Wesco confirms security incident after ExfilSquad claims data theft

57 minutes ago 7

Wesco confirms security incident after ExfilSquad claims data theft

Global supply chain and distribution giant Wesco has confirmed in a statement to BleepingComputer that it is investigating a cybersecurity incident.

The company's statement comes after data extortion group ExfilSquad claimed to have stolen sensitive information from Wesco and leaked it on their data leak site.

Jennifer Sniderman, Vice President of Corporate Communications at Wesco, said that the incident involves the company's cloud CRM environment.

image

“Wesco is aware of a claim of CRM data exfiltration by a third party,” Sniderman told BleepingComputer.

“We have worked with our cloud CRM vendor on the matter, and we do not believe that there is a risk to sensitive data.”

The company representative added that Wesco has not experienced any business disruption, and all operations continue as normal.

Wesco said the incident was detected quickly, and its subsequent investigation found no evidence of ransomware or other malicious software on its IT systems.

“We do not believe that payment card information, financial account information or other sensitive customer or employee data is at risk,” stated the firm.

Wesco is a Fortune 500 company that distributes electrical, electronic, communications, security, utility, and broadband products while providing logistics and supply chain services to businesses.

The company employs approximately 21,000 people and operates more than 700 distribution centers, fulfillment centers, and sales offices across roughly 50 countries. Wesco generated about $24 billion in sales last year.

Recently, the data extortion group ExfilSquad, known for data breaches at Analog Devices, the U.K.'s Police National Legal Database, and Newcastle University, claimed a breach at Wesco.

The threat actor claimed to have stolen 2.6 million records containing customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

After the hacker's deadline for the company to enter ransom payment negotiations expired, ExfilSquad published the data allegedly exfiltrated from Wesco's systems.

Wesco listed on the ExfilSquad portalWesco listed on the ExfilSquad portal
Source: BleepingComputer

BleepingComputer asked Wesco to confirm ExfilSquad's claims, but we have not received a response to our additional questions.

However, recent reports from researchers at cybersecurity companies Resecurity and VenariX examining ExfilSquad activity indicate that the threat actor has targeted in the past improperly configured Microsoft Power Pages data tables.

Wesco has not shared how the threat actor breached its network, but publicly available information indicates that Wesco may be using Microsoft Dynamics 365.

article image

Test every layer before attackers do

Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

Get the whitepaper

Read Entire Article