Wesco, a Fortune 500 global supply chain and distribution leader, has confirmed it is investigating a cybersecurity incident affecting its cloud CRM environment. This confirmation follows claims by the data extortion group ExfilSquad, which alleged to have stolen 2.6 million records and subsequently leaked them after Wesco reportedly failed to engage in ransom negotiations.
Overview of the Wesco Security Incident
According to BleepingComputer, Wesco’s Vice President of Corporate Communications, Jennifer Sniderman, stated the company is “aware of a claim of CRM data exfiltration by a third party” and has been working with its cloud CRM vendor. Wesco maintains that it does not believe there is a risk to sensitive data, such as payment card or financial account information, and that its business operations have not been disrupted. The company also indicated no evidence of ransomware or other malicious software on its IT systems.
However, ExfilSquad’s claims paint a different picture, alleging the exfiltration of extensive data types. The threat actor asserts that the stolen records include customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. This discrepancy underscores the challenge in assessing data breach impacts when threat actor claims conflict with corporate statements, particularly concerning the sensitivity of the exposed information.
ExfilSquad TTPs Against Cloud CRM Environments
ExfilSquad is a data extortion group that has previously been linked to breaches against entities such as Analog Devices, the U.K.’s Police National Legal Database, and Newcastle University. While Wesco has not publicly disclosed the attack vector, reports from cybersecurity researchers at Resecurity and VenariX indicate that ExfilSquad has a history of targeting improperly configured Microsoft Power Pages data tables. Publicly available information suggests that Wesco may be utilizing Microsoft Dynamics 365, which often integrates with Microsoft Power Pages, making this a plausible vector for the attack.
This incident highlights a common tactic among data extortion groups: exploiting misconfigurations or vulnerabilities in widely used cloud services. The claimed theft of authentication metadata and access information, if true, could pave the way for further attacks or credential stuffing against Wesco’s customers or employees. Security professionals researching detecting unauthorized access to Microsoft Dynamics 365 should be particularly vigilant given the potential for exploitation of associated services like Power Pages.
Actionable Recommendations for Defenders
Organizations, especially those leveraging Microsoft Dynamics 365 and Power Pages, should prioritize the following actions to mitigate similar threats:
- Review Cloud CRM Configurations: Conduct a thorough audit of all cloud CRM environment configurations, paying close attention to access controls, data sharing settings, and permissions, particularly within securing Microsoft Power Pages configurations.
- Patch and Update: Ensure all CRM platforms, associated services, and underlying infrastructure are fully patched and updated to address known vulnerabilities. Regularly check vendor advisories for security bulletins.
- Implement Least Privilege and MFA: Enforce the principle of least privilege for all user accounts accessing CRM data. Implement multi-factor authentication (MFA) for all administrative and user accounts to significantly reduce the risk of unauthorized access even if credentials are compromised.
- Monitor for Anomalous Activity: Deploy and configure logging and monitoring solutions to detect unusual access patterns, large data exfiltrations, or suspicious activities within cloud CRM environments.
- Incident Response Planning: Develop and regularly test an incident response plan specific to data breaches involving cloud services. This includes clear communication protocols for stakeholders and affected parties.
- Employee Training: Educate employees about phishing, social engineering, and the importance of strong, unique passwords to protect against credential theft, which often precedes data exfiltration attempts.
Related: TPWD Data Breach: Third-Party Vendor Compromise Impacts 3 Million, Foxconn North America Ransomware Attack: Nitrogen Group Data Theft