Wesco Investigates CRM Breach After ExfilSquad Claims Data Theft

Wesco Probes Cloud CRM Breach Claimed by 'ExfilSquad'

HIGH
August 13, 2026
4m read
Data BreachCloud SecuritySupply Chain Attack

Impact Scope

People Affected

2.6 million records

Affected Companies

Wesco

Industries Affected

ManufacturingRetailTransportation

Related Entities

Threat Actors

ExfilSquad

Products & Tech

Microsoft Dynamics 365Microsoft Power Pages

Other

Wesco

Full Report

Executive Summary

Wesco, a Fortune 500 global supply chain and distribution company, is investigating a cybersecurity incident after the data extortion group ExfilSquad claimed to have breached its cloud Customer Relationship Management (CRM) environment. On August 11, 2026, ExfilSquad added Wesco to its dark web leak site, alleging the theft of 2.6 million records. The group later published the data when its ransom demands were not met. The stolen information reportedly includes customer and employee Personally Identifiable Information (PII), contact details, and CRM user profiles. While Wesco stated that its business operations were not disrupted and no ransomware was involved, the incident highlights the growing threat of extortion-only attacks targeting misconfigured cloud applications.

Threat Overview

The incident follows a typical data extortion playbook employed by groups like ExfilSquad.

  • Threat Actor: ExfilSquad, a data extortion group known for stealing data and leaking it if a ransom is not paid. They do not typically deploy ransomware.
  • Attack Vector: While not officially confirmed by Wesco, the attack likely exploited a misconfiguration in Wesco's cloud CRM platform, suspected to be Microsoft Dynamics 365 or Microsoft Power Pages. ExfilSquad has a known history of targeting improperly configured data tables in Microsoft Power Pages.
  • Exfiltrated Data: The attackers claim to have stolen 2.6 million records, including:
    • Customer and employee PII
    • Account and contact details
    • CRM user profiles
    • Credit and business identifiers
    • Authentication metadata
  • Impact: The group published the stolen data on its leak site, exposing Wesco, its employees, and its customers to follow-on risks.

Technical Analysis

The attack likely falls under the category of exploiting misconfigured cloud services.

  1. Reconnaissance (T1595.001): ExfilSquad likely scanned for public-facing Microsoft Power Pages portals with misconfigured table permissions that allow anonymous users to access data.
  2. Collection (T1530): Upon discovering a vulnerable portal, the attackers used APIs to systematically query and exfiltrate all data from the exposed tables. This is not a 'hack' in the traditional sense of exploiting a software vulnerability, but rather taking advantage of a security misconfiguration.
  3. Impact (T1657): The group used the stolen data for extortion. When Wesco did not pay the ransom, ExfilSquad leaked the data to inflict reputational damage and to pressure future victims into paying.

This TTP is increasingly common as more organizations adopt low-code/no-code platforms like Power Pages without fully understanding the security implications of data permissions.

Impact Assessment

For Wesco, the incident results in significant reputational damage and potential regulatory scrutiny, even if core financial systems were not impacted. The leaked data exposes its employees and customers to risks such as identity theft, spear-phishing, and business email compromise (BEC) attacks. For the broader industry, this attack serves as a critical warning about the security risks inherent in rapidly deployed cloud and SaaS applications. A simple misconfiguration—a checkbox in a settings panel—can lead to a multi-million-record data breach.

IOCs — Directly from Articles

No specific IOCs were provided in the source articles.

Cyber Observables — Hunting Hints

To identify similar risks, organizations using Microsoft Power Platform should look for:

Type
Other
Value
Anonymous Table Permissions
Description
Any table in Microsoft Dataverse that allows 'Read' access to anonymous users is a potential risk.
Type
Log Source
Value
Power Platform audit logs
Description
Monitor for an unusually high volume of read operations from an unauthenticated user or a single IP address against a specific table.
Type
URL Pattern
Value
*.powerappsportals.com
Description
This is the default domain for Power Pages portals. Organizations should be aware of all such portals they have deployed.

Detection & Response

  • SaaS Security Posture Management (SSPM): Use SSPM tools to continuously audit Power Platform environments for misconfigurations, particularly anonymous table permissions and open-to-public portals.
  • Auditing: Regularly enable and review audit logs within the Power Platform and Dataverse to look for anomalous data access patterns. D3FEND's Cloud API Monitoring (D3-CAM) is relevant here.
  • Data Discovery: Run data discovery tools to understand what sensitive data resides in Dataverse tables to prioritize securing them.

Mitigation

  • Review Table Permissions (M1054): The most critical mitigation is to review all table permissions in Microsoft Power Pages and Dataverse. By default, access should be denied to anonymous users. Only explicitly and intentionally expose public data.
  • Principle of Least Privilege: Apply the principle of least privilege to all aspects of the cloud environment, from user accounts to API permissions and data table access.
  • Developer Training: Train developers and citizen developers using low-code platforms on secure configuration best practices. Security cannot be an afterthought in a rapid development environment.
  • Vendor Risk Management: For supply chain partners, this incident underscores the need to ask specific questions about how their data is protected in their partners' cloud environments.

Timeline of Events

1
August 11, 2026
Wesco acknowledges it is investigating a cybersecurity incident after claims from ExfilSquad.
2
August 13, 2026
This article was published

MITRE ATT&CK Mitigations

The primary mitigation is to correctly configure table permissions in Microsoft Power Pages, ensuring that sensitive data is not accessible to anonymous users.

Mapped D3FEND Techniques:

Audit

M1047enterprise

Regularly audit cloud configurations and data access logs to proactively identify misconfigurations and detect anomalous access patterns.

Timeline of Events

1
August 11, 2026

Wesco acknowledges it is investigating a cybersecurity incident after claims from ExfilSquad.

Sources & References

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachExtortionExfilSquadCloud SecurityMisconfigurationMicrosoft Power Pages

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.