STOCK TITAN

IEH Corporation (OTCQX: IEHC) reports Microsoft 365 email incident

(High)
(Neutral)
Form Type
8-K

Rhea-AI Filing Summary

IEH Corporation reported a cybersecurity incident discovered on August 4, 2026, involving unauthorized access to a Microsoft 365 mailbox following a phishing attack. A threat actor obtained an employee’s credentials and could view emails, attachments, customer communications, purchase orders, engineering documents, and potentially export-controlled technical information.

IEH states there is no current evidence that information was transmitted externally, downloaded, or that emails were sent from the compromised account, though sensitive data was accessible during the compromise period. The account has been secured, malicious mailbox rules disabled, and Microsoft 365 security controls are under review. IEH is analyzing impacted communications, will notify affected parties and regulators if required, believes the incident will not have a material adverse effect on business operations, and continues its investigation.

Positive

  • None.

Negative

  • None.
Item 8.01 Other Events Other
Voluntary disclosure of events the company deems important to shareholders but not covered by other items.
Incident discovery date August 4, 2026 Date IEH identified unauthorized access to a Microsoft 365 mailbox
Report signing date August 6, 2026 Date the Chief Financial Officer signed the current report
Registrant telephone (718) 492-4440 Phone number for IEH Corporation’s principal executive offices
cybersecurity incident technical
"IEH Corporation discovered that it sustained a cybersecurity incident"
A cybersecurity incident is an event where someone's computer systems or data are attacked or broken into without permission. It matters because it can lead to stolen information, financial loss, or disruptions in services, similar to a break-in at a store that damages property or steals valuable items.
phishing attack technical
"the compromise originated from a phishing attack in which a malicious actor"
export-controlled technical information regulatory
"and potentially export-controlled technical information"
forward-looking statements regulatory
"Certain of the statements included in this Report constitute forward-looking statements"
Forward-looking statements are predictions or plans that companies share about what they expect to happen in the future, like estimating sales or profits. They matter because they help investors understand a company's outlook, but since they are based on guesses and assumptions, they can sometimes be wrong.

AI-generated analysis. How Rhea-AI works. Not financial advice.

See more from StockTitan in Google Search and AI answers. Adds StockTitan as a preferred source · opens Google
Add on Google
Learn about SEC filing dates

FAQ

What cybersecurity incident did IEH Corporation (IEHC) report?

IEH Corporation reported a cybersecurity incident in which a threat actor gained unauthorized access to an employee’s Microsoft 365 mailbox via a phishing attack. The intruder could view emails, attachments, customer communications, purchase orders, engineering documents, and potentially export-controlled technical information.

How did the IEH (IEHC) email account compromise occur?

The compromise stemmed from a phishing attack where a malicious actor impersonated a prospective business contact and sent a fraudulent Microsoft document-sharing link. The employee entered Microsoft 365 credentials on a fake login page, allowing unauthorized mailbox access.

Was any data exfiltrated in IEH Corporation’s (IEHC) incident?

IEH states it has no evidence that information was transmitted externally, downloaded, infiltrated, or that unauthorized emails were sent. However, sensitive information was accessible to the threat actor during the compromise period while the mailbox was exposed.

What information was exposed in IEH’s (IEHC) mailbox incident?

The threat actor could access mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information, during the time the Microsoft 365 account was compromised.

What steps has IEH Corporation (IEHC) taken after the incident?

IEH secured the affected account, disabled malicious mailbox rules, preserved evidence, and began reviewing Microsoft 365 security controls and authentication protections. The company is analyzing impacted communications and will notify affected parties and regulators if required.

Does IEH Corporation (IEHC) expect a material business impact from the cyber incident?

IEH states it believes the incident will not have a material adverse effect on its business operations as of the report date, although its investigation of the cybersecurity incident is ongoing and additional review work continues.
false 0000050292 0000050292 2026-08-04 2026-08-04 iso4217:USD xbrli:shares iso4217:USD xbrli:shares

UNITED STATES
SECURITIES AND EXCHANGE COMMISSION
WASHINGTON, D.C. 20549

 

FORM 8-K

 

CURRENT REPORT

Pursuant to Section 13 or 15(d) of the

Securities Exchange Act of 1934

 

Date of report (Date of earliest event reported): August 4, 2026

 

 IEH Corporation

(Exact Name of Registrant as Specified in Charter)  

 

New York   0-5278   13-5549348
(State or Other Jurisdiction
of Incorporation)
  (Commission
File Number)
  (I.R.S. Employer
Identification No.)

