-
A hacker tricked an IEH Corporation worker into giving up their Microsoft 365 login.
-
IEH builds parts used in fighter jets, satellites, and missile defense systems.
-
The company says it found no proof that stolen files left the account.

A US company that builds parts for jets and missiles has reported a break-in. Hackers tricked one of its workers into handing over an email password. The company, IEH Corporation, makes connectors and other small parts. These parts go into aerospace and defense equipment, including missile defense systems.
IEH found the break-in on August 4, 2026. The company then told the US Securities and Exchange Commission about it. IEH’s report to the SEC explains how the attack happened and what the hacker may have seen.
How the Attack Happened
A hacker pretended to be a possible business partner. The hacker sent a worker a link that looked like a real Microsoft file-sharing link. The worker clicked it and landed on a fake login page. They then typed in their Microsoft 365 username and password.
That single click gave the hacker access to the worker’s email inbox. The hacker did not break through any firewall or crack any code. Instead, they used a trick called phishing. This method fools people into giving up their own passwords.
IEH’s report shows the attack did not need advanced hacking skills. It only needed a convincing fake link and one person who trusted it. This kind of trick works on all kinds of companies, not just defense ones.
What Information Was At Risk
The hacked inbox held many kinds of company files. It contained emails, file attachments, and messages with customers. It also held purchase orders and technical files about engineering work. Some of these technical files may fall under export control rules. Export-controlled data means the government limits who can see or share it.
IEH’s connectors are used in serious military systems. According to coverage from The Register, the exposed files may include engineering data tied to export rules. The Record points out that IEH supplies parts for military satellites, missiles, and fighter jets, which raises the stakes of this incident.
IEH’s parts show up in satellites, radar systems, and fighter planes. They also appear in the Patriot missile system and the Terminal High Altitude Area Defense system, known as THAAD. Because of this, even a small leak could matter to national security.
The risks of defense data exposure are not limited to U.S. suppliers, a threat actor has claimed to be selling sensitive data from India’s Astra air-to-air missile program on an underground forum, with the advertised dataset allegedly containing defense-related information involving military quantities and allocations.
Still, IEH says it has not found proof that anyone stole the data. The company checked for signs that the hacker sent emails from the account. It found none. It also checked whether files got downloaded or sent outside the company. Again, it found no evidence of that. So access to the inbox is confirmed, but actual data theft is not.
Several security news sites picked up the story after IEH’s filing. SecurityWeek, SC Media, and Security Affairs all reported on the breach. Each outlet noted how sensitive the exposed material could be, given IEH’s role in the defense supply chain.
What IEH is Doing Now
Once IEH spotted the break-in, it locked down the affected account right away. Workers removed harmful mailbox rules the hacker may have set up. Such rules can secretly forward or hide emails without the owner noticing. The team also saved evidence for its investigation.
IEH started a full review of its Microsoft 365 security settings. It wants to check how logins get protected across the company. The company plans to keep reviewing the exposed messages closely. If needed, it will alert other affected parties or regulators.
For now, IEH does not expect this event to seriously hurt its business. But the investigation is still open, so that could change. The company has not confirmed the full scope of what the hacker saw or could have taken.
This incident shows how one convincing email can open the door to serious risk. The hacker did not need a hidden software flaw. They only needed a worker to believe a fake link was real. For a company tied to national defense work, that single click carries extra weight. The full impact of this breach may take time to become clear.