On 11 August 2026, WESCO International, Inc. (Wesco), a Fortune 500 distributor of electrical, electronic, communications, security, utility and broadband products with roughly 21,000 employees across 50 countries, confirmed it was investigating a cybersecurity incident. The confirmation came after the data extortion group ExfilSquad claimed to have exfiltrated sensitive data from the company's cloud CRM environment. Wesco's investigation found no ransomware and no malware on its systems, and the company said it does not believe payment card information, financial account details, or other sensitive customer or employee data is at risk.
ExfilSquad claims otherwise. The group says it took 2.6 million records covering customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information, then published the set on its leak site after Wesco's ransom deadline expired without payment. Wesco has not confirmed how the group obtained the data, but researchers at Resecurity and VenariX, who have tracked ExfilSquad's recent campaigns, say the group has repeatedly targeted misconfigured Microsoft Power Pages data tables, and public information indicates Wesco's CRM environment runs on Microsoft Dynamics 365.
If that reporting holds, the mechanics are almost anticlimactic. Power Pages portals are built to expose selected tables to the public web by design. When the access controls on those tables are left at default or configured too broadly, anyone who finds the endpoint can query and export whatever the table holds. No phishing email. No vished employee. No stolen session token. Just a public API answering a request it should never have been configured to answer, at a scale of 2.6 million records.
This is not ExfilSquad's first run at this exact failure mode. The group claimed a near-identical breach of the UK's Police National Legal Database on 26 July, where more than 100,000 records tied to serving police officers, prosecutors and national security staff left without a single compromised password. It has made the same claim against Analog Devices and Newcastle University this year. Three organisations, three data sets, and in each case a threat actor that never needed to steal a credential because nobody had gated the export in the first place.
The defences that failed here were not weak by conventional standards. Wesco's endpoint protection, identity monitoring and network detection all had nothing to catch, because nothing anomalous happened at the identity or endpoint layer. No account logged in from an unfamiliar location. No malware ran. The gap sat one layer up, at the point where a data table capable of returning millions of records had no step between the request and the export that checked whether the request should be allowed to happen at all.
A bulk export at that scale is an execution event, whatever the requester presents. Under GoFirm, a query against a CRM data table that returns records beyond a defined threshold triggers a real-time confirmation request to the named data owner on their registered device before the export completes. The request does not depend on whether the caller authenticated correctly. It depends on whether a named human authorised this specific export, at this scale, right now.
An anonymous request against a misconfigured public endpoint cannot produce that confirmation. Neither can a stolen password, a vished credential, or a forged token. The execution boundary holds regardless of how the request arrives.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Toulas, B. 2026. Wesco confirms security incident after ExfilSquad claims data theft. BleepingComputer, 11 August 2026.
2. Toulas, B. 2026. ExfilSquad hackers leak info of over 100,000 UK police officers, staff. BleepingComputer, 4 August 2026.
