IEH Corporation, a U.S. defense and aerospace manufacturer, was targeted in a phishing attack that compromised its Microsoft 365 mailbox. The breach, discovered on August 4, 2026, occurred when an employee clicked a disguised link and entered their credentials on a fraudulent page, granting the attacker access to emails and possibly export-controlled military data. The attacker set up malicious mailbox rules to maintain access, but no data exfiltration was confirmed.
IEH, which reported nearly $30 million in revenue for 2026, is currently investigating the incident and claims it will not materially affect their operations.