US Defense Supplier IEH Corp Breached Via Phishing Attack on Microsoft 365
IEH Corporation, a US defense supplier, disclosed a breach of its Microsoft 365 environment following a phishing attack that compromised an employee's credentials.

IEH Corporation, a prominent US supplier for the defense and aerospace industries, has reported a security incident where a threat actor gained unauthorized access to its Microsoft 365 environment. The breach, detailed in a filing with the Securities and Exchange Commission (SEC), originated from a sophisticated phishing attack targeting an employee.
The incident unfolded when an employee received an email impersonating a business contact, which contained a link designed to mimic a legitimate Microsoft sharing notification. Upon clicking the link, the employee was directed to a fake login page that harvested their Microsoft 365 credentials. This allowed the attacker to access the contents of the employee's mailbox.
According to IEH's disclosure, the compromised mailbox contained sensitive information including email messages, attachments, customer communications, purchase orders, and engineering-related documentation. Of particular concern is the potential exposure of export-controlled technical information, given IEH's role in supplying critical components for advanced defense systems.
While IEH stated that it has found no evidence of data exfiltration, the accessible nature of the information during the compromise period raises significant concerns. The company discovered the intrusion on August 4, 2026, and has since secured the affected account, disabled malicious mailbox rules, and begun preserving evidence. The exact duration of the attacker's access remains undisclosed.
In response to the incident, IEH is undertaking corrective actions and initiating a review of its security controls and authentication measures for Microsoft 365 services. The company has assured that the breach has not disrupted its operations and does not anticipate a material impact, though investigations are ongoing.
Experts caution that even without detected exfiltration, compromised mailboxes can be exploited for various malicious purposes. These include monitoring internal communications, impersonating employees for further social engineering, redirecting financial transactions, or laying the groundwork for more extensive follow-on attacks. The true extent of the compromise may not always be evident in standard logs.
IEH Corporation, based in Brooklyn, New York, manufactures specialized hyperboloid connectors used in demanding environments. Its components are integral to numerous high-profile US defense programs, including the PATRIOT air-defense system, AMRAAM missiles, THAAD, and the MARK-48 torpedo, underscoring the potential strategic implications of such a breach.
While the specific threat actor behind this attack has not been identified, the targeting of a defense supplier's sensitive data aligns with the objectives of nation-state actors and sophisticated cybercriminal groups. The incident highlights the persistent threat of phishing and credential harvesting against cloud-based productivity suites, even among organizations handling critical national security information.