Phishing Frenzy: Brand Impersonations and TOAD Attacks on the Rise in 2025!

Cybersecurity researchers warn of phishing campaigns using brand impersonation to trick victims into calling threat actors. Known as Telephone-Oriented Attack Delivery, or TOAD, these scams convince targets they’re resolving issues by calling fake support lines, leading to data theft or malware installation. Microsoft and Docusign are the most impersonated brands.

Pro Dashboard

Hot Take:

Who knew that a phone call could be your cyber downfall? TOAD attacks are hopping all over the place, and they’re as slick as a frog in a grease trap. It seems like every brand you trust is now a possible phishing bait, so keep your eyes peeled and your phone on airplane mode!

Key Points:

  • TOAD attacks use phone calls to impersonate popular brands and trick victims into revealing sensitive information.
  • Microsoft, Docusign, NortonLifeLock, PayPal, and Geek Squad are the most impersonated brands in these phishing campaigns.
  • Phishing emails often include PDF attachments with QR codes leading to fake login pages.
  • Threat actors employ VoIP numbers and social engineering tactics to remain anonymous and convincing.
  • New research indicates that AI-generated phishing scams are on the rise, using unregistered domains and fake GitHub projects.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?