TOAD Attack is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 18, 2025; most recent activity November 18, 2025.
TOAD Attack is a phishing campaign that exploits the Microsoft Entra guest invitation workflow (Azure AD guest invites) to deliver lure messages to target users. By leveraging legitimate Entra invitation mechanics, attackers aim to harvest credentials or access tokens and gain unauthorized access to cloud resources. The campaign highlights the risk posed by enterprise collaboration features when abused by threat actors.
A new phishing campaign, identified as TOAD, has been targeting Microsoft Entra guest invitees by sending fake invoices. The campaign was uncovered by threat researcher Matt Taggart and associates over the weekend,…
A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to…