Looking for an update now? Check the current status, or follow Expel, Inc. for future changes.
94.6%of 37 verified observed days had no reported provider issue
90-Day Trend
Dashed calendar markers below identify legacy observations whose source-at-observation was not recorded.
Monthly Status Summary
Month
Issue-free days
Days Tracked
Days with issues
September 2026
96.7%
30
1
This percentage summarizes normalized provider-status observations by calendar day. It is not duration-based, component-weighted, or contractual uptime. See the methodology and limitations.
Recorded Daily Status (Last 91 Days)
Jul 2Today
Legacy observation Operational Degraded Partial Outage Major Outage Maintenance No Data
We have implemented a fix and believe the incident to be resolved. We are monitoring the health of the infrastructure and will resolve this if there are no outstanding issues. Please let us know if you are experiencing any problems.
investigating
At 10:30AM ET, we began experiencing a problem with alert ingestion. SOC operations are affected, but will catch up once service is restored; no data will be lost. We will provide an update by 3:30PM ET.
investigating
At 10:30AM ET, we began experiencing a problem with alert ingestion. SOC operations are affected, but will catch up once service is restored; no data will be lost. We will provide an update by 2:30PM ET.
investigating
At 10:30AM ET, we began experiencing a problem with alert ingestion. SOC operations are affected, but will catch up once service is restored; no data will be lost. We will provide an update by 1:30PM ET.
investigating
At 10:30AM ET, we began experiencing a problem with alert ingestion. SOC operations are affected, but will catch up once service is restored; no data will be lost. We will provide an update by 12:30PM ET.
EmailTicketing systems (via email, such as Jira)Phishing submissions
monitoring
Email delivery from Workbench is now working and emails in the queue are being replayed. An update will be posted once the replay is complete.
identified
We are continuing to work on remediation.
MDR services are unaffected. Alert ingestion, detection, and investigation are operating normally. Slack, Microsoft Teams, PagerDuty, Opsgenie, and Service Now notifications are still being delivered.
Email delivery from Workbench remains unavailable. No action is required at this time; we will confirm resubmission steps for phishing submissions once service is restored.
Next update: Monday, 31 August at 13:00 UTC (9:00 AM ET)
identified
We have identified the cause are continuing to work on remediation. We have also confirmed that due to this issue, when someone submits a suspected phishing email, the email will not reach Workbench for review. Next update at 1pm UTC.
identified
Emails from Workbench are delayed since 12am UTC. We have identified the root cause and are working on a remediation. Phishing outcome responses, User Email notifications, and Org-Level Email Ticketing notifications are delayed since 12am UTC. SOC operations and alert ingestion are not affected. We will provide another update by 12:30pm UTC
Legacy Incident Archive
11 archived records restored. These records predate source-at-observation attestation. They are shown as historical ServiceAlert records only and do not establish a provider-reported incident, resolution, duration, or current active state.
July 2026
Workbench Availability due to Database Issue
criticalSource not attested
Last archived state: resolved
View archived record details
monitoring
We have implemented a fix and believe the incident to be resolved. We are monitoring the health of the infrastructure and will resolve this if there are no outstanding issues. Please let us know if you are experiencing any problems.
investigating
At 9:58pm EDT, we began experiencing a problem with the Workbench database that is preventing users from accessing Workbench. We will provide an update by 11pm EDT.
Issue affecting some vendor alerts
Source not attested
Last archived state: resolved
View archived record details
investigating
On June 18th, a change was made in Expel's environment that inadvertently introduced logic that silently indexed vendor alerts. This change was reverted in order to restore alerting as soon as it was identified on July 1st. Our team has identified several alerts that occurred during the impacted service period within a number of customer environments that we are replaying. If any incidents surface, impacted customers will be notified via Workbench. In the meantime please do not hesitate to re...
June 2026
Delayed Notifications
minorSource not attested
Last archived state: resolved
View archived record details
monitoring
The cause of the notification delays has been resolved and we are observing delayed messages being delivered. All delayed notifications will be processed and we will continue to monitor.
identified
Workbench notifications continue to be delayed since 19:09 UTC due to an issue with a third-party notification vendor. They are working on a fix. All delayed notifications will be processed once the outage is resolved. Next update 22:00 UTC
identified
We've identified the cause of the delayed notifications as an issue with a third-party notification vendor. A fix is currently being applied. Workbench notifications have been delayed since 19:09 UTC, and we'll provide another update at 21:30 UTC.
investigating
At 2pm ET, we began experiencing a problem with our notification system that is causing notification delays to our customers. We will provide an update by 5pm ET.
