Phishing Attack Compromises IEH Employee's Mailbox
IEH Corp has reported a breach of one of its Microsoft 365 mailboxes due to a phishing attack. According to an SEC filing, the threat actor accessed the employee's email account after entering their credentials into a fraudulent login page.
The compromised mailbox contained sensitive information, including emails, attachments, customer communications, purchase orders, and engineering documents, potentially including export-controlled data.
However, the company claims that there is no evidence of data exfiltration or unauthorized transmission from the affected account. IEH has taken steps to contain the incident by securing the mailbox, disabling malicious rules, and completing corrective actions.
An ongoing review of security controls and impacted communications will also be conducted.