Military Contractor IEH Corporation Hit by Phishing Attack, Sensitive Data Exposed
A recent phishing attack has compromised the email inbox of **IEH Corporation**, a key manufacturer of specialized components for military satellites, missiles, and fighter jets. The breach potentially exposed sensitive information, including export-controlled technical data, raising concerns about supply chain security for critical defense systems.
Hackers successfully gained unauthorized access to an employee's email inbox at **IEH Corporation**, a crucial supplier to the defense industry. The incident, discovered on Tuesday, prompted the company to immediately initiate containment protocols.
According to an **8-K filing** with the **U.S. Securities and Exchange Commission (SEC)**, the breach was a result of an employee falling victim to a phishing attack. This granted intruders access to a wealth of information, including "email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information."
### Potential Exposure of Sensitive Data
While **IEH Corporation** states there is no evidence yet that data was exfiltrated from the compromised account, the company confirmed that "sensitive information was accessible to the unauthorized party during the compromise period." This accessibility alone poses significant risks, given the nature of the company's products.
**IEH Corporation** manufactures a specialized brand of connectors vital to numerous military applications, including satellites, fighter jets, airborne radars, rotary-winged aircrafts, ground radars, radios, and torpedoes. Their components are also integrated into precision-guided missile programs such as **THAAD** and **Patriot Missiles**, and are used in fighter jets operated by European nations and the government of India.
### Ongoing Investigation and Remediation
The company is currently undertaking corrective actions to secure the compromised mailbox and preserve all relevant evidence for an ongoing investigation. As of Friday, **IEH Corporation** reported no evidence that the incident would impact its business operations, which reported nearly $30 million in revenue for the 2026 fiscal year.
This incident underscores the persistent threat of phishing attacks, even against organizations handling highly sensitive defense-related data, and highlights the continuous need for robust cybersecurity measures and employee training.