloud CRM vendor.

Key Points: • ExfilSquad claims to have stolen 2.6 million records from Wesco's cloud CRM. • Wesco reported no evidence of ransomware or malware and no business disruption. • The incident highlights risks associated with misconfigured cloud environments.

Timeline

2026-08-05
ExfilSquad sets ransom deadline
ExfilSquad announced a deadline for ransom negotiations, threatening to release stolen data if unmet.
Resecurity
2026-08-11
Wesco confirms cybersecurity incident
Wesco acknowledged a data breach involving ExfilSquad's claims of data theft from its cloud CRM.
Bleepingcomputer
2026-08-11
ExfilSquad publishes stolen data
After ransom negotiations failed, ExfilSquad released the stolen data on their leak site.
Rescana
2026-08-12
Wesco investigates breach
Wesco is conducting an investigation into the breach, confirming no sensitive data is at risk.
mallory.ai