logo

2023 Great eXpeltations report: top six findings

ID: 4c770b23-500f-59a0-a8e4-c636318e0ac0

STIX ID: report--4c770b23-500f-59a0-a8e4-c636318e0ac0

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2023-01-31

Date Updated: 2026-04-27

Author: Ben Brigida

...
...

**Expel Great eXpeltations (2022) — executive summary:** The SOC annual report highlights that business email compromise (BEC) represented ~50% of incidents (mostly targeting Microsoft 365), credential-harvesting phishing made up 88% of malicious email submissions, adversaries employed AiTM phishing (Evilginx2) to bypass MFA, attackers targeted Workday for payroll fraud, and 11% of incidents could have led to ransomware if not interrupted; the report includes prevalence statistics and mitigation advice such as enforcing MFA, using FIDO2/certificate-based auth, and implementing approval workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.