PROOFPOINT has uncovered a technique called OAuth client ID spoofing, allowing attackers to enumerate Microsoft Entra ID accounts and validate credentials without a successful sign-in. This method exploits the handling of OAuth client IDs and involves the creation of fake IDs that result in undetectable account enumeration. Two independent campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) have been identified, affecting over 3 million users across thousands of tenants.
Key actions to protect against this threat include monitoring for blank application names in logs and treating specific error codes as indicators of compromised credentials.