There is a new Proofpoint report highlighting a credential theft operation involving OAuth Client ID spoofing, raising significant concerns about identity security:.
Key Takeaways
- Proofpoint has observed OAuth client ID spoofing emerging as a novel technique, increasingly leveraged in cloud campaigns.
- Microsoft Entra ID returns different responses depending on whether a supplied OAuth client ID is valid and whether it corresponds to a registered application.
- This behavior enables account enumeration without a registered OAuth application and allows attackers to infer password validity or account state without generating a successful sign‑in event.
- Researchers observed multiple campaigns at scale abusing spoofed OAuth application identifiers, with distinct tooling, infrastructure, and execution patterns indicating independent adoption by multiple threat actors.
- To detect similar activity, defenders should monitor sign-in logs for events without an application name, which may indicate spoofed client IDs.
Kevin Surace, CEO, TokenCore had this comment:
Attackers submit stolen usernames and passwords to Microsoft’s OAuth endpoint while continually inventing fake client IDs. Differences in Microsoft’s error responses can reveal whether an account exists and whether the password is correct, allowing attackers to quietly identify working credentials before attempting account takeover.
Biometric assured identity stops this attack cold. Even when the attacker has confirmed the correct username and password, the account cannot be accessed without the authorized biometric, the registered physical Token device and the cryptographic credential stored inside it.
The danger is that attackers can validate enormous lists of stolen credentials without generating the successful sign in events that many security tools are designed to detect. Confirmed credentials can then be used to target email, cloud applications, administrative accounts, VPNs and other enterprise systems.
Biometric assured identity makes those credentials worthless. A correct password is no longer treated as proof of identity, so the attacker cannot complete the login, establish a foothold or move laterally through the organization.
Credential testing and password spraying are not new, but the use of constantly changing fictional OAuth client IDs is a clever new way to obscure the activity and exploit gaps in identity telemetry. It is an evolution of credential theft designed to make password validation quieter and more scalable.
The larger lesson is that any architecture still relying on passwords as meaningful proof of identity remains vulnerable. Biometric assured identity ends that dependency and stops the operation from progressing from credential validation to account compromise.
Organizations should immediately investigate unusual ROPC activity, unknown client IDs, blank application names and large numbers of OAuth errors across multiple accounts. They should disable ROPC and other password based legacy flows wherever possible, reset exposed credentials and require phishing resistant authentication throughout the environment.
Most importantly, enterprises should deploy biometric assured identity such as Token across their workforce. Token requires the authorized fingerprint, the registered hardware device, physical proximity and a valid cryptographic exchange with the legitimate service, leaving the attacker with nothing they can steal, spoof, relay or reuse.
This attack demonstrates why passwords and legacy MFA are no longer defensible for protecting valuable enterprise systems. Attackers may be able to determine that a password is correct, but biometric assured identity ensures that the password still gets them nowhere.
Now is a good time to move to passwordless authentication solutions. Failing that, modern MFA solutions is another option to protect organizations from threats of all sorts.
Related
This entry was posted on July 15, 2026 at 12:04 pm and is filed under Commentary with tags Proofpoint. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
OAuth Client ID spoofing lets attackers bypass security
There is a new Proofpoint report highlighting a credential theft operation involving OAuth Client ID spoofing, raising significant concerns about identity security:.
Key Takeaways
Kevin Surace, CEO, TokenCore had this comment:
Attackers submit stolen usernames and passwords to Microsoft’s OAuth endpoint while continually inventing fake client IDs. Differences in Microsoft’s error responses can reveal whether an account exists and whether the password is correct, allowing attackers to quietly identify working credentials before attempting account takeover.
Biometric assured identity stops this attack cold. Even when the attacker has confirmed the correct username and password, the account cannot be accessed without the authorized biometric, the registered physical Token device and the cryptographic credential stored inside it.
The danger is that attackers can validate enormous lists of stolen credentials without generating the successful sign in events that many security tools are designed to detect. Confirmed credentials can then be used to target email, cloud applications, administrative accounts, VPNs and other enterprise systems.
Biometric assured identity makes those credentials worthless. A correct password is no longer treated as proof of identity, so the attacker cannot complete the login, establish a foothold or move laterally through the organization.
Credential testing and password spraying are not new, but the use of constantly changing fictional OAuth client IDs is a clever new way to obscure the activity and exploit gaps in identity telemetry. It is an evolution of credential theft designed to make password validation quieter and more scalable.
The larger lesson is that any architecture still relying on passwords as meaningful proof of identity remains vulnerable. Biometric assured identity ends that dependency and stops the operation from progressing from credential validation to account compromise.
Organizations should immediately investigate unusual ROPC activity, unknown client IDs, blank application names and large numbers of OAuth errors across multiple accounts. They should disable ROPC and other password based legacy flows wherever possible, reset exposed credentials and require phishing resistant authentication throughout the environment.
Most importantly, enterprises should deploy biometric assured identity such as Token across their workforce. Token requires the authorized fingerprint, the registered hardware device, physical proximity and a valid cryptographic exchange with the legitimate service, leaving the attacker with nothing they can steal, spoof, relay or reuse.
This attack demonstrates why passwords and legacy MFA are no longer defensible for protecting valuable enterprise systems. Attackers may be able to determine that a password is correct, but biometric assured identity ensures that the password still gets them nowhere.
Now is a good time to move to passwordless authentication solutions. Failing that, modern MFA solutions is another option to protect organizations from threats of all sorts.
Share this:
Like this:
Related
This entry was posted on July 15, 2026 at 12:04 pm and is filed under Commentary with tags Proofpoint. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.