Back Streetinsider IEH Corporation reports Microsoft 365 email breach via phishing attack
IEH Corporation (OTC: IEHC ) disclosed that it discovered a cybersecurity incident on August 4, 2026, in which an unauthorized actor gained access to a Microsoft 365 employee mailbox through a phishing attack.
According to the company, the attack originated when a malicious actor impersonated a prospective business and delivered a hyperlink disguised as a Microsoft document-sharing link. The employee entered login credentials into a fraudulent page, resulting in unauthorized account access.
The compromised mailbox contained email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information. The company stated it has no current evidence that unauthorized emails were sent from the account or that data was successfully exfiltrated, though the information was accessible to the unauthorized party during the compromise period.
IEH Corporation said it secured the account, disabled malicious mailbox rules, preserved evidence, and initiated corrective actions. The company also conducted a review of account security controls and authentication protections for its Microsoft 365 services.
The company said it is continuing to review impacted communications and will provide required notifications to affected parties and applicable regulatory agencies if necessary.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
