“Wesco is aware of a claim of CRM data exfiltration by a third party,” Jennifer Sniderman, Vice President of Corporate Communications at Wesco, told BleepingComputer.
Wesco's public statement and the scope it describes
Wesco, the global supply chain and distribution company, confirmed it is investigating a cybersecurity incident involving the firm's cloud CRM environment. In its statement to BleepingComputer the company said it has “worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.”
The company added that it has not experienced business disruption and that “all operations continue as normal.” According to Wesco, the incident was detected quickly and its internal investigation so far has found no evidence of ransomware or other malicious software on its IT systems. The firm stated explicitly, “We do not believe that payment card information, financial account information or other sensitive customer or employee data is at risk.”
ExfilSquad's claim and the data it says it published
That assurance comes after the data extortion group ExfilSquad claimed to have stolen information from Wesco and then published data on its leak site. The threat actor said it took 2.6 million records and listed the contents as customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.
ExfilSquad reportedly set a deadline for ransom negotiations; after that deadline expired the group published the material it said had been exfiltrated. ExfilSquad has publicly claimed prior breaches at Analog Devices, the U.K.'s Police National Legal Database, and Newcastle University.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadIndicators and possible attack surface: Power Pages and Dynamics 365
Wesco has not disclosed how any alleged breach occurred. BleepingComputer noted publicly available information indicating Wesco may be using Microsoft Dynamics 365, and independent researchers have flagged a recurring pattern in ExfilSquad activity.
Researchers at cybersecurity firms Resecurity and VenariX told BleepingComputer that ExfilSquad has targeted improperly configured Microsoft Power Pages data tables in previous incidents. Those findings are cited as contextual information about the threat actor's known techniques, though Wesco has not confirmed a specific vector in its statement.
How customers, employees, and security teams are affected
- Customers and employees: ExfilSquad's claim describes broad types of personally identifiable and account-related data; Wesco, however, has stated it does not believe payment card, financial account, or other sensitive customer or employee data are at risk.
- Operations and vendors: Wesco reports no business disruption and says it worked with its cloud CRM vendor during the investigation.
- Security and incident response teams: Wesco says the incident was detected quickly and that investigators found no ransomware or other malicious software. External researchers (Resecurity and VenariX) are pointing to a particular configuration weakness—improperly configured Microsoft Power Pages tables—that has been associated with ExfilSquad activity in past cases.
Investigation status, reporting, and open questions
Wesco is conducting an investigation and has engaged its cloud CRM vendor, according to the company's statement. BleepingComputer asked Wesco to confirm ExfilSquad's claims and to provide additional details; the publication has not received a response to its follow-up questions. Meanwhile, ExfilSquad has published the material it said was taken after the company did not enter ransom negotiations.
The public record as of this report therefore contains competing assertions: a threat actor's claim of 2.6 million records posted to a leak site, and a corporate statement that the company detected the incident quickly, found no ransomware or malware, and does not believe sensitive financial or personal data are at risk. The avenue of compromise has not been disclosed; researchers point to improperly configured Power Pages in other ExfilSquad incidents and public information suggests Wesco uses Microsoft Dynamics 365, but Wesco has not detailed any technical root cause.
For now, the immediate facts are straightforward: a data extortion group published material it says came from Wesco, and Wesco says it has investigated with its CRM vendor, sees no evidence of malware, and believes sensitive financial and account data are not at risk. The tension between those two statements, and the unanswered question of how the alleged access occurred, will be the threads to follow as Wesco, its vendor partners, and independent researchers continue their work.
Original reporting: BleepingComputer — Wesco confirms security incident after ExfilSquad claims data theft




