IEH Corp says phished staffer opened gates to company M365

https://image.theregister.com/5284669.jpg?imageId=5284669&x=0&y=0&cropw=100&croph=71.67&panox=0&panoy=0&panow=100&panoh=71.67&width=1200&height=683

Attacker phished way into US defense supplier's Microsoft 365 account

Intruder gained access to engineering files and potentially export-controlled technical data

US defense and aerospace supplier IEH Corporation 'fessed up that a criminal managed to break into its Microsoft 365 mailbox in a filing with regulators.

In a Form 8-K filed with the Securities and Exchange Commission on Thursday, IEH said one of its staffers fell for a phishing scam that gave an attacker access to its M365 environment.

The attacker "impersonated a prospective business contact" and sent the employee what appeared to be a genuine Microsoft sharing link. The accompanying fake login page duly harvested the victim's M365 credentials.

"The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information," IEH said in the SEC filing [PDF].

IEH said it had found "no evidence" that the...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more