On 11 August, Wesco, a global distributor of electrical and industrial products, confirmed a cybersecurity incident after the extortion group ExfilSquad published data it claims to have taken from the company. The group claims 2.6 million records from Wesco's cloud customer relationship management environment: customer and employee personal information, account data, CRM user profiles, business identifiers, authentication metadata. Publication followed the expiry of the ransom deadline, after negotiations failed.
Through vice president Jennifer Sniderman, the company says it has worked with its CRM vendor and does not believe sensitive data is at risk, nor that payment card or financial account information is involved. Both versions coexist, and both need holding at once: a criminal group's claim is not a finding, and a corporate statement mid-investigation is not a conclusion.
But what makes this incident instructive for a risk owner is not the record count. It is what did not happen.
No encryption, no disruption, no plan triggered
Wesco's investigation found neither ransomware nor malware on its infrastructure. Operations were never interrupted. The company kept delivering, invoicing and shipping throughout.
That deserves a pause, because it undoes a widely shared assumption. Almost the entire resilience apparatus organisations have built over the past five years answers one specific scenario: the systems stop, and you have to bring them back. Immutable backups, recovery objectives, degraded mode, crisis cell, downtime communication plan. In the Wesco scenario, none of it fires, because nothing stops. The continuity plan stays in its binder, and rightly so: there is no continuity to maintain.
Yet extortion through data theft alone has become a business model in its own right, precisely because it is simpler. No encryptor to write, no EDR detection at the moment of encryption, and no possible restore to destroy the attacker's leverage. Successful exfiltration is irreversible by nature: no backup un-publishes a record.
And no regulatory disclosure either
Since 2023, the Securities and Exchange Commission has required US-listed companies to report any cybersecurity incident they deem material within four business days, under Item 1.05 of a Form 8-K. As of 13 August, Wesco's EDGAR record contains no such filing: its most recent Form 8-K is dated 30 July and covers quarterly results.
That silence is not a failure, it is a conclusion. It reflects a materiality determination: the company judges that the incident does not materially affect its business, which is consistent with its public statement. And that is exactly where the reasoning becomes instructive for an executive. One and the same event can trigger neither a continuity plan nor a securities disclosure obligation, while still causing real and lasting harm to third parties who decided nothing at all.
The harm does not hit you, it hits your customers
The second shift is less comfortable. In a ransomware attack, the victim absorbs the harm. Here, the breached organisation walks away with reputational discomfort, and the real harm moves downstream.
A distributor's CRM file means names, job titles, work email addresses, order histories and customer account identifiers. In other words, the ideal raw material for targeted phishing and business email compromise. An email quoting your account number, your last order and your rep's exact name does not look like fraud. It looks like a sales follow-up. Wesco's customer base includes utilities, contractors and industrial firms, several of them in Canadian critical infrastructure.
For those organisations, this is not industry news. It is a third-party incident that concerns them directly, and one their supplier probably has not told them about.
The other reading: Wesco is a third party to thousands of organisations
This is where the incident stops being a case study and becomes a test of your own programme.
Ask the question in reverse. If your organisation buys from Wesco, or from any comparable distributor, your contact and account data sat in that CRM. Three questions follow, and a mature third-party risk management programme answers them in hours, while other programmes never do.
- Do you know you are affected? Did you learn it from your supplier, from your own monitoring, or from this article? The gap between publication and your awareness is a direct measure of how mature your setup is.
- Do you know what that supplier holds on you? A vendor inventory that lists providers without qualifying the data entrusted to them cannot answer. You need to state, per supplier, which data categories and which accesses are in play.
- Does your contract give you a right to be notified, and within what deadline? Most industrial supply contracts are silent on this, because they were negotiated as purchasing agreements, not as data processing agreements.
These questions are not asked during the incident. They are prepared, exactly as we set out in our guide to building a third-party risk management programme. And they echo the lesson of the Accenture incident: your attack surface includes your suppliers' systems, whether or not you have assessed them.
What your programme should take away
- Add the "leak without outage" scenario to your exercises. If your last crisis exercise was about mass encryption, you have not tested the more likely case. The scenario to run is: the data is already public, everything works, and you have to decide what to say, to whom, and how fast.
- Map the data entrusted, not just the suppliers. The useful question is not "how many third parties do we have" but "which ones hold data whose publication would hurt us, and which ones hold access".
- Treat the CRM as a critical asset. It runs no production line, so it slips through criticality classifications. Yet it concentrates your entire commercial relationship.
- Prepare the notification before you need it. Depending on who is affected, Law 25, the GDPR or sector regimes impose short deadlines. An incident without downtime buys you no extra time.
- Warn your customers about the phishing wave. When customer relationship data leaks, the next attack targets your customers in your name. Telling them early is a protective measure, and a commercial one.
The question for the board
It fits in a sentence, and it deserves to be asked exactly as written at the next committee: "if our CRM were published tomorrow morning, our continuity plan would not even trigger, so what is our plan?" If the answer involves only the IT function, it is incomplete. An incident of this type is first legal, regulatory and commercial, and it is handled with customers, not with backups.
Where FortaRisks fits
The Third-party risk management module keeps a living inventory of your suppliers, the data you entrust to them and the access they hold, with continuous monitoring rather than an annual questionnaire, so that you learn about a supplier incident somewhere other than the press. The Compliance module then ties your notification obligations to the applicable frameworks, with deadlines and evidence. To place your setup in a few minutes, our free third-party risk readiness check is a good starting point.