Wesco Confirms Cloud CRM Incident After ExfilSquad Dumps 2.6 Million Records

The Fortune 500 distributor says no sensitive customer or employee data is at risk, but the extortion crew has already published what it claims to have stolen.

ThreatVectr Newsdesk· 4 min read
A quiet university server room at night, rows of dark storage racks with faint blue and amber status lights, one rack door left ajar, cables hanging loose, a re
Share

Key points

  • Wesco, a Fortune 500 electrical and industrial distributor with roughly 21,000 staff, confirmed a cybersecurity incident affecting its cloud customer relationship management system.
  • Extortion group ExfilSquad claims it stole 2.6 million records covering customers, employees, and account data, and has now leaked them after Wesco declined to pay.
  • Wesco says the intrusion did not touch ransomware, business operations, payment card data, or financial account details.
  • Researchers link ExfilSquad's recent activity to badly configured Microsoft Power Pages data tables, a common cloud misstep.
  • The company has not said how the attackers got in or whether it will notify individuals named in the leaked files.

Wesco, the Pittsburgh-based distributor that ships electrical and communications gear to businesses in about 50 countries, has confirmed it is investigating a cybersecurity incident. The company disclosed the intrusion after an extortion crew called ExfilSquad claimed on its leak site to have stolen millions of records.

Jennifer Sniderman, Wesco's vice president of corporate communications, told BleepingComputer the incident is confined to the company's cloud CRM environment. CRM, short for customer relationship management, is the software firms use to store contact details, sales notes, and account records for the people they do business with.

"Wesco is aware of a claim of CRM data exfiltration by a third party," Sniderman said. She added that Wesco worked with its CRM vendor on the matter and does not believe sensitive data is at risk.

What did the hackers take?

ExfilSquad claims it walked off with 2.6 million records. According to the group, the haul includes customer and employee personal information, account and contact details, CRM user profiles, credit and business identifiers, and authentication metadata (the internal tokens and settings that control who can log in).

When Wesco did not enter ransom negotiations by the deadline, ExfilSquad published the files. The same group has been tied to earlier leaks from chipmaker Analog Devices, the UK's Police National Legal Database, and Newcastle University.

Wesco disputes the severity. The company says its investigation found no ransomware (malicious software that scrambles files until a ransom is paid) and no sign that payment card numbers, bank account information, or other sensitive customer or employee data were exposed. Operations are running normally.

How did the attackers get in?

Wesco has not said. But researchers at Resecurity and VenariX have tracked ExfilSquad hitting poorly configured Microsoft Power Pages sites, and public information suggests Wesco uses Microsoft Dynamics 365.

Power Pages is Microsoft's tool for building customer-facing web portals that plug into Dynamics 365 data. When administrators leave the wrong permissions on the underlying tables, an outsider with a browser can pull records that were never meant to be public. Microsoft warned about this exact class of misconfiguration in late 2024 and issued guidance for locking tables down.

That is a plausible route here, but it is not confirmed. Wesco has not responded to follow-up questions on how the breach happened.

Should customers and employees be worried?

Probably watch, but do not panic. Wesco sells to businesses, not consumers, so most of the exposed records likely relate to procurement contacts at other companies. Still, if you have ever registered on a Wesco portal or done business with the company, treat unexpected emails referencing your account with extra suspicion for the next few months. Phishing (fake emails designed to trick you into handing over passwords or clicking a bad link) tends to follow leaks like this.

Detail Value
Company Wesco International
Employees ~21,000
2023 sales ~$24 billion
Records claimed leaked 2.6 million
System affected Cloud CRM
Extortion group ExfilSquad

Wesco is one of the largest industrial distributors in North America, with more than 700 distribution and sales sites. A leak of its CRM contact book, if genuine, is a useful lure kit for anyone building targeted phishing against the industrial supply chain.

© 2026 Threat Vectr