TOAD Phishing Attacks — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 17, 2025
Last Seen
November 17, 2025

TOAD Phishing Attacks is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 17, 2025; most recent activity November 17, 2025.

Overview

TOAD Phishing Attacks is a threat campaign that abuses Microsoft Entra (Azure Active Directory) invitation workflows to conduct phishing at scale. Attackers hijack or manipulate Entra invitations to lure recipients into interacting with malicious content, leveraging legitimate identity management processes. The campaign is significant because it targets cloud identity and guest access workflows, potentially bypassing some traditional phishing defenses.

Related Threat Clusters

Recent Intelligence Reports

  • Microsoft Entra Invitations Hijacked in Surge of TOAD Phishing Attacks — Gbhackers · November 17, 2025

CVSS v3.1 Breakdown