Expel incident

Amazon Web Services outage affecting Expel Workbench

Notice Resolved View vendor source →

Expel experienced a notice incident on October 20, 2025 affecting Email and Slack and 1 more component, lasting 2h 28m. The incident has been resolved; the full update timeline is below.

Started
Oct 20, 2025, 10:06 AM UTC
Resolved
Oct 20, 2025, 12:35 PM UTC
Duration
2h 28m
Detected by Pingoru
Oct 20, 2025, 10:06 AM UTC

Affected components

EmailSlackTeamsTicketing systems (via email, such as Jira)Alert ingestionPagerDutyOpsgenie

Update timeline

  1. monitoring Oct 20, 2025, 10:06 AM UTC

    Amazon Web Services reported an outage affecting AWS services in the US-EAST-1 region starting at approximately 06:50am UTC. AWS communicated that it identified the root cause and took mitigation actions, and that it’s seeing significant signs of recovery. This outage is affecting how Expel Workbench ingests and processes alerts, as well as how we communicate with customers. At this time, Expel Workbench is operating normally. Our systems are working through a backlog of security device data.

  2. monitoring Oct 20, 2025, 10:33 AM UTC

    We are continuing to monitor. Workbench is working the backlog of alerts. Please note that no customer data was lost as a result of the AWS outage. We will post the next update at 11:00am UTC.

  3. monitoring Oct 20, 2025, 11:04 AM UTC

    We are continuing to monitor. Workbench continues to process the backlog of alerts. Amazon reports that it has mitigated the underlying the DNS issue, and most AWS Service operations are succeeding normally now. Please note that no customer data was lost as a result of the AWS outage. We will post the next update at 11:30am UTC.

  4. monitoring Oct 20, 2025, 11:31 AM UTC

    We are continuing to monitor. Workbench continues to process the backlog of alerts. Please note that no customer data was lost as a result of the AWS outage. We will post the next update at 12:00pm UTC.

  5. monitoring Oct 20, 2025, 11:59 AM UTC

    Expel Workbench is fully operational, has processed the full backlog of alerts, and is ingesting and processing current alerts normally. We will continue to monitor and provide additional updates as necessary.

  6. monitoring Oct 20, 2025, 12:24 PM UTC

    We are continuing to monitor for any further issues.

  7. resolved Oct 20, 2025, 12:35 PM UTC

    The incident has been resolved, and all systems are once again fully available. No customer data was lost.