Attacker phished way into US defense supplier’s Microsoft 365 account

← Back to the feed

Attacker phished way into US defense supplier’s Microsoft 365 account

The Register · 3 weeks ago

IEH Corporation, a US defence and aerospace supplier, says an attacker accessed a staff member’s Microsoft 365 account after the employee was deceived by a phishing email posing as a prospective business contact. The breach matters because the mailbox contained engineering documents and potentially export-controlled technical information, although the company says it has found no evidence that data was copied or taken.

IEH discovered the incident on 4 August and secured the affected account, disabled malicious mailbox rules and began reviewing its Microsoft 365 security and authentication controls. The company did not say when access began or how long it lasted, and expects no material operational impact; its connectors are used in systems including military aircraft, missiles, satellites and US weapons programmes.

  • Phishing gave an attacker access to IEH’s Microsoft 365 mailbox.
  • Potentially export-controlled engineering data was accessible.
  • IEH found no confirmed data theft or operational disruption.

Americas World

Read the full article at the source →