Attacker phished way into US defense supplier's Microsoft 365 account
What happened
A US defense supplier reported that an employee was phished and an attacker accessed its Microsoft 365 mailbox. The intruder could view engineering documents, purchase orders and potentially export-controlled files; the company discovered and secured the account and reported containment actions publicly. Watch whether suppliers provide preserved logs and forensic artifacts and whether contracts already permit rapid evidence access
Why the category manager should care
Require phishing-resistant authentication and contractual rights to preserved logs and forensic artifacts because supplier-managed mailboxes are a high-impact attack path
Key facts
- Attacker accessed Microsoft 365 mailbox contents
- Email, attachments, purchase orders and engineering files were exposed
- Company reported discovery and containment actions in a public filing