Phishing Frenzy: Brand Impersonations and TOAD Attacks on the Rise in 2025!
Cybersecurity researchers warn of phishing campaigns using brand impersonation to trick victims into calling threat actors. Known as Telephone-Oriented Attack Delivery, or TOAD, these scams convince targets they’re resolving issues by calling fake support lines, leading to data theft or malware installation. Microsoft and Docusign are the most impersonated brands.

Hot Take:
Who knew that a phone call could be your cyber downfall? TOAD attacks are hopping all over the place, and they’re as slick as a frog in a grease trap. It seems like every brand you trust is now a possible phishing bait, so keep your eyes peeled and your phone on airplane mode!
Key Points:
- TOAD attacks use phone calls to impersonate popular brands and trick victims into revealing sensitive information.
- Microsoft, Docusign, NortonLifeLock, PayPal, and Geek Squad are the most impersonated brands in these phishing campaigns.
- Phishing emails often include PDF attachments with QR codes leading to fake login pages.
- Threat actors employ VoIP numbers and social engineering tactics to remain anonymous and convincing.
- New research indicates that AI-generated phishing scams are on the rise, using unregistered domains and fake GitHub projects.
Already a member? Log in here