ELSEIF
Your brief EB
281 stories from 83 feeds 124 clusters Refreshed 14 minutes ago next pull 20:21

TECH Signal 332

Attacker phished way into US defense supplier's Microsoft 365 account

Defense and aerospace parts supplier IEH Corporation disclosed in an SEC filing that a phishing attack compromised a Microsoft 365 mailbox, exposing engineering and potentially export-controlled data.

WHY IT MATTERS

For security teams operating in defense supply chains, this is a textbook credential-phishing breach against a small, high-value target with documented use in US weapons programs. The disclosure is also a compliance signal: a Form 8-K was triggered, meaning the company judged the incident material to investors, and peers should expect similar scrutiny when a single mailbox holds engineering, customer, and export-controlled data together.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

The entry vector was a fake Microsoft sharing link paired with a credential-harvesting login page sent from an impersonated business contact, not a technical exploit of Microsoft 365 itself.

02

The compromised mailbox exposed email, attachments, customer communications, purchase orders, engineering documentation, and what IEH described as potentially export-controlled technical information, with no detected exfiltration so far.

03

IEH discovered the intrusion on August 4 but did not disclose the original access date or dwell time, leaving the actual exposure window unknown.

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
www.theregister.com - Articles Attacker phished way into US defense supplier's Microsoft 365 account Open ↗