US National WireUS NATIONAL WIRE
Tech

The Cloud Vulnerability: IEH Corporation's M365 Breach

Portrait of Cole Fenwick
Cole Fenwickspace & defense techAug 7AI
The Cloud Vulnerability: IEH Corporation's M365 Breach

AI-generated image · US National Wire

A phishing attack on a defense supplier highlights the precarious nature of storing export-controlled technical data on commercial cloud stacks.

Q: What happened at IEH Corporation?

A: As first reported by The Register, the Brooklyn-based defense and aerospace supplier IEH Corporation disclosed in a Form 8-K filing with the Securities and Exchange Commission that a criminal gained access to its Microsoft 365 environment. The breach occurred after a staff member fell victim to a phishing scam involving a fake login page and a fraudulent Microsoft sharing link sent by an attacker impersonating a prospective business contact.

Q: What specific data was exposed during the intrusion?

A: IEH Corporation stated in its SEC filing that the intruder gained access to mailbox contents. This included customer communications, purchase orders, email messages, attachments, and engineering-related documentation. Most critically, the company noted that potentially export-controlled technical information was accessible to the attacker.

Q: Did the attacker steal the data?

A: IEH Corporation reported that it found "no evidence" that information was exfiltrated or copied. However, The Register notes that data theft is not always visible in Microsoft 365 logs and that compromised mailboxes can be utilized for monitoring communications, redirecting payments, or launching follow-on attacks.

Q: When was the breach discovered and how did the company respond?

A: The company discovered the intrusion on August 4, according to The Register. In response, IEH Corporation secured the account, disabled malicious mailbox rules, and preserved evidence. The company also initiated a review of its authentication protections and account security controls specifically for Microsoft 365 services.

Q: Why is this breach significant given IEH Corporation's business model?

A: IEH Corporation manufactures hyperboloid connectors for high-stress environments. As reported by The Register, these components are integral to several high-profile U.S. defense programs, including the MARK-48 torpedo, the APKWS precision-guided rocket, THAAD, AMRAAM, and the PATRIOT air-defense system. Their products are also used in satellites, fighter jets, missiles, and commercial aircraft.

Q: Who is responsible for the attack?

A: There is currently not enough information to attribute the attack to a specific actor. While The Register notes that Russia and China have targeted U.S. organizations for defense information in the past year, there is no evidence suggesting either nation was behind the IEH breach. The attacker could have been a state-sponsored spy or an ordinary cybercriminal seeking fraud and data theft.

Q: What is the expected impact on the company's operations?

A: IEH Corporation stated in its regulatory filing that the incident has not disrupted its operations and the company does not expect the breach to have a material impact, though the investigation is ongoing.

Sources

More from Cole Fenwick