{"id":265,"date":"2026-02-09T15:03:55","date_gmt":"2026-02-09T20:03:55","guid":{"rendered":"https:\/\/freshphish.info\/?p=265"},"modified":"2026-02-09T15:05:25","modified_gmt":"2026-02-09T20:05:25","slug":"toad-sent-through-microsoft","status":"publish","type":"post","link":"https:\/\/freshphish.info\/?p=265","title":{"rendered":"TOAD Sent Through Microsoft"},"content":{"rendered":"\n<p>Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on the message at the top of the email. The links don\u2019t appear to be malicious per se. The emails are TOADs, providing a phone number to call for a refund scam. That said, I don\u2019t want these emails containing links to potentially dangerous sites in our users mailboxes.<\/p>\n\n\n\n<p>Microsoft &#8220;Invitations&#8221; are sent from &#8220;invites@microsoft.com&#8221;, which is a legitimate Microsoft service so we can&#8217;t just block all of these emails.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"993\" height=\"615\" src=\"https:\/\/freshphish.info\/wp-content\/uploads\/2026\/02\/Untitled-1.png\" alt=\"\" class=\"wp-image-269\" srcset=\"https:\/\/freshphish.info\/wp-content\/uploads\/2026\/02\/Untitled-1.png 993w, https:\/\/freshphish.info\/wp-content\/uploads\/2026\/02\/Untitled-1-300x186.png 300w, https:\/\/freshphish.info\/wp-content\/uploads\/2026\/02\/Untitled-1-768x476.png 768w\" sizes=\"auto, (max-width: 993px) 100vw, 993px\" \/><\/figure>\n","protected":false},"excerpt":{"rendered":"<p>Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a<\/p>\n<p><a href=\"https:\/\/freshphish.info\/?p=265\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\">TOAD Sent Through Microsoft<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[12],"tags":[19,4,49],"class_list":["post-265","post","type-post","status-publish","format-standard","hentry","category-phish","tag-microsoft","tag-phish","tag-toad"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.9 - aioseo.com -->\n\t<meta name=\"description\" content=\"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Matt\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/freshphish.info\/?p=265\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.9\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Fresh Phish - All the freshest phish\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"TOAD Sent Through Microsoft - Fresh Phish\" \/>\n\t\t<meta property=\"og:description\" content=\"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/freshphish.info\/?p=265\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-02-09T20:03:55+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-02-09T20:05:25+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"TOAD Sent Through Microsoft - Fresh Phish\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#blogposting\",\"name\":\"TOAD Sent Through Microsoft - Fresh Phish\",\"headline\":\"TOAD Sent Through Microsoft\",\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/freshphish.info\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Untitled-1.png\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265\\\/#articleImage\",\"width\":993,\"height\":615},\"datePublished\":\"2026-02-09T15:03:55-05:00\",\"dateModified\":\"2026-02-09T15:05:25-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#webpage\"},\"articleSection\":\"Phish, Microsoft, phish, TOAD\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/freshphish.info\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"position\":2,\"name\":\"Phish\",\"item\":\"https:\\\/\\\/freshphish.info\\\/?cat=12\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#listItem\",\"name\":\"TOAD Sent Through Microsoft\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#listItem\",\"position\":3,\"name\":\"TOAD Sent Through Microsoft\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?cat=12#listItem\",\"name\":\"Phish\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?author=1\",\"name\":\"Matt\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Matt\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#webpage\",\"url\":\"https:\\\/\\\/freshphish.info\\\/?p=265\",\"name\":\"TOAD Sent Through Microsoft - Fresh Phish\",\"description\":\"Just an FYI about a new type of phish we\\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?p=265#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/?author=1#author\"},\"datePublished\":\"2026-02-09T15:03:55-05:00\",\"dateModified\":\"2026-02-09T15:05:25-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/freshphish.info\\\/#website\",\"url\":\"https:\\\/\\\/freshphish.info\\\/\",\"name\":\"Fresh Phish\",\"description\":\"All the freshest phish\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/freshphish.info\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"TOAD