IEH Corporation, a US defense and aerospace supplier, has confirmed that an attacker gained unauthorized access to one of its Microsoft 365 mailboxes through a phishing scam. The incident, disclosed in a Form 8-K filing with the Securities and Exchange Commission, involved an employee falling victim to a sophisticated phishing attempt that harvested their M365 credentials.
According to IEH, the attacker impersonated a prospective business contact and sent the employee a deceptive Microsoft sharing link. This link led to a fake login page designed to capture the victim's M365 username and password. Once inside, the threat actor accessed mailbox contents, including emails, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.
IEH stated that it discovered the intrusion on August 4, though the duration of the compromise period and the initial access date were not specified. The company has secured the compromised account, disabled malicious mailbox rules, preserved evidence, and initiated corrective actions. A review of account security controls and authentication protections for Microsoft 365 services is also underway.
While IEH found no evidence that the accessed information was copied or exfiltrated, the data was accessible to the intruder. Cybersecurity experts note that even without detected exfiltration, compromised mailboxes can be used for various malicious activities, including monitoring communications, impersonating employees, redirecting payments, or preparing subsequent attacks. Data theft in Microsoft 365 logs is not always visible.
IEH, based in Brooklyn, manufactures hyperboloid connectors used in demanding environments for printed circuit boards, medical devices, commercial aircraft, fighter jets, missiles, satellites, and other systems. Its components are integrated into significant US defense programs such as the PATRIOT air-defense system, AMRAAM, THAAD, the APKWS precision-guided rocket, and the MARK-48 torpedo.
The company has indicated that the incident has not disrupted its operations and is not expected to have a material impact, though the investigation is ongoing. While the attack's attribution remains unconfirmed, IEH's involvement in defense and aerospace makes it a potential target for both state-sponsored espionage and financially motivated cybercriminals. Both Russian and Chinese state-linked actors have previously been observed targeting US organizations for defense-related information.






