TOAD Phishing Attacks is a threat campaign tracked across 2 threat clusters and 1 intelligence report mention on ThreatCluster. First observed November 17, 2025; most recent activity November 17, 2025.
TOAD Phishing Attacks is a threat campaign that abuses Microsoft Entra (Azure Active Directory) invitation workflows to conduct phishing at scale. Attackers hijack or manipulate Entra invitations to lure recipients into interacting with malicious content, leveraging legitimate identity management processes. The campaign is significant because it targets cloud identity and guest access workflows, potentially bypassing some traditional phishing defenses.
A new phishing campaign, identified as TOAD, has been targeting Microsoft Entra guest invitees by sending fake invoices. The campaign was uncovered by threat researcher Matt Taggart and associates over the weekend,…
A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to…