Sent Through Microsoft - Fresh Phish","description":"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on","canonical_url":"https:\/\/freshphish.info\/?p=265","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/freshphish.info\/?p=265#blogposting","name":"TOAD Sent Through Microsoft - Fresh Phish","headline":"TOAD Sent Through Microsoft","author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"publisher":{"@id":"https:\/\/freshphish.info\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/freshphish.info\/wp-content\/uploads\/2026\/02\/Untitled-1.png","@id":"https:\/\/freshphish.info\/?p=265\/#articleImage","width":993,"height":615},"datePublished":"2026-02-09T15:03:55-05:00","dateModified":"2026-02-09T15:05:25-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/freshphish.info\/?p=265#webpage"},"isPartOf":{"@id":"https:\/\/freshphish.info\/?p=265#webpage"},"articleSection":"Phish, Microsoft, phish, TOAD"},{"@type":"BreadcrumbList","@id":"https:\/\/freshphish.info\/?p=265#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","position":1,"name":"Home","item":"https:\/\/freshphish.info","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","position":2,"name":"Phish","item":"https:\/\/freshphish.info\/?cat=12","nextItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=265#listItem","name":"TOAD Sent Through Microsoft"},"previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?p=265#listItem","position":3,"name":"TOAD Sent Through Microsoft","previousItem":{"@type":"ListItem","@id":"https:\/\/freshphish.info\/?cat=12#listItem","name":"Phish"}}]},{"@type":"Organization","@id":"https:\/\/freshphish.info\/#organization","name":"Fresh Phish","description":"All the freshest phish","url":"https:\/\/freshphish.info\/"},{"@type":"Person","@id":"https:\/\/freshphish.info\/?author=1#author","url":"https:\/\/freshphish.info\/?author=1","name":"Matt","image":{"@type":"ImageObject","@id":"https:\/\/freshphish.info\/?p=265#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/82f14a734f69eb729d8b59b4a2438ea6e14bd793d23b22d4299ec5228b06260a?s=96&d=mm&r=g","width":96,"height":96,"caption":"Matt"}},{"@type":"WebPage","@id":"https:\/\/freshphish.info\/?p=265#webpage","url":"https:\/\/freshphish.info\/?p=265","name":"TOAD Sent Through Microsoft - Fresh Phish","description":"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/freshphish.info\/#website"},"breadcrumb":{"@id":"https:\/\/freshphish.info\/?p=265#breadcrumblist"},"author":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"creator":{"@id":"https:\/\/freshphish.info\/?author=1#author"},"datePublished":"2026-02-09T15:03:55-05:00","dateModified":"2026-02-09T15:05:25-05:00"},{"@type":"WebSite","@id":"https:\/\/freshphish.info\/#website","url":"https:\/\/freshphish.info\/","name":"Fresh Phish","description":"All the freshest phish","inLanguage":"en-US","publisher":{"@id":"https:\/\/freshphish.info\/#organization"}}]},"og:locale":"en_US","og:site_name":"Fresh Phish - All the freshest phish","og:type":"article","og:title":"TOAD Sent Through Microsoft - Fresh Phish","og:description":"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on","og:url":"https:\/\/freshphish.info\/?p=265","article:published_time":"2026-02-09T20:03:55+00:00","article:modified_time":"2026-02-09T20:05:25+00:00","twitter:card":"summary_large_image","twitter:title":"TOAD Sent Through Microsoft - Fresh Phish","twitter:description":"Just an FYI about a new type of phish we\u2019ve seen over the past couple of months. I implemented a block specifically for this phish. The emails are sourced from Microsoft systems and they link to subdomains in the legitimate onmicrosoft.com domain. Note that even Microsoft appears to be aware of these emails based on"},"aioseo_meta_data":{"post_id":"265","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-02-09 20:03:55","updated":"2026-02-09 20:12:45","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/freshphish.info\/?cat=12\" title=\"Phish\">Phish<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tTOAD Sent Through Microsoft\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/freshphish.info"},{"label":"Phish","link":"https:\/\/freshphish.info\/?cat=12"},{"label":"TOAD Sent Through Microsoft","link":"https:\/\/freshphish.info\/?p=265"}],"_links":{"self":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/265","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=265"}],"version-history":[{"count":2,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/265\/revisions"}],"predecessor-version":[{"id":270,"href":"https:\/\/freshphish.info\/index.php?rest_route=\/wp\/v2\/posts\/265\/revisions\/270"}],"wp:attachment":[{"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/freshphish.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}