logo

OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials

ID: c25453e9-77de-57ad-99e5-cabbb9eeecea

STIX ID: report--c25453e9-77de-57ad-99e5-cabbb9eeecea

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

Proofpoint has identified active campaigns exploiting a technique called "OAuth client ID spoofing" to enumerate user accounts and validate stolen credentials in Microsoft Entra ID environments while avoiding successful sign-in telemetry. Two large campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) targeted millions of users across thousands of tenants, using randomized or modified client IDs to evade detections and rate-limiting, enabling large-scale credential checking and stealthy access reconnaissance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.