US defense supplier IEH says hackers accessed emails via fake Microsoft login page
This digest was compiled by AI from multiple sources — links to the originals are below.

IEH Corporation, a maker of components for military satellites and missiles, discloses that hackers broke into its email systems using a fake Microsoft login page. The company says no data was exfiltrated but removed malicious mailbox rules designed to forward emails to an attacker-controlled inbox. The breach exposed customer communications and technical documents in an intrusion reported to the U.S. Securities and Exchange Commission.
The Phishing Campaign
Unidentified threat actors contacted an IEH employee posing as a prospective business contact, according to the company’s 8-K report. The attackers sent a link to a bogus Microsoft login page, enabling them to steal the employee’s credentials. IEH confirmed that the hackers subsequently gained access to mailbox contents, including emails, attachments, and engineering documentation.
Malicious Rules Removed
IEH’s security team discovered and removed malicious mailbox rules likely aimed at exfiltrating data to an attacker-controlled inbox. Despite the unauthorized access, the company stated it found no evidence of actual data theft. An internal audit was completed, and IEH implemented corrective actions to contain the impact. The compromised material included customer communications and purchase orders.
Defense Contractor Exposure
IEH produces specialized components for military satellites, missiles, and fighter jets, with applications in the Patriot and THAAD missile systems, among others. The company generates about $30 million in annual revenue and serves prime defense contractors. The accessed information could interest nation-states such as Russia, China, North Korea, or Iran, though no attribution has been made.
What's Next
IEH has not publicly identified its clients or the extent of potential downstream risks. It remains unclear whether the attackers will attempt to leverage the stolen communications for espionage or further intrusions.
2 sources
US defense supplier IEH says hackers accessed emails via fake Microsoft login page



