Defense Supplier Tricked by Fake M365 Share Link

The Register Security · Medium sophistication
Last updated August 7, 2026

IEH Corporation disclosed that an attacker got into its Microsoft 365 email environment after an employee clicked what looked like a legitimate Microsoft file-sharing link from a supposed new business contact. The fake link led to a phony login page that captured the employee’s credentials, letting the intruder access emails, attachments, purchase orders, and engineering documentation, including potentially export-controlled technical information.

Key findings

  • IEH reported an employee was phished, giving an attacker access to its Microsoft 365 environment.
  • The attacker impersonated a prospective business contact and used a fake Microsoft sharing link leading to a fake login page to harvest credentials.
  • The intruder accessed mailbox contents including customer communications, purchase orders, and engineering-related documents, including potentially export-controlled technical information.
  • IEH discovered the intrusion on August 4; it did not disclose when access began or how long it lasted.
  • Response actions included securing the account, disabling malicious mailbox rules, preserving evidence, and reviewing M365 authentication and account controls.
  • IEH said it found no evidence of data exfiltration but acknowledged the mailbox data was accessible during the compromise window.

Who’s being targeted

  • Commonly targeted roles: Engineering, Sales/Business Development, Procurement, Program/Project Management, Executive assistants and frequent email handlers, IT/Helpdesk (mailbox security and incident response).
  • Affected industries: Defense manufacturing, Aerospace supply chain, Engineering, Government/Defense contractors.
  • Attack channels: email, website.
  • Impersonated: Prospective business contact (external partner/customer) using a Microsoft file-sharing link.

Awareness takeaways

  • Treat unexpected Microsoft file-share links as suspicious, especially from new or unverified external contacts; confirm the request through a known channel before signing in.
  • Never enter Microsoft 365 credentials on a sign-in page reached from an email link; instead, open a browser and sign in through your normal trusted Microsoft/SSO bookmark.
  • Assume a compromised mailbox can expose sensitive business data (orders, engineering docs, customer emails) even if there is no clear evidence of downloads.
  • After any suspected mailbox compromise, immediately check for and remove malicious inbox/mailbox rules and tighten authentication controls.

Red flags to watch for

  • Unexpected file-share from an unknown/new contact
  • Login page reached via a link in an email (possible fake sign-in)
  • Pressure to access shared documents quickly without verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

A defense supplier got burned because one employee clicked a “Microsoft share” link from a supposed new business contact. They clicked, hit a fake Microsoft 365 login page, typed their password… and the intruder quietly walked into their mailbox: purchase orders, customer emails, engineering docs, even export‑controlled info. Here’s the twist: the link looked just like a real Microsoft share from a new contact. The only giveaway was where it took them, a sign-in page reached straight from an email link. Your move: if any email link sends you to a Microsoft 365 login, close it and instead open your normal Microsoft or SSO bookmark and sign in from there.

Similar attacks

Defense Supplier Phish Exposes Export-Controlled Data

Defense Supplier Phish Exposes Export-Controlled Data

IEH Corporation disclosed that a phishing email tricked an employee into entering Microsoft 365 credentials on a fake login page, giving an attacker access to the employee’s mailbox. The compromised inbox contained emails and attachments including engineering documents and potentially…

August 9, 2026
Defense Supplier Hit by Fake Microsoft Share Link

Defense Supplier Hit by Fake Microsoft Share Link

A US defense and aerospace parts supplier reported that an attacker got into its Microsoft 365 environment after an employee clicked what looked like a legitimate Microsoft file-sharing link. The link led to a fake login page that captured the employee’s credentials, potentially exposing sensitive…

August 8, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing campaign. The campaign uses victim-tailored PDF attachments with QR codes that lead to Microsoft 365 credential-harvesting pages hosted on…

July 28, 2026