LIVE · cybersecurity feed
Live wire
phishing

Attacker phished way into US defense supplier's Microsoft 365 account

Intruder gained access to engineering files and potentially export-controlled technical data

zeroday.news ·

IEH Corporation, a US defense and aerospace supplier, has confirmed that an attacker gained unauthorized access to one of its Microsoft 365 mailboxes through a phishing scam. The incident, disclosed in a Form 8-K filing with the Securities and Exchange Commission, involved an employee falling victim to a sophisticated phishing attempt that harvested their M365 credentials.

According to IEH, the attacker impersonated a prospective business contact and sent the employee a deceptive Microsoft sharing link. This link led to a fake login page designed to capture the victim's M365 username and password. Once inside, the threat actor accessed mailbox contents, including emails, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information.

IEH stated that it discovered the intrusion on August 4, though the duration of the compromise period and the initial access date were not specified. The company has secured the compromised account, disabled malicious mailbox rules, preserved evidence, and initiated corrective actions. A review of account security controls and authentication protections for Microsoft 365 services is also underway.

While IEH found no evidence that the accessed information was copied or exfiltrated, the data was accessible to the intruder. Cybersecurity experts note that even without detected exfiltration, compromised mailboxes can be used for various malicious activities, including monitoring communications, impersonating employees, redirecting payments, or preparing subsequent attacks. Data theft in Microsoft 365 logs is not always visible.

IEH, based in Brooklyn, manufactures hyperboloid connectors used in demanding environments for printed circuit boards, medical devices, commercial aircraft, fighter jets, missiles, satellites, and other systems. Its components are integrated into significant US defense programs such as the PATRIOT air-defense system, AMRAAM, THAAD, the APKWS precision-guided rocket, and the MARK-48 torpedo.

The company has indicated that the incident has not disrupted its operations and is not expected to have a material impact, though the investigation is ongoing. While the attack's attribution remains unconfirmed, IEH's involvement in defense and aerospace makes it a potential target for both state-sponsored espionage and financially motivated cybercriminals. Both Russian and Chinese state-linked actors have previously been observed targeting US organizations for defense-related information.

phishing
ShareXLinkedInWhatsAppFacebook

More News

view all →
phishing

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active "widespread email-driven phishing campaign" that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with an aim to identify key personnel involved in financial workflows and gather related email. "The campaign uses residential proxies to disguise malicious sign-ins as ordinary consumer traffic,

security

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]

cloud

Unveiling good and bad behaviors on the Agentic Internet

Cloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot.

ai

Introducing Radar Researcher: An AI tool for exploring Internet data in plain language

Cloudflare Radar Researcher is a new AI-powered tool that lets you explore global Internet trends and traffic data using plain language. Built entirely on Cloudflare's Developer Platform, it turns natural language queries into real, interactive charts.

security

Meta Ordered to Pay $567 Million Over Child Safety Failures in New Mexico Case

Meta was ordered to pay $567M after a judge ruled its platforms harmed children, bringing New Mexico penalties to $942M. Meta ‘s child-safety legal bill just got another half-billion dollars heavier. A New Mexico state judge ruled that company’s platforms constitute a “public nuisance,” the BBC reports, ordering $567 million into a fund meant to […]

security

Vishing Extortion Group UNC6671 Rebrands After Making Millions

Initially calling itself BlackFile, the group has expanded operations to the Redact, Pink, Helix, and Falcon brands. The post Vishing Extortion Group UNC6671 Rebrands After Making Millions appeared first on SecurityWeek.