US Defense Supplier Breached by Phishing Attack on Microsoft 365 Account
A US defense and aerospace supplier, IEH Corporation, has revealed that it was breached by an attacker who phished their way into a Microsoft 365 account.
The attack occurred when one of IEH's employees fell for a phishing scam that tricked them into giving up their M365 login credentials. The attacker used the stolen info to gain access to various data, including email messages, attachments, customer communications, purchase orders, and engineering-related documentation.
IEH discovered the breach on August 4 and reported it to regulators. While there's no evidence that the data was copied or exfiltrated, it's likely that the attacker could have used the compromised mailbox for monitoring communications, impersonating employees, or redirecting payments.
IEH's work with defense and aerospace customers makes it an attractive target for espionage, but ordinary cybercriminals also compromise mailboxes for fraud and data theft. The company has initiated a review of its account security controls and authentication protections to prevent similar incidents in the future.