IEH Corporation Hit by Phishing Scam That Exposed Sensitive Defense Data
IEH Corporation, a US defense and aerospace supplier, has revealed that one of its employees fell victim to a phishing scam that gave an attacker access to their Microsoft 365 mailbox. The company reported the incident in a filing with regulators on Thursday.
The attacker impersonated a prospective business contact and sent the employee what appeared to be a genuine Microsoft sharing link. This led the employee to enter their M365 credentials, which were then harvested by the fake login page.
As a result of this breach, the attacker gained access to various sensitive information, including email messages, attachments, customer communications, purchase orders, and engineering-related documentation. Some of these documents may contain export-controlled technical data, making them particularly valuable targets for espionage.