Threat Intelligence Brief
Curated summary with source attribution
Source: rescana.com
Threat Risk: Medium
Victim: Wesco (Global Supply Chain and Distribution)
Incident: Data exfiltration from a cloud CRM environment.
Impact: Exposure of 2.6 million PII and corporate records, increasing the risk of downstream phishing and fraud.
Attacker: ExfilSquad
Analysis: The attack targeted Wesco’s cloud CRM, likely exploiting misconfigurations in Microsoft Power Pages or utilizing compromised credentials. While no ransomware was deployed, the threat actor ExfilSquad successfully exfiltrated 2.6 million records. This incident highlights a growing trend of ‘extortion-only’ campaigns that avoid detection by bypassing malware installation.
Recommendations: Audit cloud CRM permissions and public-facing data tables for misconfigurations.; Implement phishing-resistant MFA for all cloud-based administrative accounts.; Monitor network traffic for unauthorized data transfers to common cloud storage services like MEGA or pCloud.
Source: Rescana
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source