TOAD Attacks is a threat campaign tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed November 17, 2025; most recent activity November 19, 2025.
TOAD Attacks is a threat campaign that abuses Microsoft Entra (Azure Active Directory) invitation features—guest and tenant invitations—to infiltrate organizations, establish footholds, and enable credential theft or data exfiltration. Described as sophisticated, the campaign relies on trusted invitation mechanisms to blend with normal collaboration and bypass some controls, underscoring identity-based risks in cloud environments.
A new phishing campaign, identified as TOAD, has been targeting Microsoft Entra guest invitees by sending fake invoices. The campaign was uncovered by threat researcher Matt Taggart and associates over the weekend,…
Cybercriminals are conducting a phishing campaign that utilizes Microsoft Entra tenant invitation emails to execute Telephone-Oriented Attack Delivery (TOAD) attacks. This method targets users by misleading them into…
A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to…