MSP in the UK, about 40 clients. I have seen most of the ways this goes wrong.
The uploads one caught something on a client from about a month ago, unrelated to this. Not a great morning but a useful one.
Mailbox rules is the one. Every BEC case I have been near had a rule moving anything with "invoice" or "payment" into a folder nobody opens.
100k is a lot for a bounty and still less than the same bug goes for elsewhere, which is the depressing part of this whole economy.
> failing since March
And there it is. That is the actual reason to care about failed logons that are "not an attack".
That matches what I have been seeing. This is more useful than the last two weeks of vendor calls.
Splunk, QRadar, Sentinel, Trunc, take your pick. Honestly nobody knows, every survey is sponsored by somebody on the list.
How many servers is "a few"? Under about 20 the answer is usually different than over 20.