Aug 7, 2026
Policy

IEH Microsoft 365 phishing exposed defense supplier mailbox

IEH said a fake Microsoft sharing link gave an intruder mailbox access, including potentially export-controlled technical information.

Renata Fuchs

By Renata Fuchs · Policy Reporter

· 3 min read

IEH Microsoft 365 phishing exposed defense supplier mailbox
Photo: The Register

IEH Corporation disclosed an IEH Microsoft 365 phishing incident in which an attacker accessed an employee mailbox after the employee entered credentials into a fraudulent login page. The Brooklyn connector maker said the mailbox held customer communications, purchase orders and engineering material, making the event relevant to defense and aerospace supply chains even though IEH has not found evidence of data leaving its systems.

IEH said it discovered the unauthorized access on August 4 and reported it in a Form 8-K. According to the company, the attacker posed as a prospective business contact and sent a link presented as a Microsoft document-sharing request. The link led to a counterfeit sign-in page that collected the employee's Microsoft 365 credentials.

The company said the intruder could access email messages and attachments, customer communications, purchase orders, engineering-related documents and potentially export-controlled technical information. That is a description of what was available in the mailbox during the compromise, not a finding that those materials were copied.

What did the attacker access in IEH's Microsoft 365 account?

IEH said the attacker had access to the contents of the compromised mailbox. It said it had no evidence that information was downloaded or sent outside the company, and no evidence that unauthorized messages were sent from the account. IEH did not disclose when the account was first accessed or how long the attacker remained in it. Its investigation and review of potentially affected communications are continuing.

The distinction matters operationally. A mailbox compromise can expose active commercial exchanges and technical correspondence even where an investigation has not established external transfer. IEH said it would notify affected parties and regulators if required.

The company said it secured the account, turned off malicious mailbox rules and preserved evidence. It is also reviewing Microsoft 365 account-security controls and authentication protections. Those actions fit the broader view that enterprise security is a program, not a product, involving identity controls as well as incident response and monitoring.

IEH said the incident had not interrupted operations and was not expected to have a material adverse effect, while cautioning that its work remained underway. The company makes hyperboloid connectors and, in a June filing, said its backlog had been driven primarily by orders supporting missile-defense programs and that it serves prime defense contractors.

The disclosure does not identify the attacker or assign a motive. It also describes a credential-harvesting fake-login-page attack, not the separate Kali365 technique that the FBI warned about in May. In that advisory, the FBI described phishing that persuades targets to enter a device code on a legitimate Microsoft page, granting an attacker OAuth tokens without collecting the user's credentials. The FBI's device-code-flow controls address that separate method, rather than explaining the IEH intrusion.

This story draws on original reporting from The Register.

More from Policy

All Policy →