TOAD Attack — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 18, 2025
Last Seen
November 18, 2025

TOAD Attack is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 18, 2025; most recent activity November 18, 2025.

Overview

TOAD Attack is a phishing campaign that exploits the Microsoft Entra guest invitation workflow (Azure AD guest invites) to deliver lure messages to target users. By leveraging legitimate Entra invitation mechanics, attackers aim to harvest credentials or access tokens and gain unauthorized access to cloud resources. The campaign highlights the risk posed by enterprise collaboration features when abused by threat actors.

Related Threat Clusters

Recent Intelligence Reports

  • Microsoft Entra guest invites harnessed in new phishing campaign — Scworld · November 18, 2025

CVSS v3.1 Breakdown