Attacker phished way into US defense supplier's Microsoft 365 account
Intruder gained access to engineering files and potentially export-controlled technical data
Defense and aerospace supplier IEH Corporation disclosed that one of its employees was duped by a phishing scam, which allowed a criminal to infiltrate its Microsoft 365 mailbox. The attacker impersonated a potential business contact and provided a seemingly legitimate Microsoft sharing link. This link led to a fake login page that captured the victim's Microsoft 365 credentials.
The intruder gained access to various confidential information, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical data. Despite IEH's discovery on August 4, they have not specified the exact date of the initial account access or the duration of the intruder's presence.
The company secured the compromised account, disabled malicious mailbox rules, preserved evidence, and is actively reviewing account security controls and authentication protections for Microsoft 365 services. The incident has not affected IEH's operations, and the company does not anticipate any material impact from the breach, although the investigation is ongoing.
While the lack of detected exfiltration does not imply the attacker merely browsed the inbox, compromised mailboxes can be exploited for various malicious purposes, such as monitoring communications, impersonating employees, redirecting payments, or setting up follow-on attacks, even if data theft is not immediately observable in Microsoft 365 logs.
The nature of IEH's work for defense and aerospace customers, as well as its use by various high-profile US programs, could make it an attractive target for espionage or cybercriminal activities. However, no attribution has been made for this specific attack, with both Russia and China previously implicated in similar intrusions targeting defense-related information from US organizations in recent times.
Written by urgent.news from The Register's reporting — not their text. Machine-written; read the original for the full account.

