Skip to content
Phishing Campaign Exploits Microsoft Entra Invitations for TOAD Attacks

Phishing Campaign Exploits Microsoft Entra Invitations for TOAD Attacks

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate 'invites@microsoft.com' domain to distribute emails that appear to be from Microsoft, tricking recipients into providing sensitive information. This campaign has been identified as a Telephone-Oriented Attack Delivery (TOAD) attack.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 194d ago How this analysis works

More articles in this cluster (6)

Following this threat?

Track Microsoft in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed