TECH Signal 332
Attacker phished way into US defense supplier's Microsoft 365 account
Defense and aerospace parts supplier IEH Corporation disclosed in an SEC filing that a phishing attack compromised a Microsoft 365 mailbox, exposing engineering and potentially export-controlled data.
For security teams operating in defense supply chains, this is a textbook credential-phishing breach against a small, high-value target with documented use in US weapons programs. The disclosure is also a compliance signal: a Form 8-K was triggered, meaning the company judged the incident material to investors, and peers should expect similar scrutiny when a single mailbox holds engineering, customer, and export-controlled data together.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The entry vector was a fake Microsoft sharing link paired with a credential-harvesting login page sent from an impersonated business contact, not a technical exploit of Microsoft 365 itself.
The compromised mailbox exposed email, attachments, customer communications, purchase orders, engineering documentation, and what IEH described as potentially export-controlled technical information, with no detected exfiltration so far.
IEH discovered the intrusion on August 4 but did not disclose the original access date or dwell time, leaving the actual exposure window unknown.
THE CLUSTER