Hackers phish their way into US defense manufacturer’s Microsoft 365 account
Exposed details may include highly sensitive export-controlled technical info.

Patriot missile launch. Photo By Idf/Getty Images.
- Hackers breached IEH Corporation's Microsoft 365 mailbox using a phishing link disguised as a legitimate document-sharing invite.
- IEH Corporation supplies connectors for satellites, fighter jets, radars, and missile systems including THAAD and Patriot programs.
- The breach may have exposed export-controlled technical data, engineering documents, purchase orders, and customer communications.
- IEH found no evidence of data exfiltration but disclosed the incident to the SEC via an 8-K filing.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Attackers penetrated IEH Corporation, a US defense and airspace company, via a malicious link that impersonated a legitimate Microsoft sharing link. The hackers accessed an employee’s mailbox, which was full of sensitive information.
IEH Corporation disclosed the security incident in an 8-K form filed with the Securities and Exchange Commission (SEC). According to the company, a threat actor stole access to an employee’s Microsoft 365 mailbox.
IEH Corporation makes connectors used in satellites, fighter jets, ground radars, torpedoes, and airborne radars. Some of its produce is used in precision-guided missile systems such as THAAD and Patriot.
According to the 8-K form, attackers managed to access the IEH Corporation employee’s mailbox after impersonating a “prospective business contact.” The fraudster sent a hyperlink disguised as a Microsoft document-sharing link.
“The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access,” reads the form.
According to the company, attackers may have accessed:
- Email messages
- Attachments
- Customer communications
- Purchase orders
- Engineering-related documentation
- Potentially export-controlled technical information
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Export-controlled technical information typically involves blueprints, software, or engineering designs that the US government regulates to protect national security interests. Given the IEG Corporation profile, it is highly likely that the exposed data could be related to arms manufacturing.
“No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period,” the company said.
IEH said the company has secured the account and disabled the affected mailbox, while preserving digital forensics for the subsequent investigation. So far, there’s no information that anyone has downloaded or exfiltrated sensitive details from the impacted mailbox.
“As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations,” IEH said.