🚨Phishing Attack Hits US Defense Supplier's M365 Account
A phishing attack compromised a defense supplier’s Microsoft account
TL;DR
A phishing scam hit a US defense supplier's Microsoft 365, gaining access to sensitive data. The breach was contained but highlights the risks of such attacks.
A security attacker gained unauthorized access to IEH Corporation’s Microsoft 365 account through a phishing scheme on August 4th. The attacker impersonated a business contact and tricked an employee into sharing M365 credentials, exposing emails, attachments, customer communications, purchase orders, engineering documentation, and potentially export-controlled information. Although no data was exfiltrated during the breach period, the incident underscores the severe risks of phishing attacks on defense contractors. IEH Corporation supplies hyperboloid connectors for critical systems in military aircraft, missiles, satellites, and more.

Key Points
IEH Corporation’s M365 was breached on August 4th via phishing scam; no data exfiltrated during compromise period
Attackers impersonated business contact to harvest credentials for IEH's Microsoft account, gaining access to sensitive information
Compromised mailbox contained emails, attachments, customer communications, purchase orders, and engineering documentation
IEH Corporation supplies hyperboloid connectors used in military aircraft, missiles, satellites, and other critical systems
Microsoft 365 services reviewed for security controls and authentication protections following the containment of the breach
Why It Matters
The phishing attack on IEH Corporation's M365 highlights the vulnerability of defense contractors to such schemes. If you're a developer working with sensitive data in a similar environment, this is a stark reminder to strengthen your security protocols and educate employees about phishing threats.
Frequently Asked Questions
Why does this matter?
The phishing attack on IEH Corporation's M365 highlights the vulnerability of defense contractors to such schemes. If you're a developer working with sensitive data in a similar environment, this is a stark reminder to strengthen your security protocols and educate employees about phishing threats.
What happened?
A phishing scam hit a US defense supplier's Microsoft 365, gaining access to sensitive data. The breach was contained but highlights the risks of such attacks.
Comments
Be the first to comment
Enjoyed this article?
Get it daily. 7am. Free. Reads in 5 minutes.
Join 2,707 builders reading daily.