08/06/2026 | Press release | Distributed by Public on 08/06/2026 11:14
| Item 8.01 | Other Events |
On August 4, 2026, IEH Corporation ("IEH" or the "Company") discovered that it sustained a cybersecurity incident whereby a threat actor using an alias gained unauthorized access to the Microsoft 365 mailbox of an employee of the Company. As soon as the incident was observed, the Company took action to contain the unauthorized access.
An investigation determined the compromise originated from a phishing attack in which a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link. The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access.
The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information. No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period.
The account was secured, malicious mailbox rules were disabled, evidence was preserved, and corrective actions are underway.
Following containment and investigation activities, the Company initiated a review of account security controls and authentication protections applicable to Microsoft 365 services. The Company has already taken and completed a series of corrective actions to contain any impact of the unauthorized access.
However, at this time, the Company has no evidence that information was transmitted externally, downloaded or infiltrated. The Company only knows that the information was accessible to the unauthorized actor during the compromise period.
The Company is continuing to review the impacted communications and will provide, if necessary, any required notifications to affected parties and applicable regulatory agencies.
As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations. The Company is continuing to investigate the incident.