← Wesco International

2026 Wesco — ExfilSquad CRM claim; company confirms cloud CRM incident (actor ~2.6M)

2026 2.6M records affected Share on X

Data compromised

ExfilSquad claims ~2.6M records: customer/employee PII, account/contact data, CRM profiles, credit/business identifiers, auth metadata. Wesco says it worked with CRM vendor and does not believe sensitive data is at risk; no ransomware on IT systems. Actor count labeled unverified against company sensitive-data denial.

Technical writeup

Company-confirmed CRM security incident — statement to BleepingComputer August 11, 2026 following ExfilSquad leak-site activity. Wesco VP Jennifer Sniderman said the firm is aware of a third-party claim of CRM data exfiltration, worked with its cloud CRM vendor, does not believe sensitive data is at risk, reported no business disruption, and found no ransomware on IT systems after quick detection. ExfilSquad claimed ~2.6 million records (customer/employee PII, contacts, CRM profiles, identifiers, auth metadata) and published alleged data after a negotiation deadline. Researchers (Resecurity, VenariX) have previously tied ExfilSquad to misconfigured Microsoft Power Pages tables; Wesco uses Microsoft Dynamics 365 in public materials. BreachHistory indexes companyConfirmed true for the CRM incident and recordsAffected 2600000 as the actor-cited scale, clearly labeled unverified relative to Wesco’s sensitive-data assessment.

Root cause

Company-confirmed cybersecurity incident involving cloud CRM environment after ExfilSquad claimed CRM data theft and published alleged exfil; researchers note ExfilSquad history with misconfigured Microsoft Power Pages

References