Why am I seeing logins from unexpected countries on my Monthly Report?

Your Monthly report presents an overview of interesting Field Effect metrics.  The Monthly report is broken down into several sections and is covered in more detain in our guide Meet your Monthly report


The Email Security section of your Monthly report provides a breakdown of which email accounts were accessed most frequently, as well as from which countries authorization attempts were attempted.



In the example above, we can see that 3 most popular countries where logins were attempted were the US, India and China.  If your organization only has employees in the US then authorization attempts from India and China are obviously suspicious.


This is not entirely unexpected as threat actors from around the world are always trying to gain access to user accounts by guessing passwords and usernames. 


As noted in the report, these are authorization attempts - not successful logins, and as long as MFA is enabled and strong passwords are being used, there shouldn't be any concern about this activity. 


It is reported as a way to give you visibility into what's going on on your network, however anything that poses a security risk or your immediate attention will always be reported to you through an ARO.

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article