Attacker phished way into US defense supplier's Microsoft 365 account
- ID
- 11893
- Status
- summarized
- Published
- 07 Aug 2026, 7:32 PM
- Fetched
- 07 Aug 2026, 7:47 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/08/07/ieh-corp-says-phished-staffer-opened-gates-to-company-m365/5284523
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 2.0
- Created
- 07 Aug 2026, 7:48 PM
- Tags
- Audience
- developers
What happened
US defense supplier IEH Corporation disclosed in an SEC Form 8-K filing that an attacker phished an employee via a fake Microsoft sharing link impersonating a business contact, harvesting M365 credentials and gaining access to mailbox contents including engineering documentation and potentially export-controlled technical data. IEH discovered the intrusion on August 4, found no evidence of exfiltration, and has since secured the account and disabled malicious mailbox rules.
Why it matters
This is a standard M365 phishing incident with no AI, agent, developer tooling, or Malaysian/SEA relevance. The only concrete takeaway is that fake Microsoft sharing links remain an effective initial access vector and that compromised mailboxes can be used for payment redirection and follow-on attacks even without visible exfiltration in M365 logs—but this is not actionable for this audience beyond basic MFA hygiene they should already practice.
Discussion angle
Skip this one for the weekly segment unless pivoting to a broader discussion of M365 tenant hardening—conditional access policies, mailbox rule auditing, and external sharing link controls—that builders managing their own SaaS stacks should verify.