Wesco confirms CRM data breach after ExfilSquad leaks 2.6 million records

Electrical products distributor Wesco has acknowledged a cybersecurity incident and said it is investigating after the extortion group ExfilSquad published data allegedly stolen from its systems.
The incident affected Wesco's cloud CRM environment. Vice President of Corporate Communications Jennifer Sniderman said the company has already contacted its cloud CRM vendor and does not believe there is a risk to sensitive data.
The company representative added that the incident was detected quickly, and a subsequent investigation found no signs of ransomware or other malicious software on its IT systems. Wesco also stated it sees no threat to payment card information, financial account details, or other confidential customer or employee data. Business operations have not been disrupted and continue normally.
Wesco is a Fortune 500 company that distributes electrical, electronic, communications, and security equipment while providing logistics services. It employs around 21,000 people and operates more than 700 distribution and service centers in roughly 50 countries. Revenue for the last year was about $24 billion.
ExfilSquad, known for attacks on Analog Devices, the UK's Police National Legal Database, and Newcastle University, claimed the breach of Wesco. The hackers said they stole 2.6 million records containing personal data of customers and employees, including contacts, CRM user profiles, credit and business identifiers, authentication metadata, and access information.
After the deadline set by the hackers for ransom negotiations expired, ExfilSquad published the data allegedly taken from Wesco's systems. The company has not yet responded to additional questions about confirming these claims.
Researchers at cybersecurity firms Resecurity and VenariX, who studied ExfilSquad's activity, noted that the group has previously targeted misconfigured Microsoft Power Pages data tables. Wesco has not disclosed how the intrusion occurred.


