Wesco Confirms Cloud CRM Incident After ExfilSquad Dumps 2.6 Million Records
The Fortune 500 distributor says no sensitive customer or employee data is at risk, but the extortion crew published what it claims to have stolen after Wesco missed the ransom deadline.

Key points
- Wesco, a Fortune 500 electrical and industrial distributor with roughly 21,000 staff, confirmed a cybersecurity incident affecting its cloud CRM system.
- ExfilSquad claims it stole 2.6 million records covering customer and employee data, then leaked them after Wesco declined to pay.
- Wesco says the intrusion didn't touch ransomware, business operations, payment card data, or financial account details.
- Researchers link ExfilSquad's recent activity to misconfigured Microsoft Power Pages data tables.
- The company hasn't said how the attackers got in, or whether it will notify individuals named in the leaked files.
Wesco, the Pittsburgh-based distributor that ships electrical and communications gear to businesses in about 50 countries, has confirmed it's investigating a cybersecurity incident. The company disclosed it after ExfilSquad, a data extortion crew, claimed on its leak site to have stolen millions of records.
Jennifer Sniderman, Wesco's vice president of corporate communications, told BleepingComputer the incident is confined to the company's cloud CRM environment. CRM, short for customer relationship management, is the software firms use to store contact details and account records for the people they do business with.
"Wesco is aware of a claim of CRM data exfiltration by a third party," Sniderman said. Wesco worked with its CRM vendor on the matter and doesn't believe sensitive data is at risk.
What did the hackers take?
ExfilSquad claims it walked off with 2.6 million records: customer and employee personal information, account and contact details, CRM user profiles, credit and business identifiers, and authentication metadata (the internal tokens that control who can log in).
When Wesco didn't enter ransom negotiations by the deadline, ExfilSquad published the files. We covered the group's hit on the UK's Police National Legal Database on 3 August, where it claimed 135,000 records and demanded a ransom, and its breach at Analog Devices on 30 July. Wesco is the largest target the group has named publicly.
Wesco disputes the severity. Its investigation found no ransomware (malicious software that scrambles files until a ransom is paid) and no sign that payment card numbers or bank account details were exposed. Operations are running normally.
How did the attackers get in?
Wesco hasn't said. Researchers at Resecurity and VenariX have tracked ExfilSquad targeting poorly configured Microsoft Power Pages sites, and public information suggests Wesco uses Microsoft Dynamics 365.
Power Pages is Microsoft's tool for building customer-facing web portals that connect to Dynamics 365 data. When administrators leave the wrong permissions on the underlying tables, an outsider with a browser can pull records never meant to be public. Microsoft warned about this class of misconfiguration in late 2024 and issued guidance for locking tables down.
That's a plausible route, but it isn't confirmed. Wesco hasn't responded to follow-up questions on how the breach happened.
Should customers and employees be worried?
Probably watch, but don't panic. Wesco sells to businesses, not consumers, so most exposed records likely relate to procurement contacts at other companies. Still, if you've ever registered on a Wesco portal, treat unexpected emails referencing your account with extra suspicion for the next few months. Phishing (fake emails designed to trick you into handing over passwords or clicking a bad link) tends to follow leaks like this.
| Detail | Value |
|---|---|
| Company | Wesco International |
| Employees | ~21,000 |
| 2023 sales | ~$24 billion |
| Records claimed leaked | 2.6 million |
| System affected | Cloud CRM |
| Extortion group | ExfilSquad |
Wesco operates more than 700 distribution and sales sites. A leak of its CRM contact book, if genuine, is a ready-made targeting list for anyone building phishing campaigns against the industrial supply chain. That's the part worth watching: not what Wesco lost, but how that data gets used next.



