Illustrative image generated with AI
IEH Hit by Phishing Attack: Defense Emails and Technical Documents at Risk
IEH Corporation, a Brooklyn-based U.S. company that manufactures defense and aerospace components, reported a cyber incident to the SEC in an 8-K filing.
Text generated by artificial intelligence, published without human review. AI transparency
Access to the Microsoft 365 Mailbox
IEH Corporation, a Brooklyn-based U.S. company that manufactures defense and aerospace components, reported a cyber incident to the SEC in an 8-K filing.
The breach was discovered on August 4, 2026, and disclosed publicly on August 9, 2026. An unidentified threat actor impersonated a prospective business contact and sent an employee a link disguised as a shared Microsoft document.
The link led to a fake login page. After the employee entered their Microsoft 365 credentials, the attacker gained unauthorized access to the mailbox.
The attacker also created mailbox rules, which IEH later removed. Such rules can be used to hide messages, intercept future communications, or maintain access to the account for longer.
Information That May Have Been Exposed
The access may have allowed the attacker to view emails and attachments, customer data, and engineering documentation. Potentially exposed materials may also have included technical information subject to export controls and data related to military systems.
IEH manufactures high-reliability electrical connectors, including hyperboloid models used in:
- rotary-wing aircraft;
- THAAD and Patriot missile systems;
- combat aircraft;
- airborne radar systems;
- satellites and spacecraft;
- military radio equipment;
- torpedoes.
The potential disclosure of information covered by ITAR or EAR to unauthorized foreign persons could have consequences under U.S. federal law.
Exfiltration Not Confirmed
IEH has not confirmed that any data was copied or transferred outside its systems. The confirmed impact is limited to the compromise of a Microsoft 365 mailbox and access to its contents.
The company has not identified the responsible group or the country of origin of the attack. IEH also stated that, at this time, it has no evidence of a material impact on its operations.
The risk remains significant because IEH operates within the U.S. defense supply chain and reported nearly $30 million in revenue for fiscal year 2026.
Response Measures and Required Checks
IEH contained the intrusion, secured the compromised account, and removed the malicious mailbox rules. The investigation is ongoing.
For organizations using Microsoft 365, the incident highlights several priority controls:
- review recently created mail-flow rules;
- check account sign-ins, active sessions, and configured forwarding;
- revoke tokens and active sessions after a credential compromise;
- force a password reset and enable multifactor authentication;
- review emails and attachments accessed by the account;
- search for messages impersonating business contacts and shared Microsoft documents.
The specific Microsoft 365 product versions involved have not been disclosed.
Sources
This article is an original reworking based on the sources below.
