08/12/25

Let’s talk about TOAD phishing scams

It’s time to talk about an old topic in a whole new way. Yes, this is a piece on the next evolution of wire fraud and cybercriminals. Through AI and other advances, scammers are now using phone calls as the next way to get you to fall for a phishing attack, thanks to a new tactic called Telephone Oriented Attack Delivery, or TOAD for short, because they use an email to get you to call a scam number yourself.

This TOAD warning doesn’t specifically apply only to real estate. In fact, you’ll probably recognize this scam from other parts of life once we dive into the topic. However, it’s only a matter of time before it becomes the preferred weapon of fraudsters if it continues to prove successful, which is exactly what we’re trying to stop.

What is a TOAD scam? It usually begins with an email or text message urging the victim to dial a phone number provided within the message, which, of course, is a departure from the suspicious link playbook. Often, that message will supposedly come from a reputable company, like PayPal or Amazon and/or include a fake invoice simply requesting that the receiver call a provided phone number. 

But here’s the twist: the phone number goes straight to the scammer.

Once the victim makes the call, attackers pose as trusted entities, such as IT support teams to banks, using caller-ID spoofing or AI-cloned voices to appear legitimate. The goal? The same as it always is to get the target to reveal sensitive personal or financial information or simply send money using fear and urgency.

Why do they work? In the first couple of years of existence, these scams have been highly successful. Why? According to an advisory from the state of Wyoming, it’s because this new tactic “circumvents email security filters, catches victims off-guard since they initiated the contact themselves and abuses the natural human tendency to trust real-time voice interactions.” In other words, these scammers have found a new way to trick people over the phone and will keep doing so until the issue becomes more publicly known. Plus, not including a malicious link means that the scam doesn’t raise one of the main red flags of a traditional phishing attack. 

How many of these TOAD scams are happening? A lot. According to this piece, experts estimate it at 10 million attempts each day, with these criminal rings now recruiting “specialists” who know how to make these scams even more lucrative.

  • How can we protect ourselves and others? That’s the easy part. Do what we’ve always done regarding scams: Be wary of any unsolicited email or texts, even if they appear to come from a legitimate sender.
  • If you are calling someone because of a message they sent you, make sure the number is legitimate.
  • Never give personal information to someone you don’t know until you verify they are who they say they are.
  • Keep spreading the word and practice caution and vigilance ourselves. The more people know about TOAD tactics, the harder they become to pull off.

The bottom line is scammers will continue to target us and people we know, whether it’s through a real estate transaction or another avenue. It’s key for us to stay cyber aware and never let our guard down.

Fraud of any kind is not the most fun topic to talk about, but our teams are always here to address the topic with you. That conversation could be what it takes to keep your next transaction safe and secure, and that is always our ultimate goal.      

0 0 votes
Article Rating
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted