Military Device Maker IEH Corporation Hit by Phishing Attack, Files SEC Notice
Military device manufacturer IEH Corporation disclosed a cyber incident to the U.S. Securities and Exchange Commission (SEC) on Thursday after attackers compromised an employee's email inbox through a targeted phishing attack. The company discovered the breach on Tuesday and immediately launched containment efforts, according to an 8-K regulatory filing. IEH reported that an employee fell victim to a phishing scheme that granted intruders persistent access to their corporate mailbox.
The compromised account contained a trove of sensitive material, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information. IEH stated there is no evidence that emails or other data were exfiltrated from the account, but acknowledged that 'sensitive information was accessible to the unauthorized party during the compromise period.' Corrective actions are underway to secure the mailbox and preserve forensic evidence as the investigation continues.
IEH Corporation manufactures specialized connectors used in military satellites, fighter jets, airborne radars, ground radars, radios, and torpedoes. Some of its products are deployed in precision-guided missile programs including THAAD and Patriot, as well as in fighter jets operated by European countries and the government of India. The company reported nearly $30 million in revenue for fiscal year 2026 and has not yet responded to media requests for comment.
As of Friday, the company said there was no evidence the incident would materially impact business operations. The incident underscores the persistent threat of phishing to organizations handling sensitive defense and export-controlled data. Security teams and individuals can verify whether their credentials have appeared in known breaches using an email breach checker, audit their digital exposure with a privacy checkup, and confirm password strength through a password checker.