Circuit Wire — a daily news update from the Circuit.
IEH Corporation, a Brooklyn, New York, manufacturer of connectors used in the Patriot and THAAD missile systems, disclosed on August 6 that hackers gained access to an employee's email account four days earlier through a phishing attack. The company said in a filing with the Securities and Exchange Commission that the intruder impersonated a prospective business contact and sent a fake Microsoft document-sharing link that harvested the employee's Microsoft 365 credentials.
The intruder reached mailbox contents that included email messages, attachments, customer communications, purchase orders and engineering-related documentation, some of it potentially export-controlled technical information tied to defense programs. IEH discovered the intrusion on August 4 and said it has found no evidence the material was copied or sent outside the company, though the filing acknowledged the data was accessible to the unauthorized party throughout the compromise period. The company secured the account, disabled malicious mailbox rules, preserved evidence and began reviewing its authentication controls for Microsoft 365 services.
IEH's hyperboloid connectors are built into the Patriot and THAAD air-defense systems, the AMRAAM missile, the APKWS guided rocket, the MARK-48 torpedo, fighter jets and satellites, according to The Register. That makes the small Brooklyn manufacturer, which reported close to $30 million in fiscal 2026 revenue, a sensitive node in the US defense supply chain. Neither IEH nor federal investigators have publicly identified who carried out the attack.
The incident fits a broader pattern of state-linked hackers probing defense contractors through ordinary business email rather than technical exploits. Russian and Chinese intelligence services have both been caught targeting American defense-related communications over the past year, though nothing so far ties either to the IEH compromise. The FBI and CISA have repeatedly warned that phishing remains the most common way state-linked actors and criminal groups first gain a foothold inside US defense suppliers, particularly smaller firms with fewer dedicated security staff than prime contractors. IEH said the breach has not disrupted its operations and does not expect a material financial impact, and its investigation continues.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

