Scworld
ExfilSquad Targets Wesco in Major Data Theft Incident
Article Content
On August 11, 2026, Wesco, a global supply chain company, confirmed a cybersecurity incident involving data theft by the group ExfilSquad. The group claimed to have stolen 2.6 million records from Wesco's cloud CRM environment, including sensitive customer and employee personally identifiable information (PII). Wesco stated that no ransomware or malware was detected and that operations were not disrupted. The attack method is consistent with ExfilSquad's historical tactics of data theft and extortion rather than ransomware. The group has previously targeted misconfigured Microsoft Power Pages data tables, suggesting a potential vulnerability in Wesco's systems. After failing to negotiate a ransom, ExfilSquad published the stolen data on their leak site. Wesco is currently investigating the incident and collaborating with their cloud CRM vendor.
Key Points: • ExfilSquad claims to have stolen 2.6 million records from Wesco's cloud CRM. • Wesco reported no evidence of ransomware or malware and no business disruption. • The incident highlights risks associated with misconfigured cloud environments.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.