1w ago · bleeping-computer
Wesco confirmed a cybersecurity incident involving its cloud CRM environment after the data extortion group ExfilSquad claimed to have stolen and leaked 2.6 million records containing customer and employee PII, CRM data, and authentication metadata. The company stated it does not believe sensitive data is at risk and reported no ransomware or malicious software found in its systems. ExfilSquad, known for targeting improperly configured Microsoft Power Pages, published the data after Wesco did not meet a ransom deadline. Researchers link the group's past activity to misconfigured Microsoft Dynamics 365 instances.