Custom illustration showing a Microsoft Entra guest invitation overlaid with a warning about TOAD callback phishing attacks

Hackers Exploit Microsoft Tenant Invitations for TOAD Phishing

Threat actors are abusing Microsoft Entra tenant invitations to run TOAD (Telephone-Oriented Attack Delivery) phishing campaigns that look like legitimate Microsoft 365 billing notifications. Instead of pushing links or attachments, they convince users to call attacker-controlled “support” numbers, where credentials and remote-access authorizations are harvested. This analysis explains how the attack chain works, which guest invitation properties are being misused, and how security teams can hunt for and mitigate these callbacks.

Read More