TOAD is a phishing campaign that targets Microsoft Entra guest invitees using fake invoices to lure recipients into revealing credentials or interacting with a fraudulent login page.
TOAD is a phishing campaign that targets Microsoft Entra guest invitees using fake invoices to lure recipients into revealing credentials or interacting with a fraudulent login page. By exploiting the Entra guest invitation workflow and invoice branding, the operation seeks to compromise external collaborators and access tenant resources. This highlights the risk of identity-platform abuse and invoice-themed phishing in modern threat campaigns.
A new phishing campaign, identified as TOAD, has been targeting Microsoft Entra guest invitees by sending fake invoices. The campaign was uncovered by threat researcher Matt Taggart and associates over the weekend,…
A new phishing campaign is exploiting Microsoft Entra's guest user invitation system, targeting users with fake invoices related to Microsoft 365. Attackers are using the legitimate '[email protected]' domain to…