IEH Corporation, a US defense and aerospace supplier and military device manufacturer, disclosed that attackers accessed an employee's Microsoft 365 mailbox after a phishing campaign used a fake Microsoft sharing link and counterfeit login page to steal credentials. The compromised inbox contained email messages, attachments, customer communications, purchase orders, engineering documentation, and potentially export-controlled technical information, giving the intruder access to sensitive business and technical materials during the period of compromise.
The company said it discovered the intrusion on August 4 and moved to secure the account, disable malicious mailbox rules, preserve evidence, and review Microsoft 365 security controls and authentication protections. IEH reported no evidence of data exfiltration or operational disruption and said it does not currently expect a material business impact, although the investigation and corrective actions remain ongoing.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
IEH discovered the intrusion on August 4 and responded by securing the compromised account, disabling malicious mailbox rules, preserving evidence, and starting corrective actions. The company also began reviewing Microsoft 365 security controls and authentication protections.
IEH disclosed the cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission. The company said it had found no evidence of data exfiltration, operations were not disrupted, and it did not currently expect a material impact while the investigation continued.
As part of its response to the Microsoft 365 mailbox compromise, IEH notified relevant law enforcement authorities and launched an investigation with assistance from external cybersecurity experts. The company also said it activated incident response and business continuity procedures while reviewing whether affected parties or regulators must be notified.
IEH said an attacker impersonated a prospective business contact, used a fake Microsoft sharing link and counterfeit login page, and gained access to one employee's Microsoft 365 mailbox. The accessible mailbox contents included emails, attachments, customer communications, purchase orders, engineering documentation, and potentially export-controlled technical information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecurityaffairs.com
Open sourcetherecord.media
Open sourcetheregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.