Delays in processing phishing submissions
minorSource not attested
Last archived state: resolved
View archived record details
investigating
Beginning at 19:47 UTC, phishing submissions are not being processed, which is preventing the creation of Phishing Expel Alerts. Suspected phishing emails submitted for review during this period may not yet be analyzed. We've identified the cause and we are working with the vendor to address the issue. We expect to retrieve and process them once service is restored.
investigating
We think we have identified the problem and are working on a resolution right now. Will update again in 60 minutes.
investigating
We are continuing to investigate this issue. Will post another update in 60 minutes.
investigating
We are continuing to investigate this issue
investigating
We are investigating an issue affecting the processing of phishing submissions. Beginning at 19:47 UTC, phishing submissions are not being processed, which is preventing the creation of Phishing Expel Alerts. Suspected phishing emails submitted for review during this period may not yet be analyzed.
Our team is actively working to identify the cause. We will provide an update by 00:00 UTC.
Alert Ingestion Delay for AWS Cloudtrail
minorSource not attested
Last archived state: resolved
View archived record details
monitoring
A fix has been implemented and we are monitoring the results.
investigating
At 10am ET, we began experiencing a problem with alert ingestion for some AWS Cloudtrail devices. We will provide an update by 1pm ET.
Workbench Availability
Source not attested
Last archived state: resolved
View archived record details
monitoring
We are continuing to monitor for any further issues.
monitoring
We have identified the issue, have rolled out a fix and are monitoring the situation.
investigating
Workbench is still experiencing connectivity issues. We are still investigating the issue and will provide an update in 1 hour.
investigating
Workbench is currently experiencing connectivity issues and may be inaccessible for some users. We are investigating the issue and will provide an update within an hour.
May 2026
Workbench Expel Alert Count Discrepancy
Source not attested
Last archived state: resolved
View archived record details
identified
We have remediated the issue with Expel Alerts count being inflated for customers by shifting to a different source of statistics. We are working on fixing the underlying issue with our main source of count data. We will provide another update by 1pm EDT.
identified
We are aware of an issue with the Expel Alerts count being inflated for customers. We have identified the root cause and are working on a remediation. SOC operations and alert ingestion are not affected. We will provide another update by 1pm EDT.
Security Device Credentials Availability
majorSource not attested
Last archived state: resolved
View archived record details
monitoring
We have implemented a fix and believe the incident to be resolved. We are seeing customer security devices returning to healthy status. We are monitoring the health of the infrastructure and will post another update by 4pm EDT.
investigating
At 2pm EDT, we began experiencing a problem with the customer device secrets service that is preventing our infrastructure from accessing customer security devices. We will provide an update by 3:30pm EDT.
April 2026
Delayed Notifications
minorSource not attested
Last archived state: resolved
View archived record details
investigating
At 1pm ET, we began experiencing a problem with our notification system that is causing notification delays to our customers. We will provide an update by 2:30pm ET.
Alert ingestion delayed for a subset of security devices
majorSource not attested
Last archived state: resolved
View archived record details
monitoring
We restored the credentials for the subset of devices, and are seeing that the majority of devices have returned to a healthy state. We are investigating the remaining unhealthy devices, which do not seem related to credentials. We will provide another update by 4:30pm EDT.
monitoring
We restored the credentials for the subset of devices, and are seeing that the majority of devices have returned to a healthy state. We are investigating the remaining unhealthy devices, which do not seem related to the credentials. We will provide another update by 4:00pm EDT.
identified
We have restored the credentials for the subset of devices. We are monitoring closely to ensure proper ingestion of delayed alerts. We will provide another update by 3:30pm EDT.
identified
We have restored the credentials for the affected subset of devices. We are monitoring closely to ensure proper ingestion of delayed alerts. We will provide another update by 3:00pm EDT.
investigating
We have identified the specific subset of devices that are affected and are working on restoring the credentials for those devices. Once restored, all alerts that have not been ingested for these devices will be ingested. We will provide another update by 2:30pm EDT.
investigating
We have identified the specific subset of devices that are affected and are working on restoring the credentials for those devices. Once restored, all alerts that have not been ingested for these devices will be ingested. We will provide another update by 2:00pm EDT.
investigating
We have identified the specific subset of devices that are affected and are working on restoring the credentials for those devices. Once restored, all alerts that have not been ingested for these devices will be ingested. We will provide another update by 1:30pm EDT.
investigating
At 10:59AM EDT, we noticed that a set of devices have been unhealthy since last week due to invalid credentials. We believe the cause to be a change to our device credentials storage subsystem. We are working to identify the specific set of devices and restore the credentials. Once restored, all delayed alerts will be ingested. We will provide an updated by 1pm EDT.