Wesco says it is investigating a security incident after extortion group ExfilSquad claimed it stole and leaked data from the company’s customer relationship management system. Wesco said the incident involved its cloud CRM environment and that it worked with its cloud CRM vendor, while saying it saw no ransomware or malware on internal systems and did not believe payment-card, bank-account, or other highly sensitive customer and employee data was at risk; ExfilSquad claimed 2.6 million records were taken, and researchers have linked some of the group’s past activity to exposed Microsoft Power Pages data tables.
Why it matters: Wesco is a large global distributor and supply-chain company, so any CRM data theft could affect customers, employees, and business partners across many sectors. Organizations that work with Wesco should watch for targeted phishing or fraud using leaked contact or account data, while Wesco customers and staff should be alert for impersonation attempts.
Bill Toulas
2026.08.11
100% relevant
This article appears to be the first company-confirmed report that Wesco is investigating a cloud CRM data-exfiltration incident tied to ExfilSquad’s public leak claims.
← Back to all stories