logo

Hackers Exploiting .onmicrosoft.com Domains to Launch TOAD Scam Attack

ID: c37045fd-f03f-5a30-819e-1ef96d8002ab

STIX ID: report--c37045fd-f03f-5a30-819e-1ef96d8002ab

Feed Name: cybersecurityNews.com

Threat Score
55/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Attackers are registering Azure tenants that use the default *.onmicrosoft.com domain to send Microsoft invitation emails that include social-engineered messages urging recipients to call fraudulent support numbers (Telephone-Oriented Attack Delivery). Because the invites originate from Microsoft infrastructure they often bypass email gateways; the report advises deploying an Exchange Transport Rule with a regex to detect the onmicrosoft.com pattern, auditing partners that legitimately use the default domain, and whitelisting or requesting custom domains to prevent business disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.