IEH Corporation: U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

IEH Corporation: U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data

U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Sensitive Military Data

On August 4, 2026, IEH Corporation a Brooklyn-based defense and aerospace manufacturer specializing in high-reliability electrical connectors for military and aerospace systems discovered a cybersecurity breach. The attack, disclosed in an SEC 8-K filing, originated from a phishing email sent by a threat actor posing as a prospective business contact. An employee clicked a malicious link disguised as a Microsoft document-sharing request, entered their Microsoft 365 credentials into a fake login page, and inadvertently granted the attacker full access to their inbox.

The breach exposed emails, attachments, customer data, engineering documents, and potentially export-controlled technical information governed by ITAR (International Traffic in Arms Regulations) and EAR (Export Administration Regulations). While no data exfiltration was confirmed, the attacker established persistence by creating malicious mailbox rules, suggesting prolonged access to intercept future communications. IEH secured the compromised account and removed the unauthorized rules but continues its investigation.

IEH’s connectors are critical components in systems such as THAAD and Patriot missile defense, fighter aircraft, satellites, and military radios, making the company a high-value target for cyber espionage. Despite the breach, IEH reported no material impact on operations and stated that its $30 million in 2026 revenue remains unaffected. The incident underscores the risks of phishing attacks in the defense supply chain, where even unsophisticated tactics can lead to significant exposure of sensitive data.

Source: https://securityaffairs.com/196890/cyber-crime/u-s-defense-manufacturer-ieh-hit-by-phishing-attack-exposing-potentially-export-controlled-data.html

IEH Corporation cybersecurity rating report: https://www.rankiteo.com/company/ieh-corporation

"id": "IEH1786299914",
"linkid": "ieh-corporation",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Defense, Aerospace',
                        'location': 'Brooklyn, New York, USA',
                        'name': 'IEH Corporation',
                        'type': 'Defense and Aerospace Manufacturer'}],
 'attack_vector': 'Phishing Email',
 'data_breach': {'data_exfiltration': 'Not confirmed',
                 'sensitivity_of_data': 'High (military and aerospace systems, '
                                        'export-controlled)',
                 'type_of_data_compromised': ['Emails',
                                              'Attachments',
                                              'Customer Data',
                                              'Engineering Documents',
                                              'Export-Controlled Technical '
                                              'Information (ITAR/EAR)']},
 'date_detected': '2026-08-04',
 'description': 'On August 4, 2026, IEH Corporation, a Brooklyn-based defense '
                'and aerospace manufacturer specializing in high-reliability '
                'electrical connectors for military and aerospace systems, '
                'discovered a cybersecurity breach. The attack originated from '
                'a phishing email sent by a threat actor posing as a '
                'prospective business contact. An employee clicked a malicious '
                'link disguised as a Microsoft document-sharing request, '
                'entered their Microsoft 365 credentials into a fake login '
                'page, and inadvertently granted the attacker full access to '
                'their inbox. The breach exposed emails, attachments, customer '
                'data, engineering documents, and potentially '
                'export-controlled technical information governed by ITAR and '
                'EAR. The attacker established persistence by creating '
                'malicious mailbox rules, suggesting prolonged access to '
                'intercept future communications. IEH secured the compromised '
                'account and removed the unauthorized rules but continues its '
                'investigation.',
 'impact': {'data_compromised': 'Emails, attachments, customer data, '
                                'engineering documents, export-controlled '
                                'technical information (ITAR/EAR)',
            'operational_impact': 'No material impact on operations',
            'revenue_loss': 'None (2026 revenue of $30 million unaffected)',
            'systems_affected': 'Microsoft 365 inbox'},
 'initial_access_broker': {'backdoors_established': 'Malicious mailbox rules '
                                                    'for persistence',
                           'entry_point': 'Phishing email (fake Microsoft '
                                          'document-sharing request)',
                           'high_value_targets': 'Defense and aerospace '
                                                 'systems (THAAD, Patriot '
                                                 'missile defense, fighter '
                                                 'aircraft, satellites, '
                                                 'military radios)'},
 'investigation_status': 'Ongoing',
 'motivation': 'Cyber Espionage',
 'post_incident_analysis': {'root_causes': 'Phishing attack leading to '
                                           'credential theft'},
 'references': [{'source': 'SEC 8-K Filing'}],
 'regulatory_compliance': {'regulations_violated': ['ITAR (International '
                                                    'Traffic in Arms '
                                                    'Regulations)',
                                                    'EAR (Export '
                                                    'Administration '
                                                    'Regulations)']},
 'response': {'containment_measures': 'Secured compromised account, removed '
                                      'unauthorized mailbox rules'},
 'title': 'U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing '
          'Sensitive Military Data',
 'type': 'Phishing Attack',
 'vulnerability_exploited': 'Credential Theft via Fake Microsoft 365 Login '
                            'Page'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.