TOAD Phishing Campaign — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
November 18, 2025
Last Seen
November 18, 2025

TOAD is a phishing campaign that targets Microsoft Entra guest invitees using fake invoices to lure recipients into revealing credentials or interacting with a fraudulent login page.

Overview

TOAD is a phishing campaign that targets Microsoft Entra guest invitees using fake invoices to lure recipients into revealing credentials or interacting with a fraudulent login page. By exploiting the Entra guest invitation workflow and invoice branding, the operation seeks to compromise external collaborators and access tenant resources. This highlights the risk of identity-platform abuse and invoice-themed phishing in modern threat campaigns.

Related Threat Clusters

Recent Intelligence Reports

  • New TOAD phishing campaign targets Microsoft Entra guest invitees with fake invoices — Cybernews · November 18, 2025

Related Entities

CVSS v3.1 Breakdown