Expel Quarterly Threat Report, Q1 2025: Cloud-based service trends
ID: 1867ec6d-d4c6-5733-9de1-07770473f0a9
STIX ID: report--1867ec6d-d4c6-5733-9de1-07770473f0a9
Feed Name: Expel Blog
This Q1 2025 report section examines cloud-based service threats, showing identity and email compromise dominate incidents as attackers leverage credential theft and phishing—particularly phishing-as-a-service—to gain access. Hosting providers accounted for 67.3% of malicious logins tracked; credential harvesters and social engineering were the most common phishing submissions, and commonly abused sender domains included gmail.com, dropbox.com, and docusign.net. The report recommends mitigations such as enforcing logins from managed devices and adopting FIDO2-compliant MFA to reduce account takeover risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
