Here is a story that should permanently retire one of the most dangerous ideas in small business security: the belief that “we’re too small to be a target” or “we don’t have anything worth stealing.” A company whose components sit inside Patriot and THAAD missile-defense systems, fighter jets, satellites, and torpedoes was just breached. Not by a foreign intelligence service defeating military-grade defenses. Not by some Hollywood hacking sequence. It happened because one employee clicked one link.
The company, IEH Corporation, disclosed the incident in a required filing with the Securities and Exchange Commission — which is how we know the details with unusual precision. And those details are worth walking through carefully, because the exact technique used against a defense contractor is the identical technique being used against accounting firms, medical practices, law offices, and contractors every single day. If it can take down a company that builds missile connectors, the “we’re too small to matter” defense is not a defense at all. Let’s break down what happened and, more importantly, what it means for you.
What actually happened
According to the company’s own filing, the attack unfolded in a sequence that is almost mundane in its simplicity — and that’s exactly what makes it instructive:
- The bait. An attacker, posing as a prospective business contact, emailed an employee a hyperlink dressed up as a normal Microsoft document-sharing link — the kind of “someone shared a file with you” message everyone receives constantly.
- The hook. The employee clicked it and landed on a fake login page — a counterfeit built to look exactly like the real Microsoft sign-in screen. Believing it was genuine, they typed in their Microsoft 365 username and password.
- The breach. Those credentials went straight to the attacker, who used them to log into the employee’s real mailbox and read its contents.
- The entrenchment. This is the detail that tells you it wasn’t a casual snoop. The attacker created malicious mailbox rules — automated instructions inside the email account — that later had to be found and disabled. Those rules are a hallmark of an intruder setting up to stay: quietly forwarding or hiding messages to maintain access and monitor communications after the fact.
That’s the whole attack. No malware in the traditional sense. No exploited software flaw. No sophisticated tooling. A convincing email, a fake login page, one click, one password — and an intruder was inside the email system of a company that supplies the U.S. and allied militaries.
The single most important takeaway: the technique that beat a defense contractor is not exotic. It is the most common attack on Earth, and it works the same way against every business regardless of size. It doesn’t target your firewall or your software — it targets a busy person having a normal workday, and asks them to do something that feels completely routine. That is precisely why “we’re too small” offers no protection. The attack was never aimed at how big you are. It was aimed at your people.
Why a single mailbox is a genuine disaster
It’s tempting to think “it was just one email account.” But stop and consider what actually lives in a single business mailbox — yours, right now. According to the filing, the attacker had access to emails, attachments, customer communications, purchase orders, engineering documentation, and potentially export-controlled technical information. In other words: a substantial cross-section of how the business actually operates.
Your email account is not just a place where messages arrive. For most people it’s the skeleton key to their entire professional life. Think about what someone reading your inbox would gain:
| What’s in almost any business inbox | What an intruder can do with it |
|---|---|
| Every past conversation with clients and vendors | Learn exactly how you talk, who you deal with, and what deals are in motion |
| Invoices, purchase orders, banking and payment details | Redirect a real payment by inserting fake bank details into a genuine-looking thread |
| The “reset my password” link for your other accounts | Take over your other services, since most password resets go to email |
| Contracts, documents, and sensitive attachments | Steal confidential business information or client data |
| Your identity and relationships | Impersonate you convincingly to your own staff, clients, and suppliers |
That fourth-column reality is why a compromised inbox is so dangerous. An attacker sitting in your email can send a message, as you, from your real account, to your bookkeeper, saying “please update the wire details for this vendor” — and it will pass every test, because it genuinely came from you. This is the mechanism behind business email compromise, one of the costliest forms of fraud there is, and it starts with exactly the kind of single-mailbox access this attacker obtained.
The detail security professionals noticed: the mailbox rules
We want to draw your attention to the malicious mailbox rules, because to a security professional, that single detail changes the whole complexion of the incident. A smash-and-grab thief reads what they can and leaves. Setting up mailbox rules is different — it’s the digital equivalent of a burglar making a copy of your key and unscrewing a window latch on the way out, so they can come and go later without being noticed.
