Skip to content
← BlogStrategyAnalysis9 min read

A defense giant's data breach shows exactly what makes phishing convincing now

RTX Corporation disclosed a breach exposing real employee and customer records — and a preview of how accurate stolen data supercharges phishing.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

RTX Corporation — the aerospace and defense giant that owns Raytheon, Collins Aerospace, and Pratt & Whitney — disclosed a data breach to the Massachusetts Attorney General on July 24, 2026. The exposed data includes full names, mailing addresses, and Social Security numbers belonging to employees and, in some cases, customers. Notification letters went out in the following days, along with an offer of 24 months of credit monitoring through Equifax. RTX hasn’t said publicly how the breach happened, and hasn’t confirmed a total headcount — though a lawsuit filed by a former employee, reported by Law360, claims the exposure reaches as many as 1.5 million people, a figure that is the plaintiff’s characterization rather than a company-confirmed number.

There’s a version of this story that’s just “another big company got breached, again.” That version isn’t very useful. The more useful version is about what specifically got taken, and what that specific category of data is worth to whoever has it now.

Not every stolen dataset is equally dangerous

A breach of, say, browsing history or marketing preferences is bad, but it’s not precision fuel for social engineering. A breach of name, home address, and Social Security number — the exact fields payroll and HR systems hold, tied together and confirmed accurate — is a different category entirely. It’s the raw material for the specific thing that makes modern phishing and business email compromise work: not a cleverly worded email, but an email (or call, or text) that already knows true, specific, personal facts about the target before the first word is said.

This is the mechanism behind why business email compromise has become one of the most financially damaging categories of cybercrime tracked by the FBI’s Internet Crime Complaint Center — reported BEC losses run into the billions of dollars annually across tens of thousands of complaints nationwide, with individual incidents frequently costing well over $100,000 each. The scam isn’t sophisticated in a technical sense. It’s sophisticated in a research sense: the attacker knows enough true detail about a company, a person, or a pending transaction that the request to “resend that wire to the updated account” reads as routine rather than suspicious.

Where a breach like RTX’s actually leads

RTX itself, as a company, has enormous internal security resources and a deep, sprawling supplier network — the kind of aerospace and defense supply chain that regularly moves large invoice amounts between vendors who don’t interact daily enough to instantly notice something’s off. That combination (accurate personal data now circulating, plus a supply chain built on large periodic payments between parties who trust each other by relationship rather than by verifying every transaction from scratch) is exactly the environment BEC thrives in. Whether or not this specific dataset is ever used that way, it’s worth understanding the shape of the risk it creates, because the same shape applies to any company with a real supplier or client relationship conducted partly over email — which is most of them.

SignalGeneric phishingPrecision phishing using breached data
Sender detail accuracyOften slightly off — wrong name, vague greetingCan cite your real name, role, or address correctly
TimingRandom, untargeted blastCan be timed around a real event the attacker learned about
What defeats itSpotting an obvious tellVerifying the request through a separate, already-trusted channel — not the channel the request arrived on

Why a supplier network makes this worse, not just bigger

A large industrial company like RTX doesn’t run on one payment relationship — it runs on thousands of them, spread across a supplier base where a single invoice can legitimately run into six or seven figures, and where the people approving a payment often work at a different company entirely from the one requesting it. That’s precisely the environment where “does this look right” is a weaker check than it feels like in the moment: the approver frequently doesn’t have deep, personal context on the counterparty to notice something’s subtly off, only a set of documents and an email thread that look procedurally correct. Breached employee data doesn’t need to unlock RTX’s own systems to be dangerous here — it’s just as useful pointed outward, at the hundreds of smaller vendors and suppliers who deal with a company like RTX and who have far less security infrastructure of their own to catch a well-researched impersonation attempt.

This is exactly why company size is a poor predictor of who actually eats the loss in this category of fraud. The large enterprise at the center of a supply chain is rarely the one whose bank account the money leaves from — it’s the smaller vendor a few links away, acting on what looks like a routine, accurately-detailed request from a partner they’ve worked with for years.

