securityonline.info 7/20/2026, 2:50:57 PM · external

Attackers exploit OAuth IDs to check Microsoft Entra accounts

Attackers exploit OAuth IDs to check Microsoft Entra accounts
Developing story campaign 2 articles tracked
OAuth Client ID spoofing enables stealthy enumeration of Microsoft Entra ID accounts
CyberSIXT Evidence Panel
Primary Source proofpoint.com

PROOFPOINT has uncovered a technique called OAuth client ID spoofing, allowing attackers to enumerate Microsoft Entra ID accounts and validate credentials without a successful sign-in. This method exploits the handling of OAuth client IDs and involves the creation of fake IDs that result in undetectable account enumeration. Two independent campaigns (UNK_pyreq2323 and UNK_OutFlareAZ) have been identified, affecting over 3 million users across thousands of tenants.

Key actions to protect against this threat include monitoring for blank application names in logs and treating specific error codes as indicators of compromised credentials.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline