Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Microsoft Dynamics 365 Community

Microsoft Dynamics 365 Community Vendor Cyber Rating & Cyber Score

dynamics.com

Your home for all things Microsoft Dynamics 365! Connect with the global community and discover tips and tricks, unique insights, news and product updates--and so much more. From Community Calls to featured IT Pro blogs, from the latest events to feature stories--whether CRM or ERP, you'll find it here.


MDC A.I CyberSecurity Scoring

MDC
Company Information
Website:https://community.dynamics.com
Employees number:590
Number of followers:64,505
NAICS:5112
Industry Type:Software Development
Homepage:dynamics.com
MDC Risk Score (AI oriented)
Between 750 and 799
logo
MDCSoftware Development
Updated:
17/08/2026
757/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
MDC Global Score (TPRM)
xxxx
logo
MDCSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

MDC
MDCFair
Current Score
757Baa (FAIR)
01000
1 incidents
-91 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
667Before Incident
AUGUST 2026
757Before Incident
Breach
11 Aug 2026MDC
Wesco: Wesco Cloud CRM Data Breach: ExfilSquad Data Theft and Supply Chain Risks Analyzed

Wesco Investigates Data Breach After ExfilSquad Claims Theft of 2.6 Million Records

666After Incident
CRITICAL-91
WES1786569977
Wesco Investigates Data Breach After ExfilSquad Claims Theft of 2.6 Million Records On August 11, 2026, global supply chain and distribution company Wesco confirmed it is investigating a cybersecurity incident following claims by the data extortion group ExfilSquad that it stole and leaked 2.6 million records from the company’s cloud CRM environment. Wesco stated that no business disruption occurred, no ransomware or malware was detected on internal systems, and sensitive customer or employee data including payment card or financial account information was not believed to be at risk. However, ExfilSquad’s leak allegedly includes personally identifiable information (PII), account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access-related details, raising concerns about downstream phishing, business email compromise (BEC), and fraud risks for Wesco’s partners and customers. The attack appears to have targeted Wesco’s cloud CRM system, likely based on Microsoft Dynamics 365, with potential exploitation of misconfigured Microsoft Power Pages data tables. ExfilSquad, known for extortion-only operations, typically gains initial access via compromised credentials or exposed cloud applications, then uses legitimate tools like 7z, rclone, and PowerShell to stage and exfiltrate data to attacker-controlled cloud storage (e.g., MEGA, pCloud). The group’s tactics align with the MITRE ATT&CK framework, including valid account abuse (T1078), cloud service discovery (T1526), and exfiltration over web services (T1567.002). No malware was detected, and all activities leveraged dual-use administrative tools, complicating detection. ExfilSquad has a history of targeting supply chain, education, and public sector organizations, with prior breaches at Analog Devices, the UK’s Police National Legal Database, and Newcastle University. The stolen data reportedly containing customer lists, shipment details, and project pricing poses significant third-party risk, as it can be weaponized for spear phishing and invoice fraud across Wesco’s ecosystem. Key Timeline: - August 7, 2026: ExfilSquad begins distributing stolen data via torrents. - August 11, 2026: Wesco confirms the incident after ExfilSquad publishes the leaked data following failed ransom negotiations. As of the report date, no technical indicators of compromise (IOCs) beyond a single domain (mallory[.]ai) have been publicly disclosed, and no regulatory filings or law enforcement advisories have been referenced. The incident underscores the growing threat of data theft extortion targeting cloud environments, particularly in sectors handling sensitive partner data.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Extortion
IMPACT
Data Compromised: 2.6 million recordsSystems Affected: Cloud CRM system (Microsoft Dynamics 365)Operational Impact: No business disruptionIdentity Theft Risk: High (PII exposed)Payment Information Risk: None (payment card or financial account information not believed to be at risk)
DATA BREACH
Personally identifiable information (PII)Account and contact dataCRM user profilesCredit and business identifiersAuthentication metadataAccess-related detailsNumber Of Records Exposed: 2.6 millionSensitivity Of Data: High
JULY 2026
757Before Incident
JUNE 2026
757Before Incident
MAY 2026
757Before Incident
APRIL 2026
757Before Incident
MARCH 2026
757Before Incident
FEBRUARY 2026
757Before Incident
JANUARY 2026
757Before Incident
DECEMBER 2025
757Before Incident
NOVEMBER 2025
757Before Incident
OCTOBER 2025
757Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for MDC ?
?
What was MDC's A.I Rankiteo Cyber Score in August 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in July 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in June 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in May 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in April 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in March 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in February 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in January 2026 ?
?
What was MDC's A.I Rankiteo Cyber Score in December 2025 ?
?
What was MDC's A.I Rankiteo Cyber Score in November 2025 ?
?
What was MDC's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on MDC's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with MDC ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view MDC's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?