logo

Expel Quarterly Threat Report Q3: Top 5 takeaways

ID: e6773c65-6f3f-5eb8-b11a-02ae14d80067

STIX ID: report--e6773c65-6f3f-5eb8-b11a-02ae14d80067

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2022-11-16

Date Updated: 2026-04-27

Author: Ben Brigida

...
...

Q3 2022 Quarterly Threat Report: SOC analysis shows identity-based attacks (credential theft, credential abuse, and long-term access key theft) comprised ~60% of incidents, with BEC/BAC responsible for 55% of events and all BEC incidents observed in Microsoft 365; MFA push-notification fatigue is an increasing cause of successful compromises. Attackers frequently use U.S.-geolocated VPN/hosting IPs to bypass conditional access, and ransomware groups favor zipped JavaScript and ISO attachments over VBA/Excel macros as initial vectors; common phishing subject themes include blank subjects and payment/invoice lures. The report provides practical mitigations such as enforcing stronger MFA (FIDO/number matching), monitoring IP organizations, and updating detection for zipped JS/ISO payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.