Ransomware victim disclosure
← All victimsWesco International
Claimed by ExfilSquad · listed 3 days ago
Status timeline
- ListedJul 26, 2026
- Data leakeddate unknown
At a glance
- Group
- ExfilSquad
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Jul 26, 2026
About the victim
AI dossier — public-source company profileWesco International is a major electrical and communications distributor serving North America with approximately $24 billion in annual revenue. The company supplies products and services to construction, industrial, utility, and communications markets.
- Industry
- Electrical & Electronics Distribution
Attack summary
Severity: critical — Confirmed exfiltration of large-scale PII (2.6M records) including employee and customer personal information, authentication credentials, and financial identifiers. No encryption mentioned—appears to be data theft only.ExfilSquad claims to have exfiltrated approximately 2.6 million records containing customer and employee PII, account data, CRM profiles, credit identifiers, authentication metadata, and access information from Wesco International.
Data the group says was taken
AI dossier — extracted from the leak post- customer PII
- employee PII
- account and contact data
- CRM user profiles
- credit identifiers
- business identifiers
- authentication metadata
- access information
What the group claims
Revenue: $24B DATA SUMMARY: 2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

