Attackers penetrated into IEH Corporation, a US defense and airspace firm, using a fake link that looked like a real Microsoft sharing link. The hackers got into an employee’s email, which had a lot of private information.
IEH Corporation shared news of a security incident in an 8-K form with the Securities and Exchange Commission (SEC). The company said that someone unauthorized took access to one employee’s Microsoft 365 mailbox.
IEH Corporation makes parts for satellites, fighter jets, ground radars, torpedoes, and airborne radars. Some of its products are used in guided missile systems like THAAD and Patriot.
According to the 8-K form, attackers managed to access the IEH Corporation employee’s mailbox after impersonating a “prospective business contact.” The fraudster sent a hyperlink disguised as a Microsoft document-sharing link.
“The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access,” reads the form.
According to the company, attackers may have accessed:
Email messages
Attachments
Customer communications
Purchase orders
Engineering-related documentation
Potentially export-controlled technical information
Export-controlled technical information usually includes blueprints, software, or engineering designs that the US government controls to keep the country safe. Considering the IEG Corporation profile, it is very possible that the leaked data is linked to making weapons.
“No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period,” the company said.
IEH said they got the account securie and turned off the affected mailbox. They are keeping digital evidence for the investigation. So far, there is no info that anyone downloaded or took sensitive details from the mailbox.
“As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations,” IEH said.
InfoSecBulletin Cybersecurity for mankind
