2 Remove Virus

IEH Corporation employee mailbox breached through fake Microsoft 365 sharing link

A phishing attack targeting an employee at US aerospace and defense supplier IEH Corporation gave an unauthorized party access to a Microsoft 365 mailbox containing potentially sensitive business and engineering information.

 

 

IEH disclosed the incident in a Form 8-K filing with the US Securities and Exchange Commission. According to the company, the attacker approached an employee while posing as a prospective business contact and sent what appeared to be a legitimate Microsoft document-sharing link.

The employee followed the link and was taken to a fraudulent Microsoft 365 login page. After credentials were entered, the attacker was able to access the employee’s email account.

IEH has not reported evidence that the compromised credentials were used to enter other corporate systems. The affected mailbox contained a range of business information. According to the SEC filing, the unauthorized party potentially had access to emails and attachments, communications with customers, purchase orders, and engineering documentation.

Some information stored in the account may also have been subject to US export controls. IEH has not disclosed exactly what technical documents were accessible or whether the attacker viewed specific files. The company also said its investigation has found no evidence so far that information from the mailbox was successfully downloaded or otherwise removed.

Similarly, IEH has not identified evidence that the attacker used the compromised account to send unauthorized emails. The company responded by securing the affected account and disabling the mailbox. Digital evidence was preserved for forensic analysis, and the investigation into the compromise remains ongoing.

IEH Corporation manufactures high-performance connectors designed for demanding aerospace and defense applications. Its components are used in equipment including satellites, fighter aircraft, ground and airborne radar systems, and torpedoes. The company’s products are also used in systems associated with platforms such as Patriot and THAAD.

Because of the type of information present in the mailbox, the incident raises questions about what the intruder may have been able to see during the period of unauthorized access. However, IEH’s disclosure does not establish that any particular engineering document or export-controlled file was actually obtained by the attacker.

The attack itself relied on impersonation rather than a reported compromise of Microsoft’s infrastructure. By presenting the phishing message as communication from a potential business contact and directing the employee to a fake document-sharing page, the attacker was able to obtain valid Microsoft 365 credentials.

IEH has not publicly disclosed how long the unauthorized party had access to the mailbox or identified the individual or group responsible for the attack.

The company said that, based on information available when the SEC filing was submitted, it does not expect the security incident to have a material adverse effect on its business operations.

The investigation is continuing, and IEH has not reported confirmed data exfiltration from the compromised mailbox.