Phishing Campaign Exploits Microsoft Entra Invitations for TOAD Attacks

Phishing Campaign Exploits Microsoft Entra Invitations for TOAD Attacks

First seen 2 Dec 2025, 18:33 UTC CyberpressGbhackersCybersecuritynewsCybernewsScworld+1 79% similarity 10.2

Article Content

Browse articles
ThreatCluster

A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to distribute emails that appear to be from Microsoft, tricking recipients into providing sensitive information. This campaign has been identified as a Telephone-Oriented Attack Delivery (TOAD) attack.

ThreatCluster AI

Community

Browse all →