IEH Discloses Phishing Incident Affecting Microsoft 365 Mailbox, Potentially Exposing Export-Controlled Military Data

Views: 49 views

434/69 Tuesday, August 11, 2026

IEH Corporation, a U.S. defense and aerospace manufacturer based in Brooklyn, New York, disclosed a cybersecurity incident in an 8-K filing submitted to the U.S. Securities and Exchange Commission (SEC) after discovering that a threat actor had gained unauthorized access to an employee’s Microsoft 365 mailbox. IEH manufactures high-reliability electrical connectors, particularly hyperboloid connectors used in military and aerospace applications, including rotary-wing aircraft, THAAD and Patriot missile systems, fighter aircraft, airborne radar systems, satellites, spacecraft, military radios, and torpedoes.

The company said it discovered the incident on August 4, 2026. Its investigation determined that the intrusion originated from a phishing attack in which the threat actor impersonated what appeared to be a prospective business contact and sent the employee a link disguised as a Microsoft document-sharing link. After the employee opened the link and entered Microsoft 365 credentials into a fraudulent login page, the attacker gained unauthorized access to the account. Following detection of the incident, IEH took containment measures, secured the affected account, and removed malicious mailbox rules associated with the compromised account.

Based on the information disclosed, the attacker gained access to the company mailbox, potentially exposing emails, attachments, customer information, engineering documents, and technical data that may be subject to export-control requirements. However, the company has not confirmed whether any information was actually exfiltrated. Export-controlled technical information is particularly sensitive because IEH’s products are subject to regulations including the International Traffic in Arms Regulations (ITAR) and the Export Administration Regulations (EAR). If such information were transferred to unauthorized foreign persons, the incident could potentially raise issues under U.S. federal export-control laws. IEH stated that it currently has no evidence indicating that the incident will have a material impact on its business operations, while the investigation remains ongoing.

Source https://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-exposing-potentially-export-controlled-data.html