Data extortion group ExfilSquad has claimed to have stolen 2.6 million records from Fortune 500 supply chain giant Wesco, including customer and employee PII, CRM user profiles, credit and business identifiers, and authentication metadata. Wesco confirmed it is investigating a cybersecurity incident involving its cloud CRM environment, but stated it does not believe sensitive data such as payment card or financial account information is at risk and found no evidence of ransomware. After Wesco did not enter ransom negotiations, ExfilSquad published the allegedly stolen data. Researchers at Resecurity and VenariX have linked ExfilSquad's past attacks to misconfigured Microsoft Power Pages data tables, and public information suggests Wesco may use Microsoft Dynamics 365.
Table of contents
Related Articles:Questions this post answers
What attack vector does ExfilSquad use to breach organizations?
ExfilSquad has been linked to targeting improperly configured Microsoft Power Pages data tables. Researchers at Resecurity and VenariX identified this pattern from examining the group's past activity. The group has claimed breaches at Analog Devices, the UK's Police National Legal Database, Newcastle University, and Wesco, in each case exfiltrating data and publishing it after ransom negotiation deadlines expire. Teams hardening Microsoft Power Pages deployments track ExfilSquad TTPs and similar threat actor activity on daily.dev.