 

140 58th Street, Suite 8E

Brooklyn, NY 11220

(Address of Principal Executive Offices, and Zip Code)

 

(718) 492-4440 

Registrant’s Telephone Number, Including Area Code

Not Applicable

(Former Name or Former Address, if Changed Since Last Report) 

 

Securities registered pursuant to Section 12(b) of the Act:

 

Title of each class Trading Symbol(s) Name of each exchange on which registered
Common Stock  IEHC OTCQX Market

Check the appropriate box below if the Form 8-K filing is intended to simultaneously satisfy the filing obligation of the registrant under any of the following provisions (see General Instruction A.2. below):

 

  Written communication pursuant to Rule 425 under the Securities Act (17 CFR 230.425)

 

  Soliciting material pursuant to Rule 14a-12 under the Exchange Act (17 CFR 240.14a-12)

 

  Pre-commencement communication pursuant to Rule 14d-2(b) under the Exchange Act (17 CFR 240.14d-2(b))

 

  Pre-commencement communication pursuant to Rule 13e-4(c) under the Exchange Act (17 CFR 240.13e-4(c))

 

Indicate by check mark whether the registrant is an emerging growth company as defined in Rule 405 of the Securities Act of 1933 (17 CFR §230.405) or Rule 12b-2 of the Securities Exchange Act of 1934 (17 CFR §240.12b-2).

Emerging growth company

 

If an emerging growth company, indicate by check mark if the registrant has elected not to use the extended transition period for complying with any new or revised financial accounting standards provided pursuant to Section 13(a) of the Exchange Act. ☐

1 

 

 

Item 8.01 Other Events

 

On August 4, 2026, IEH Corporation (“IEH” or the “Company”) discovered that it sustained a cybersecurity incident whereby a threat actor using an alias gained unauthorized access to the Microsoft 365 mailbox of an employee of the Company. As soon as the incident was observed, the Company took action to contain the unauthorized access.

 

An investigation determined the compromise originated from a phishing attack in which a malicious actor impersonated a prospective business contact and delivered a hyperlink disguised as a Microsoft document-sharing link. The user accessed the link and entered Microsoft 365 credentials into a fraudulent login page, resulting in unauthorized account access.

 

The threat actor gained access to mailbox contents, including email messages, attachments, customer communications, purchase orders, engineering-related documentation, and potentially export-controlled technical information. No evidence currently exists that unauthorized emails were transmitted from the account or that data was successfully exfiltrated. However, sensitive information was accessible to the unauthorized party during the compromise period.

 

The account was secured, malicious mailbox rules were disabled, evidence was preserved, and corrective actions are underway.

 

Following containment and investigation activities, the Company initiated a review of account security controls and authentication protections applicable to Microsoft 365 services. The Company has already taken and completed a series of corrective actions to contain any impact of the unauthorized access.

 

However, at this time, the Company has no evidence that information was transmitted externally, downloaded or infiltrated. The Company only knows that the information was accessible to the unauthorized actor during the compromise period.

The Company is continuing to review the impacted communications and will provide, if necessary, any required notifications to affected parties and applicable regulatory agencies.

 

As of the date of this filing on Form 8-K, the Company believes that the incident will not have a material adverse effect on its business operations. The Company is continuing to investigate the incident.

 

Cautionary Statement Regarding Forward Looking Statements

Certain of the statements included in this Report constitute forward-looking statements within the meaning of the U.S. Private Securities Litigation Reform Act of 1995. Forward-looking statements are made based on management’s current expectations and beliefs concerning future developments and their potential effects upon the Company and its subsidiaries. The Company’s actual results may differ, possibly materially, from expectations or estimates reflected in such forward-looking statements. Certain important factors that could cause actual results to differ, possibly materially, from expectations or estimates reflected in such forward-looking statements can be found in the “Risk Factors” and “Forward-Looking Statements” sections included in the Company’s Annual Reports on Form 10-K and Quarterly Reports on Form 10-Q. The Company does not undertake to update any particular forward-looking statement included in this document.

 

2 

 

 

 

SIGNATURE

 

Pursuant to the requirements of the Securities Exchange Act of 1934, the Registrant has duly caused this report to be signed on its behalf by the undersigned, hereunto duly authorized.

 

    IEH Corporation
     
    By:  /s/Subrata Purkayastha
    Name: Subrata Purkayastha
    Title: Chief Financial Officer
Date:   August 6, 2026    

 

 

 

 

3 

 

Filing Exhibits & Attachments

3 documents