U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

IEH was breached by a phishing attack that exposed its Microsoft 365 inbox, including emails and potentially export-controlled military data.
IEH Corporation is a U.S. defense and aerospace manufacturer based in Brooklyn, New York. The company specializes in high-reliability electrical connectors, particularly hyperboloid connectors used in demanding military and aerospace environments. Its connectors are used in systems including rotary-wing aircraft, THAAD and Patriot missile systems, fighter aircraft, airborne radar systems, satellites and spacecraft, military radios, and torpedoes.
IEH Corporation disclosed a cyberattack in an 8-K filing with the SEC. The company discovered the breach on August 4. An employee clicked a link disguised as a Microsoft document-sharing link from what appeared to be a prospective business contact, entered their Microsoft 365 credentials into a fake login page, and handed an attacker full access to their inbox.
“On August 4, 2026, IEH Corporation (“IEH” or the “Company”) discovered that it sustained a cybersecurity incident whereby a threat actor using an alias gained unauthorized access to the Microsoft 365 mailbox of an employee of the Company. As soon as the incident was observed, the Company took action to contain the unauthorized access.” reads the 8-K report filed with SEC. “An investigation determined the compromise originated from a phishing attack in which a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link. The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access.”
The attacker accessed company’s mailbox, exposing emails, attachments, customer data, engineering documents and potentially export-controlled information. No data exfiltration was confirmed. The U.S. Defense Manufacturer secured the account and removed malicious mailbox rules.
The phrase “export-controlled technical information” is the part worth paying attention to. IEH’s products fall under ITAR and EAR regulations, exporting that kind of data to an unauthorized foreign party isn’t just a breach, it’s a potential federal violation.
The attack didn’t require any technical sophistication. Someone posing as a business contact sent a convincing link, and one click was enough. The fact that malicious mailbox rules had been created, and had to be disabled, suggests the attacker was in the account long enough to set up persistence, likely to maintain access or intercept future emails silently.
IEH reported nearly $30 million in revenue for fiscal year 2026, a small company by most standards, but one sitting inside defense supply chains that attackers have strong reasons to target. The company says it currently has no evidence the incident will materially affect business operations and is continuing its investigation.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Pierluigi Paganini
(SecurityAffairs – hacking, Defense Manufacturer)