These rules typically do things like automatically forward incoming messages to the attacker, or silently move certain emails (say, any containing the words “invoice” or “security alert”) into a folder you never check — so that even if you’re warned, you never see the warning. It’s a play for persistence: the goal isn’t one look at the inbox, it’s a lasting, quiet foothold to monitor communications and set up the next move. It signals an attacker who knows exactly what they’re doing.
The high-stakes wrinkle: some data can’t just be “reset”
There’s a dimension here that goes beyond an ordinary breach, and it’s worth understanding even if your business never touches military work. The filing flags potential exposure of export-controlled technical information — data governed by strict federal regulations (known as ITAR and EAR) that control the sharing of defense- and technology-related material with foreign parties.
Here’s why that matters as a concept: some kinds of exposed data create obligations and consequences that a password change can’t undo. For a defense supplier, technical data reaching an unauthorized foreign party isn’t just embarrassing — it can be a federal regulatory matter. And the parallel holds for ordinary businesses: if the exposed mailbox contains patient health information, clients’ financial records, or personal data, you may inherit legal and notification duties that far outlast the incident itself. The lesson is that the true cost of a breach is rarely just the cleanup — it’s the exposure of information you had a duty to protect, and the obligations that come with it.
To their credit: IEH appears to have responded properly — they detected the intrusion, moved quickly to contain it, secured the account, removed the malicious rules, preserved evidence, and disclosed the incident transparently in a regulatory filing. That’s roughly what a good response looks like. It’s also worth noting what they reported: no evidence that data was actually copied or emailed out. But read that carefully — the sensitive information was accessible during the compromise, and, as the company was careful to say, an absence of evidence of theft is not the same as proof nothing was taken. Data theft doesn’t always leave a visible trace.
What this means for your business — and what to actually do
Strip away the missiles and the federal regulations, and this is a story about an email account, a fake login page, and one understandable human mistake. That’s a story that can happen to any business, any day. Here’s how you make sure it isn’t yours.
- Turn on multi-factor authentication — but understand its limits. MFA (that second code from your phone) is essential and would stop many attacks, so if it’s not on across your email and key systems, that’s job one. But be clear-eyed: sophisticated fake login pages can now capture that second code too, in real time, by relaying it to the real site as you type. MFA is a critical layer, not a force field. Which is exactly why the next point matters so much.
- The click is the whole game — so train the click. Every layer of this attack came after one person trusted one link. The single highest-value investment you can make is teaching your team to recognize the setup: an unexpected “shared document,” a login page that appears after clicking an email link, a new “business contact” creating a reason to click. The instinct to build is simple — never enter your password on a page you reached by clicking a link in an email. Go to the site directly instead. That one habit would have stopped this breach cold.
- Know how to check for mailbox rules. Most business owners have no idea this setting exists, which is exactly why attackers abuse it. Someone should know how to review the forwarding and inbox rules on your email accounts — both to spot an intruder’s handiwork and as a routine check. A rule you didn’t create is a screaming red flag.
- Assume the inbox is a vault, and protect it like one. Once you internalize that your email account is the skeleton key to your business, it reframes everything. It deserves your strongest password, your best MFA, and the most skepticism when anything asks for its credentials.
The reason this story is worth your time isn’t the missiles — it’s the proof. It is hard proof that sophistication, budget, and importance do not protect you from the most basic attack there is, because that attack doesn’t go through your technology. It goes through your people, on an ordinary Tuesday, with a message that looks completely normal. A company building components for missile-defense systems learned that the hard way. The good news is that the defense is teachable, affordable, and human. Our focused security training is built to create exactly the reflex that would have stopped this: the half-second of healthy suspicion when a login page appears after a click. If a defense contractor’s mailbox can be opened with one link, the question isn’t whether your team will be tested the same way. It’s whether they’ll be ready when they are.
Sources: IEH Corporation Form 8-K filed with the U.S. Securities and Exchange Commission (August 6, 2026); The Register; The Record (Recorded Future News); SecurityWeek; Security Affairs, August 2026. The company reported no evidence of data exfiltration but confirmed sensitive information was accessible during the compromise. No attribution has been made public; this article takes no view on who was responsible.













