Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What should organisations do when TOAD attacks are…
Threats, Abuse & Incident Response

What should organisations do when TOAD attacks are already reaching employees?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

When TOAD attacks are reaching employees, organisations should tighten call blocking, increase email filtering sensitivity, and review the messages, numbers, and domains involved. They should also use incident reporting data to identify repeat targets and strengthen awareness training for those users. The goal is to reduce both successful engagement and the chance that attackers can pivot from voice to email.

Why TOAD Response Needs to Shift From Blocking to Pattern Triage

Once TOAD attacks are already landing in inboxes and phones, the question is no longer just whether to block them. The practical issue is identifying the delivery pattern, the repeated lures, and the channels attackers are using so the organisation can reduce repeat exposure and stop the same campaign from finding new victims.

That means treating inbound telephone and email activity as one coordinated abuse path. If a call is used to prime trust and the follow-up email completes the fraud, defensive tuning has to work across both channels rather than as separate problems.

Reviewing the messages, numbers, and domains involved helps separate a one-off nuisance from an active campaign with reusable infrastructure. Where the same caller IDs, voicemail patterns, sender domains, or lookalike brands keep appearing, the organisation has enough evidence to tighten controls on the specific route being abused.

How to Reduce Repeat Engagement Across Voice and Email

The fastest value usually comes from raising friction at the point of contact. Tighten call blocking rules for repeat numbers, suspicious ranges, and patterns associated with impersonation or callback scams, then align email filtering so the same campaign is not simply switching channels after a blocked call. A coordinated view is especially important when the phone call is the trust hook and the email carries the payload.

Incident reporting data is also operationally useful here because it shows who is being targeted repeatedly, which messages are getting through, and where awareness messages need to be more specific. That evidence supports targeted follow-up with users who are seeing the same lures, instead of broad training that may miss the actual technique in play.

CISA cyber threat advisories are useful for matching the campaign style to known impersonation and social-engineering patterns, while MITRE ATT&CK Enterprise Matrix helps teams describe the follow-on tactics when a voice pretext is used to support credential access or lateral movement. If the same campaign is persisting through multiple contact methods, the defensive objective is to reduce successful engagement, not just to stop one delivery event.

What Changes When Employees Are the Target of the Campaign

Employee-facing TOAD attacks often succeed because the attacker is not relying on a single weak control. The call creates urgency or authority, then the email extends the interaction, and the user becomes the bridge between both. That is why simply blocking calls or only tuning email filters leaves gaps if the other channel is still open.

Where a recurring campaign is visible, the organisation should treat repeat-target users as a distinct control population. Those people often need stronger warning cues, faster reporting paths, and more specific examples of the exact lures being used. The useful question is not whether awareness exists in general, but whether the current campaign has been made harder for the same users to engage with twice.

Risk and Threat Considerations

TOAD campaigns create a compound exposure because one channel is used to legitimise the other. If the phone step builds trust and the email step delivers the fraud, the attacker can exploit weak coordination between telephony controls, mail filtering, and user reporting.

Failure mechanism: Repeated caller IDs, spoofed numbers, lookalike domains, and message templates remain reachable long enough for users to respond, which allows the attacker to pivot from voice to email and keep iterating on the same lure.

Impact: Successful engagement can lead to credential capture, fraudulent payments, account compromise, or further social engineering against the same employees and teams.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1566 — PhishingTOAD relies on social-engineering delivery and user interaction.
T1589 — Gather Victim Identity InformationAttackers use employee-targeted lures and callback context to personalise contact.
Recommendation — Map the campaign to phishing tactics and tune detections for delivery, pretexting, and follow-on access attempts. Hunt for victim-targeting patterns and remove exposed employee contact details that aid pretexting.
CIS Controls v8CIS-9 — Email and Web Browser ProtectionsEmail filtering and suspicious domain handling are central to stopping the follow-on payload.
CIS-17 — Incident Response ManagementReporting data and repeat-target analysis depend on disciplined incident handling.
Recommendation — Harden mail security controls and block malicious or lookalike sender infrastructure quickly. Use incident reports to identify repeat targets and feed campaign indicators into response playbooks.
NIST CSF 2.0PR.AT-01 — All users are informed and trainedTargeted awareness training is needed when employees are repeatedly engaged by the same campaign.
DE.CM-09 — Continuous Monitoring of Communications and System UseReviewing messages, numbers, and domains requires ongoing monitoring of communication abuse.
Recommendation — Refresh user training with the current lure pattern and reporting path. Monitor communications for repeated numbers, sender domains, and lure variants to support rapid blocking.

Practitioner Guidance

What to prioritise: Prioritise the exact numbers, sender domains, and message themes already appearing in reports, because that is where you can reduce repeat success fastest. If the same lure is resurfacing, the campaign is active enough to justify tighter filtering and targeted user follow-up.

What to verify: Check whether call blocking, mail filtering, and incident reporting are being reviewed together. A disconnected response often leaves the voice channel open after the mail side improves, or vice versa.

Practitioner takeaway: The main goal is campaign suppression across both channels, not perfect elimination of every TOAD attempt. The best signal of progress is fewer repeated contacts succeeding against the same users and fewer opportunities for attackers to use one channel to reinforce the other.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org