Zoom Infrastructure Abused in New TOAD Phishing Campaign Bypassing Email Security Controls
A newly observed phishing campaign demonstrates how attackers are increasingly abusing legitimate SaaS infrastructure to bypass traditional email security controls. The campaign leverages Zoom’s own authentication emails as part of a Telephone-Oriented Attack Delivery (TOAD) technique, allowing social engineering payloads to reach victims through fully authenticated messages.
Unlike classic phishing attempts that rely on spoofed domains or malicious links, this attack uses Zoom’s official email systems, causing the messages to pass SPF, DKIM, and DMARC checks and evade Secure Email Gateways that trust verified senders.
How the Attack Works
The attack chain is simple, quiet, and effective:
- Account creation
The attacker registers a legitimate Zoom account using an email address they control. - Payload placement in display name
Instead of a normal account name, the attacker inserts a fraudulent message into the Zoom account’s display name, such as a fake payment alert combined with a phone number. - Triggering a legitimate OTP email
A standard Zoom login attempt triggers an official One-Time Password email from Zoom’s infrastructure. - Phishing delivery
The victim receives an authentic Zoom email where the display name is rendered as part of the email body, exposing the social engineering message.
No malicious links. No attachments. No spoofing. The email itself is technically clean. The payload exists entirely within trusted content.
Why Traditional Controls Fail
This campaign highlights a growing blind spot in email security:
The email originates from a trusted domain
Authentication headers are valid
There is no malicious URL or executable content
The message relies purely on contextual manipulation
Because most controls focus on who sent the message, rather than what the message is trying to make the user do, these attacks frequently pass through automated defenses.
This is a textbook example of living-off-the-land abuse, where attackers weaponize standard platform features instead of exploiting software vulnerabilities.
Why This Matters
This technique erodes one of the strongest trust signals users rely on. A verified sender. When users see an email that is genuinely from Zoom, their suspicion drops. Attackers exploit this trust to push victims toward urgent, phone-based social engineering.
The attack also illustrates a broader trend. Modern phishing does not always require malware, fake domains, or technical exploitation. In many cases, legitimate systems are behaving exactly as designed, but are being misused in ways security controls were not built to detect.
DIAMATIX Perspective
From a defensive standpoint, this campaign reinforces a critical shift organizations must make. Email security can no longer rely solely on sender reputation and authentication checks.
Security teams should:
Treat verified SaaS emails as potential attack surfaces, not implicit trust anchors
Expand phishing detection to include content intent analysis, not just indicators of compromise
Train users to question urgency and cross-service inconsistencies (e.g. Zoom email referencing PayPal activity)
Review alert escalation playbooks for TOAD-style attacks that lack traditional technical indicators
As attackers increasingly exploit trusted platforms, detection must evolve from validating infrastructure to understanding attacker intent.
Trusted · Innovative · Vigilant
Used Sources
Prophet Security. Technical analysis of Zoom-based TOAD phishing campaign
Zoom. Official authentication email behavior and account display name rendering
Industry research on TOAD (Telephone-Oriented Attack Delivery) techniques and living-off-the-land phishing






