Data Security

Wesco investigates cybersecurity incident after data extortion group claims breach

Plain code with the word "cyberattack" in red.

According to Bleeping Computer, global supply chain and distribution company Wesco is investigating a cybersecurity incident after the data extortion group ExfilSquad claimed to have stolen sensitive information.

Wesco confirmed the incident involves its cloud CRM environment and stated that it is working with its vendor. The company does not believe sensitive data is at risk and has not experienced any business disruption, with operations continuing as normal. Wesco's investigation found no evidence of ransomware or other malicious software on its IT systems, and it does not believe payment card, financial account, or other sensitive customer or employee data is compromised.

ExfilSquad, known for previous breaches, claimed to have stolen 2.6 million records containing personal information, account data, and CRM user profiles. The group subsequently published the data after Wesco did not meet their ransom demands. While Wesco has not disclosed the breach method, researchers suggest ExfilSquad has previously targeted misconfigured Microsoft Power Pages data tables, and Wesco may use Microsoft Dynamics 365.

Source: Bleeping Computer

You can skip this ad in 5 seconds