Hackers find a new trick to collect Microsoft Entra user data without raising red flags
ID: dd7fae19-cc19-5b83-b715-0ff3dc4d8190
STIX ID: report--dd7fae19-cc19-5b83-b715-0ff3dc4d8190
Feed Name: Proofpoint Blog
Threat Score
Proofpoint observed multiple large-scale campaigns abusing spoofed OAuth client IDs against Microsoft Entra (Azure AD) to enumerate user accounts and infer password validity without generating successful sign-in events. Attackers used millions of spoofed IDs across thousands of organizations, enabling stealthy reconnaissance that can bypass trend-based monitoring and conditional-access policies; defenders are advised to monitor for blank application IDs and AADSTS700016 errors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
