Wesco Confirms Cyberattack After ExfilSquad Claims Data Theft

Photo: BleepingComputer
Quick answer
Wesco confirmed a cyberattack with potential data theft from its cloud CRM system following claims by hacker group ExfilSquad. The incident did not disrupt business operations, and the risk to sensitive data was denied.
Wesco, a major player in electronics distribution and logistics services, confirmed it is investigating a cybersecurity incident after hacker group ExfilSquad claimed to have stolen data. The incident affected the company’s cloud-based CRM system, but Wesco assured that no threats to confidential customer or employee data exist.
According to Jennifer Snyderman, Vice President of Corporate Communications, the incident was detected promptly, and further investigation revealed no signs of malware, including ransomware. Business operations remained unaffected, with all processes continuing as usual. Wesco also emphasized that payment card data, financial accounts, and other sensitive information are not at risk.
ExfilSquad, known for attacks on organizations like Analog Devices, UK police databases, and Newcastle University, claimed to have stolen 2.6 million records from Wesco’s systems. The hackers alleged the stolen data included personal customer and employee details, CRM user profiles, business identifiers, and authentication metadata. After the ransom deadline expired, the group published the data on its portal.
Cybersecurity experts from Resecurity and VenariX noted that ExfilSquad previously exploited vulnerabilities in misconfigured Microsoft Power Pages tables. While Wesco has not disclosed breach details, public data suggests the company may use Microsoft Dynamics 365, which could be related to the incident.
Common questions
- What data did ExfilSquad allegedly steal from Wesco?
- According to the hackers, 2.6 million records were stolen, including personal customer and employee data, CRM profiles, business identifiers, and authentication metadata. Wesco denies any leakage of confidential information.
- How was Wesco’s system breached?
- Exact details remain undisclosed, but experts suspect the attack may be linked to vulnerabilities in Microsoft Power Pages or Microsoft Dynamics 365, which Wesco reportedly uses.
- What actions did Wesco take following the incident?
- The company launched an immediate investigation in collaboration with its cloud CRM provider. Business operations remained unaffected, and no malware was detected on its systems.
Dzen feed: /feed/dzen.xml · RSS: /feed.xml