Defense Supplier Phish Exposes Export-Controlled Data

Security Affairs · Low sophistication
Last updated August 10, 2026

IEH Corporation disclosed that a phishing email tricked an employee into entering Microsoft 365 credentials on a fake login page, giving an attacker access to the employee’s mailbox. The compromised inbox contained emails and attachments including engineering documents and potentially export-controlled technical information, creating both security and regulatory risk.

How the Attack Worked

This incident began with a simple phishing email. A threat actor impersonated a prospective business contact and sent a link disguised as a Microsoft document-sharing invitation. The message asked the recipient to review a shared document, a routine-sounding request that many employees in sales, business development, or program management roles receive regularly.

When the employee clicked the link, they were taken to a fraudulent login page designed to look like a legitimate Microsoft 365 sign-in screen. Entering credentials there handed the attacker direct access to the mailbox. From that point, no malware was needed. The attacker simply had the keys to the account.

Why It Succeeded

The attack sophistication here was low, which is part of what makes it worth studying. There was no custom malware, no zero-day exploit, just a convincing pretext and a fake login page. The lure worked because it mimicked a normal business interaction: an external contact sharing a document ahead of a possible conversation. That framing lowers suspicion, especially for roles whose job is to respond to outside inquiries.

Once inside, the attacker created malicious mailbox rules. This detail matters: it suggests the attacker had enough time in the account to set up persistence, potentially to silently forward or hide messages while continuing to monitor the mailbox.

What Was Exposed

The compromised mailbox contained emails and attachments, including customer data and engineering documents. Some of that material was potentially export-controlled technical information. For a defense manufacturer, that raises the stakes considerably. Export-controlled data exposure is not only a security event, it can also carry regulatory implications depending on how the information was handled and who may have had access to it.

What to Watch For

  • Unexpected document-sharing invitations from new or unfamiliar external contacts
  • Login pages reached via email links that don't clearly match a trusted Microsoft domain
  • Requests framed with mild urgency to "sign in and view" a document tied to a vague business inquiry
  • Unusual mailbox behavior, such as missing messages or unfamiliar forwarding rules

Building Resistance

Employees should avoid entering Microsoft 365 credentials after clicking a link in an email. Instead, open Microsoft 365 directly through a bookmark or app and locate shared files from there. Verifying unfamiliar senders through a separate, known-good channel before engaging with a shared-document request adds another layer of protection.

Organizations should also train staff to report unusual mailbox activity immediately, since attacker-created rules can be a sign of ongoing persistence. For organizations that handle controlled technical data, treating any email compromise as a potential compliance issue, and looping in security, legal, and export compliance teams early, helps limit downstream risk beyond the initial account takeover.

Key findings

  • A threat actor impersonated a prospective business contact and sent a link disguised as a Microsoft document-sharing link.
  • The employee entered Microsoft 365 credentials into a fraudulent login page, giving the attacker inbox access.
  • Emails and attachments in the mailbox included customer data, engineering documents, and potentially export-controlled information (ITAR/EAR risk).
  • The attacker created malicious mailbox rules, indicating persistence and potential silent interception of future emails.
  • IEH stated there was no confirmed data exfiltration at the time of disclosure.

Who’s being targeted

  • Commonly targeted roles: All employees (especially those using Microsoft 365 email), Sales / Business Development, Engineering, Program/Project Management, Executive assistants and leaders who receive external inquiries, Export compliance / legal (for escalation procedures).
  • Affected industries: Defense manufacturing, Aerospace manufacturing, Defense industrial base / supply chain.
  • Attack channels: email, website.
  • Impersonated: Prospective business contact (external).

Red flags to watch for

  • Unexpected document-share from a new/unknown external contact
  • Link leads to a login page that is not a trusted Microsoft domain or looks slightly off
  • Urgency to sign in to view a “shared” document tied to a vague business request
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the attacker gain access to the mailbox?

A threat actor impersonated a prospective business contact and sent a hyperlink disguised as a Microsoft document-sharing link. The employee clicked it and entered Microsoft 365 credentials into a fraudulent login page, giving the attacker unauthorized account access.

What kind of data was exposed?

The compromised mailbox contained emails and attachments including customer data and engineering documents, some of which was potentially export-controlled technical information.

Did the attacker exfiltrate data?

According to the disclosure, there was no confirmed data exfiltration at the time the incident was reported, though malicious mailbox rules had been created in the account.

Why does export-controlled data make this incident more serious?

When technical data falls under regulations like ITAR or EAR, unauthorized exposure to an unauthorized party can raise compliance and legal concerns beyond the security impact of the breach itself.

Read the video transcript

An engineer clicked one “Shared document for review” email… and their inbox with export‑controlled designs was suddenly wide open. They clicked the link, saw a Microsoft 365 login look‑alike, and typed their password. That fake page handed an outsider full access to their mailbox, customer emails, engineering docs, even ITAR and EAR‑sensitive files. Behind the scenes, the intruder set sneaky mailbox rules to quietly grab or hide messages. And all of it started with an unexpected “Microsoft document-sharing” link from a so‑called prospective business contact. Here’s the move: if you get a “shared document” email from a new contact, do NOT log in from that link. Instead, open Microsoft 365 from your bookmark or app, and only open shared files from there.

Similar attacks

Defense Supplier Hit by Fake Microsoft Share Link

Defense Supplier Hit by Fake Microsoft Share Link

A US defense and aerospace parts supplier reported that an attacker got into its Microsoft 365 environment after an employee clicked what looked like a legitimate Microsoft file-sharing link. The link led to a fake login page that captured the employee’s credentials, potentially exposing sensitive…

August 8, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake…

July 24, 2026
Kratos Kit Used W-2 QR Phish to Hijack M365

Kratos Kit Used W-2 QR Phish to Hijack M365

Law enforcement dismantled the infrastructure behind Kratos, a widely used phishing kit that helped criminals steal Microsoft 365 credentials and, in some cases, capture session cookies to bypass MFA. The article describes a real, observed campaign using tax-themed W-2 QR-code emails that led…

July 22, 2026
Kratos PhaaS Takedown: Fake Microsoft Logins

Kratos PhaaS Takedown: Fake Microsoft Logins

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help…

July 21, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026