Scworld ExfilSquad Targets Wesco in Major Data Theft Incident
Article Content
- •ExfilSquad claims to have stolen 2.6 million records from Wesco's cloud CRM.
- •Wesco reported no evidence of ransomware or malware and no business disruption.
- •The incident highlights risks associated with misconfigured cloud environments.
On August 11, 2026, Wesco, a global supply chain company, confirmed a cybersecurity incident involving data theft by the group ExfilSquad. The group claimed to have stolen 2.6 million records from Wesco's cloud CRM environment, including sensitive customer and employee personally identifiable information (PII). Wesco stated that no ransomware or malware was detected and that operations were not disrupted. The attack method is consistent with ExfilSquad's historical tactics of data theft and extortion rather than ransomware. The group has previously targeted misconfigured Microsoft Power Pages data tables, suggesting a potential vulnerability in Wesco's systems. After failing to negotiate a ransom, ExfilSquad published the stolen data on their leak site. Wesco is currently investigating the incident and collaborating with their cloud CRM vendor.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Cl0p Ransomware and Allstate in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…