Skip to content
ExfilSquad Targets Wesco in Major Data Theft Incident

ExfilSquad Targets Wesco in Major Data Theft Incident

First seen 12 Aug 2026, 08:06 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •August 13, 2026 at 07:42 UTC
  • •ExfilSquad claims to have stolen 2.6 million records from Wesco's cloud CRM.
  • •Wesco reported no evidence of ransomware or malware and no business disruption.
  • •The incident highlights risks associated with misconfigured cloud environments.

On August 11, 2026, Wesco, a global supply chain company, confirmed a cybersecurity incident involving data theft by the group ExfilSquad. The group claimed to have stolen 2.6 million records from Wesco's cloud CRM environment, including sensitive customer and employee personally identifiable information (PII). Wesco stated that no ransomware or malware was detected and that operations were not disrupted. The attack method is consistent with ExfilSquad's historical tactics of data theft and extortion rather than ransomware. The group has previously targeted misconfigured Microsoft Power Pages data tables, suggesting a potential vulnerability in Wesco's systems. After failing to negotiate a ransom, ExfilSquad published the stolen data on their leak site. Wesco is currently investigating the incident and collaborating with their cloud CRM vendor.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 48d ago How this analysis works

Timeline

2026-08-05
ExfilSquad sets ransom deadline
ExfilSquad announced a deadline for ransom negotiations, threatening to release stolen data if unmet.
Resecurity
2026-08-11
Wesco confirms cybersecurity incident
Wesco acknowledged a data breach involving ExfilSquad's claims of data theft from its cloud CRM.
Bleepingcomputer
2026-08-11
ExfilSquad publishes stolen data
After ransom negotiations failed, ExfilSquad released the stolen data on their leak site.
Rescana
2026-08-12
Wesco investigates breach
Wesco is conducting an investigation into the breach, confirming no sensitive data is at risk.
mallory.ai

More articles in this cluster (13)

Following this threat?

Track Cl0p Ransomware and Allstate in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed