mimile
Back to feed
This event is part of a larger story
Франция, Казахстан, Польша: кибератаки раскрыли данные сотен тысяч
Read briefing

US defense supplier IEH says hackers accessed emails via fake Microsoft login page

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

US defense supplier IEH says hackers accessed emails via fake Microsoft login page

IEH Corporation, a maker of components for military satellites and missiles, discloses that hackers broke into its email systems using a fake Microsoft login page. The company says no data was exfiltrated but removed malicious mailbox rules designed to forward emails to an attacker-controlled inbox. The breach exposed customer communications and technical documents in an intrusion reported to the U.S. Securities and Exchange Commission.

The Phishing Campaign

Unidentified threat actors contacted an IEH employee posing as a prospective business contact, according to the company’s 8-K report. The attackers sent a link to a bogus Microsoft login page, enabling them to steal the employee’s credentials. IEH confirmed that the hackers subsequently gained access to mailbox contents, including emails, attachments, and engineering documentation.

Malicious Rules Removed

IEH’s security team discovered and removed malicious mailbox rules likely aimed at exfiltrating data to an attacker-controlled inbox. Despite the unauthorized access, the company stated it found no evidence of actual data theft. An internal audit was completed, and IEH implemented corrective actions to contain the impact. The compromised material included customer communications and purchase orders.

Defense Contractor Exposure

IEH produces specialized components for military satellites, missiles, and fighter jets, with applications in the Patriot and THAAD missile systems, among others. The company generates about $30 million in annual revenue and serves prime defense contractors. The accessed information could interest nation-states such as Russia, China, North Korea, or Iran, though no attribution has been made.

What's Next

IEH has not publicly identified its clients or the extent of potential downstream risks. It remains unclear whether the attackers will attempt to leverage the stolen communications for espionage or further intrusions.

2 sources

US defense supplier IEH says hackers accessed emails via fake Microsoft login page