Phishing Attack Compromises US Defense Supplier's Microsoft Mailbox
A US defense and aerospace supplier, IEH Corporation, has revealed that it was breached through a phishing attack on its Microsoft 365 mailbox. The incident occurred when an employee fell victim to a fake email posing as a business contact, which led to the capture of their Microsoft 365 credentials.
The attacker gained access to emails, attachments, customer communications, purchase orders, engineering documents, and potentially export-controlled technical information. While IEH has stated that there is no evidence of data exfiltration, the compromised mailbox could have been used for malicious activities such as monitoring communications or preparing further attacks.
IEH discovered the intrusion on August 4 but did not disclose the exact duration of the breach or the initial access date. The company has secured the account, disabled malicious rules, and is implementing corrective actions and reviewing security controls.