IEH says phishing attack exposed Microsoft 365 mailbox with defense engineering and potentially export-controlled data

IEH, a U.S. defense and aerospace supplier, says an attacker phished an employee and got into the company’s Microsoft 365 email environment. The attacker posed as a prospective business contact and used a fake Microsoft sharing link and login page to steal credentials, giving access to email, attachments, purchase orders, customer communications, engineering documents, and potentially export-controlled technical information. IEH says it found the incident on August 4, 2026, disabled malicious mailbox rules, and has not found evidence of exfiltration so far.
Why it matters: This matters because a single phished Microsoft 365 account can expose sensitive internal files and enable follow-on fraud or espionage, especially at a defense supplier. Organizations using Microsoft 365 should review phishing-resistant authentication, mailbox rules, sign-in logs, and access to sensitive engineering data now.

Sources

Military device manufacturer discloses cyber incident to SEC
2026.08.07 98% relevant
This article is a direct report of the same IEH Corporation incident, adding that the company disclosed it in an SEC 8-K, said there is currently no evidence of data exfiltration, and specified the exposed mailbox contents included purchase orders, engineering documentation, and potentially export-controlled information.
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
SecurityWeek News 2026.08.07 91% relevant
The roundup references the same IEH phishing-linked mailbox breach involving Microsoft 365, adding it as one of the week’s notable undercovered incidents.
Attacker phished way into US defense supplier's Microsoft 365 account
2026.08.07 100% relevant
This article appears to be the first concrete report of IEH's SEC-disclosed Microsoft 365 breach and establishes the underlying event.
← Back to all stories