What actually holds up against this

The defense against precision phishing isn’t “get better at noticing fakes” — that arms race favors the attacker as breached data gets more accurate and more available. It’s process: never change payment details, wire instructions, or sensitive account access based on an email or a call alone, no matter how convincing or accurate the details in it are. The same logic applies to a lookalike-domain phishing attempt: the fix isn’t spotting the trick in the moment, it’s a standing rule that some requests never get actioned from the inbound channel alone, regardless of how legitimate they look.

A verification process that holds up even against accurate, well-researched pretexts

  1. Treat every payment-detail or credential change request as untrusted by default

    This applies even when it arrives from what looks like the correct sender, cites correct details, and continues an existing thread — accuracy is exactly what precision phishing is optimized to fake.

  2. Verify through a channel you already had on file, never one supplied in the message

    Call the phone number in your existing vendor record, not the one in the email signature. A message that supplies its own 'verification' contact is supplying the attacker's contact, not a real check.

  3. Require a second, separate approval for any change above a set dollar threshold

    One person acting alone under time pressure is the exact condition BEC scripts are written to create. A second approver, reachable independently, breaks that pressure.

  4. Slow down anything framed as urgent or confidential

    Legitimate finance and procurement changes rarely require same-day secrecy. 'Don't mention this to anyone else yet' paired with a payment request is one of the most consistent tells across real BEC cases, precisely because it suppresses the second-channel check that would catch it.

For anyone running outbound email specifically, there’s a second layer worth thinking about: making sure your own domain can’t be the vehicle for exactly this kind of attack against your own customers or prospects. A domain with properly enforced SPF, DKIM, and DMARC can’t be trivially spoofed, which means a recipient who’s trained to verify suspicious requests through a second channel has a real, technical signal to check — not just a gut feeling.

Where Norbelys fits

Domain authentication and DMARC monitoring are built into Norbelys on every plan, precisely because the domain you send legitimate outbound from is also the domain an attacker would love to spoof to defraud your own prospects and customers. Mailbox credentials are encrypted at rest and never returned by the API once connected, so a breach elsewhere in your stack can’t be quietly turned into a way to send fraudulent mail from an account you thought was secure.

If this story is a prompt to actually check your own domain’s authentication posture rather than assume it’s handled, that’s a fifteen-minute task worth doing this week, not next quarter. See how DMARC monitoring and sender protection fit into every Norbelys plan — it’s included from Starter up, not gated behind a higher tier once you’ve already had a problem. Start protecting your sending domain before someone else tries to borrow its trust.

RTX breach and precision phishing — quick answers

What data was exposed in the RTX Corporation breach?

Full names, mailing addresses, and Social Security numbers belonging to employees and, in some cases, customers, according to RTX's disclosure to the Massachusetts Attorney General on July 24, 2026. RTX has not disclosed how the breach occurred.

How many people were affected?

RTX has not confirmed a total figure publicly. A lawsuit filed by a former employee, reported by Law360, claims the breach affected as many as 1.5 million people — a figure from the litigation, not a company-confirmed total.

Why does accurate personal data make phishing more dangerous than a generic scam email?

Traditional phishing relies on volume and hopes someone doesn't notice inconsistencies. Phishing built on accurately breached personal data can cite real names, roles, addresses, or transaction details, removing the obvious tells that used to make fakes easy to spot — which is a core driver behind business email compromise being the costliest category of reported cybercrime.

What actually protects against this kind of attack?

A standing process that never approves payment changes, wire instructions, or credential resets based solely on an inbound email or call — always verifying through a separate, already-trusted channel — combined with enforced domain authentication (SPF, DKIM, DMARC) so your own domain can't be easily spoofed to run the same attack against your customers.

Why are smaller suppliers often more exposed than the large company at the center of a breach?

Large enterprises typically have significant security infrastructure, while the smaller vendors and suppliers who deal with them often don't. Breached employee or company data can be pointed outward at those suppliers just as easily as inward at the breached company itself, and the smaller party is frequently the one whose account the fraudulent funds actually leave from.