Phishing Entices an Unwary Employee
US defense and aerospace provider IEH Corporation acknowledged that a criminal infiltrated its Microsoft 365 mailbox. In a Form 8-K submitted to the Securities and Exchange Commission, IEH announced that one of its less perceptive employees succumbed to a phishing scheme that granted an attacker entry to its M365 environment. The assailant masqueraded as a potential business associate and sent the employee what appeared to be a legitimate Microsoft sharing link. The suspicious login page that accompanied it collected the victim’s M365 credentials like a farmer after a bountiful harvest.
The Extent of the Damage
“The perpetrator accessed mailbox contents, encompassing email messages, attachments, customer interactions, purchase orders, technical documentation, and possibly export-controlled technical data,” IEH disclosed in the SEC filing . They stated they’d found “no indication” that the information was duplicated or stolen, although it was readily available during the “compromise timeframe.”
Securing the Barn After the Horse Has Escaped
IEH uncovered the wrongdoing on August 4 but did not reveal when the breached account was initially accessed or how long the intruder was able to browse. “The account was secured, suspicious mailbox rules were disabled, evidence was preserved, and corrective measures are in progress,” they remarked. After addressing the situation, the company began a review of security controls and authentication measures for Microsoft 365 services.
Still Not Out of the Danger Zone
The incident hasn’t interrupted operations, and IEH doesn’t foresee it having a major effect, though they’re continuing their investigation. Just because they didn’t detect any data being stolen doesn’t imply the snooper simply had a quick glance and left. Breached mailboxes can be exploited for various malicious activities such as monitoring communications, impersonating staff, redirecting funds, or initiating additional attacks, while data theft can slip below the radar in Microsoft 365 logs.
No Blame Assigned
There isn’t enough information to determine who carried out the attack. IEH’s engagement with defense and aerospace clients might be an attractive target for espionage, but everyday cybercriminals also find enjoyment in compromising mailboxes for financial fraud and information theft. Russia and China have previously been discovered snooping around US defense-related information in the last year, but there’s no evidence suggesting either was responsible for the attack on IEH.
What is IEH?
Brooklyn-based IEH manufactures hyperboloid connectors intended for demanding and high-stress settings. Their products are utilized in printed circuit boards, medical equipment, commercial aircraft, fighter planes, missiles, satellites, and other systems. Some major US programs that prefer IEH’s hyperboloid connectors include the PATRIOT air-defense system, AMRAAM, THAAD, the APKWS precision-guided rocket, and the MARK-48 torpedo.
Unaware Employee Falls for Phishing: A Summary
There you have it, everyone. A story as old as time: an individual clicks on a questionable link, and before you know it, a whirlwind of chaos can arise. Perhaps it’s time to become more informed before you start distributing credentials like free samples at a grocery store. Until next time, stay safe and always remain vigilant. Cheers!