Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident.

The company’s statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site.

Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company’s cloud CRM environment.

“Wesco is aware of a claim of CRM data exfiltration by a third party,” Sniderman told BleepingComputer.

“We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.”

The company representative added that Wesco has not experienced any business disruption, and all operations continue as normal.

Wesco said the incident was detected quickly, and its subsequent investigation found no evidence of ransomware or other malicious software on its IT systems.

“We do not believe that payment card information, financial account information or other sensitive customer or employee data is at risk,” stated the firm.

Wesco is a Fortune 500 company that distributes electrical, electronic, communications, security, utility, and broadband products while providing logistics and supply chain services to businesses.

The company employs approximately 21,000 people and operates more than 700 distribution centers, fulfillment centers, and sales offices across roughly 50 countries. Wesco generated about $24 billion in sales last year.

Recently, the data extortion group ExfilSquad, known for data breaches at Analog Devices, the U.K.’s Police National Legal Database, and Newcastle University, claimed a breach at Wesco.

The threat actor claimed to have stolen 2.6 million records containing customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

After the hacker’s deadline for the company to enter ransom payment negotiations expired, ExfilSquad published the data allegedly exfiltrated from Wesco’s systems.

BleepingComputer asked Wesco to confirm ExfilSquad’s claims, but we have not received a response to our additional questions.

However, recent reports from researchers at cybersecurity companies Resecurity and VenariX examining ExfilSquad activity indicate that the threat actor has targeted in the past improperly configured Microsoft Power Pages data tables.

Wesco has not shared how the threat actor breached its network, but publicly available information indicates that Wesco may be using Microsoft Dynamics 365.

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

ExfilSquad hackers leak info of over 100,000 UK police officers, staff

Australian energy provider Origin says data breach exposes client data

Mount Royal University confirms breach as hackers claim attack

NAIC says public data stolen in ShinyHunters’ PeopleSoft breach

Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group

LexisNexis shuts down services after suspicious activity on servers

Valve notifies Steam hardware customers of a data breach

Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days

Webinar: Shadow AI in 2026 (and how attackers are taking advantage)

Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.

Overdue a password health-check? Audit your Active Directory for free

See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.

See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats

Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure

Read our posting guidelinese to learn what content is prohibited.