IEH Corporation told the SEC that a phished employee's Microsoft 365 mailbox exposed engineering files and potentially export-controlled technical data.