The ExfilSquad ransomware group listed Wesco International in July 2026, claiming to have exfiltrated internal files. Public reporting does not yet include an official, company-confirmed breach notification or a confirmed individual impact count.
Reported data types include customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information. The exact number of affected individuals remains unknown, though attackers claim approximately 2.6 million records were accessed. Public reporting does not confirm the exposure of SSNs, medical data, or payment-card data.
Details regarding consumer notifications and regulatory notifications are not publicly available, and the full scope of the breach remains unclear.