According to The Register, US defense and aerospace supplier IEH Corporation has reported a security incident where a cybercriminal gained access to its Microsoft 365 mailbox through a phishing attack.The breach occurred when an employee fell victim to a phishing scam, impersonating a business contact and presenting a fake Microsoft sharing link. The subsequent fake login page captured the employee's Microsoft 365 credentials, granting the attacker access to mailbox contents. This included emails, attachments, customer communications, purchase orders, engineering documents, and potentially export-controlled technical information. IEH discovered the intrusion on August 4, but the exact duration of the compromise and the initial access date remain undisclosed.While the company stated there is no evidence of data exfiltration, the compromised mailbox could have been used for various malicious activities, including monitoring communications or preparing for further attacks. IEH has secured the account, disabled malicious rules, and is implementing corrective actions and reviewing security controls. The incident has not disrupted operations or is expected to have a material impact.Source: The Register
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
