logo

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

ID: 66420fd0-aae4-5a96-b704-1150563fd127

STIX ID: report--66420fd0-aae4-5a96-b704-1150563fd127

Feed Name: Proofpoint Blog

Threat Score
78/100

Date Published: 2026-07-14

Date Updated: 2026-07-17

...
...

**Proofpoint warned that multiple threat actors are weaponizing an Entra ID telemetry blind spot — "OAuth client ID spoofing" — which allows attackers to enumerate accounts and validate stolen credentials without generating successful sign-ins.** Two observed campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) targeted millions of users across thousands of tenants using spoofed UUID client_ids via the ROPC flow and distributed infrastructure (AWS, Cloudflare), enabling large-scale, stealthy credential validation that can bypass application-scoped Conditional Access and typical sign-in detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.