IEH, a U.S. defense and aerospace supplier, says an attacker phished an employee and got into the company’s Microsoft 365 email environment. The attacker posed as a prospective business contact and used a fake Microsoft sharing link and login page to steal credentials, giving access to email, attachments, purchase orders, customer communications, engineering documents, and potentially export-controlled technical information. IEH says it found the incident on August 4, 2026, disabled malicious mailbox rules, and has not found evidence of exfiltration so far.
Why it matters: This matters because a single phished Microsoft 365 account can expose sensitive internal files and enable follow-on fraud or espionage, especially at a defense supplier. Organizations using Microsoft 365 should review phishing-resistant authentication, mailbox rules, sign-in logs, and access to sensitive engineering data now.
2026.08.07
98% relevant
This article is a direct report of the same IEH Corporation incident, adding that the company disclosed it in an SEC 8-K, said there is currently no evidence of data exfiltration, and specified the exposed mailbox contents included purchase orders, engineering documentation, and potentially export-controlled information.
SecurityWeek News
2026.08.07
91% relevant
The roundup references the same IEH phishing-linked mailbox breach involving Microsoft 365, adding it as one of the week’s notable undercovered incidents.
2026.08.07
100% relevant
This article appears to be the first concrete report of IEH's SEC-disclosed Microsoft 365 breach and establishes the underlying event.
← Back to all stories