Defense Executives Face Growing Risk From Identity-Based Cyberattacks
Recent phishing, impersonation, and repeated login approval attempts against a European defense investor highlight the growing identity risks facing defense companies, executives, and suppliers.
Defense companies are investing heavily in secure communications, protected infrastructure, and classified program controls. Yet attackers often begin with a less technical target: an employee carrying a smartphone and managing a crowded inbox.
Jonas Malmgren, CEO of defense technology investor Front Ventures, recently disclosed several suspected cyber intrusion attempts directed at him and his colleagues. The incidents included a fraudulent electronic signature request, repeated authentication prompts linked to an unfamiliar device, and an impersonation message sent to a colleague through a privately used email address.
The reported activity has not been independently attributed to a specific actor. However, the methods resemble established social engineering techniques used by cybercriminal groups and state-linked operators against companies with valuable technology, government relationships, and access to sensitive supply chains.
For the defense industry, the incidents provide a useful warning. A compromised executive, program manager, engineer, investor, or supplier can offer an attacker access that may be more valuable than an initial intrusion into a corporate server.
Attackers are targeting identity rather than infrastructure
The fraudulent electronic signature email reportedly presented Malmgren as the final approver while using a sender address outside the company domain. This type of impersonation can exploit familiar business processes such as contracts, procurement approvals, nondisclosure agreements, financing documents, and supplier onboarding.
Electronic signature requests are particularly effective because recipients are accustomed to opening documents hosted outside their own corporate network. A malicious link may redirect the user to a counterfeit login page, initiate a malware download, or capture an active session after authentication.
The second reported incident involved repeated requests to approve access through two-step authentication. The prompts appeared to originate from a nearby Google TV device and were reportedly delivered around 20 times during one month.
This technique is commonly described as MFA fatigue, push bombing, or authentication prompt bombing. The attacker repeatedly generates approval requests in the hope that the target will accept one through confusion, habit, or frustration. CISA has documented the use of push bombing by sophisticated social engineering groups, alongside phishing, voice impersonation, and SIM swap attacks.
The apparent use of a household device adds another layer of credibility. Remote work has blurred the boundary between corporate systems, personal accounts, home networks, smart televisions, mobile devices, and consumer cloud services. An approval request that appears consistent with the user’s home environment may attract less scrutiny than a login attempt from an unfamiliar country.
The third incident involved an urgent chat invitation sent to a colleague’s private email address while impersonating Malmgren. According to his account, the associated infrastructure included a Russian server or domain. That technical detail alone does not establish responsibility, as attackers can register foreign domains, rent infrastructure in multiple jurisdictions, or deliberately create misleading indicators.
The more important element is the combination of executive impersonation, urgency, and movement outside monitored corporate communications. Private email accounts usually provide security teams with less visibility and may not be protected by the organization’s filtering, logging, and incident response systems.
Why the defense industrial base is exposed
Defense organizations hold information with commercial, operational, and strategic value. This can include technical documentation, procurement schedules, pricing data, export licensing records, government contacts, production capacity, software repositories, and details about subcontractors.
Not every attacker needs access to classified information. Information about manufacturing bottlenecks, component suppliers, planned deliveries, investment decisions, or personnel can support espionage, fraud, disruption, or a later supply chain intrusion.
Smaller companies are particularly important. Startups, engineering consultancies, specialist manufacturers, software developers, and maintenance providers may connect to larger contractors while operating with more limited cybersecurity resources.
The EU’s NIS2 framework identifies supply chain security, vulnerability management, and cybersecurity awareness as central parts of organizational risk management. The directive also notes that smaller companies may become entry points for attacks with wider consequences for customers and partners.
ENISA’s 2025 threat assessment found that supply chain risks represented a significant share of the analyzed threat environment, reflecting the use of third parties and dependencies as indirect routes into targeted organizations. The agency also recorded continued pressure on public administration and other sectors connected to essential state functions.
NATO similarly assesses that malicious cyber activity ranges from routine phishing to sophisticated espionage operations targeting government services, military activity, and critical infrastructure.
Multi-factor authentication is necessary, but not sufficient
The reported attempts demonstrate why simply enabling multi-factor authentication does not complete an identity security program.
Basic push notifications remain vulnerable to user error and social engineering. Organizations handling sensitive defense information should prioritize phishing-resistant authentication for email, virtual private networks, administrative accounts, cloud platforms, source code environments, and systems supporting critical programs.
CISA recommends phishing-resistant MFA, particularly for email, remote access, and accounts connected to critical systems. The UK National Cyber Security Centre also advises organizations to select stronger authentication methods rather than treating every form of MFA as equally secure.
Hardware security keys, passkeys, and FIDO2-based credentials can provide stronger protection because authentication is bound to the legitimate service. This makes it harder for a counterfeit website to capture reusable credentials or persuade a user to approve an unrelated login attempt.
Controls should also limit repeated authentication prompts, require number matching or additional context, and automatically alert security teams when multiple denials occur. An unexpected MFA request should be treated as a possible sign that the attacker already knows the user’s password.
Executives and investors require dedicated protection
Senior personnel are attractive targets because they have authority, broad access, and publicly visible business relationships. Their names appear in corporate announcements, conference programs, procurement discussions, and social media posts.
Defense investors can also hold sensitive information across several portfolio companies. Compromising one account may reveal investment plans, technical assessments, founder communications, customer interest, and upcoming transactions.
Companies should therefore apply additional controls to executives, board members, investors, system administrators, and personnel involved in procurement or classified programs. These measures should cover personal exposure as well as corporate accounts.
Private email addresses and phone numbers should not be used for program-related communication. Requests involving payments, contracts, credentials, file sharing, or changes to communication channels should be verified through a separate trusted method.
Security teams should also monitor lookalike domains, fraudulent profiles, leaked credentials, and impersonation of senior personnel. Rapid reporting procedures are essential because a suspicious message sent to one employee may be part of a wider campaign against customers, suppliers, or partner organizations.
Cybersecurity is becoming a procurement issue
For defense contractors, cybersecurity maturity increasingly affects more than internal risk. It can influence eligibility for government programs, access to sensitive data, supplier selection, insurance conditions, and the ability to maintain customer confidence after an incident.
Prime contractors cannot assume that their own security controls will protect information shared across a fragmented industrial network. Cybersecurity requirements need to extend into supplier qualification, contract management, identity governance, incident notification, and subcontractor oversight.
The incidents described by Malmgren did not involve advanced exploits or previously unknown software vulnerabilities. They relied on recognizable names, credible workflows, repeated notifications, and the possibility that a busy employee would make one incorrect decision.
That is what makes them relevant across the defense industrial base. The initial point of entry may be an inbox, a mobile approval request, or a personal account. The consequences can extend into procurement programs, intellectual property, production networks, and national security supply chains.