Skip to main content

Rogue external MFA providers can steal passwords during logins

0
High
News
Published: 09/22/2026 (09/22/2026, 21:45:45 UTC)
Source: Bleeping Computer

Description

Security researchers disclosed an attack named TrustSink that allows attackers with privileged access to Microsoft Entra to register a rogue external MFA provider. This malicious provider can capture users' passwords during legitimate login attempts by displaying a fake Microsoft password prompt during the MFA step. The attack requires prior compromise of a highly privileged Entra account and abuses the trust placed in external MFA providers. Captured passwords remain vulnerable even after resets until the rogue provider is removed.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 22:02:52 UTC

Technical Analysis

TrustSink is a post-compromise attack demonstrated against Microsoft Entra's external MFA provider model. An attacker with Global Administrator or Authentication Policy Administrator privileges can register a rogue external MFA provider that intercepts the second-factor authentication step. Instead of a legitimate MFA challenge, the rogue provider presents a fake Microsoft password prompt, capturing the user's password in plaintext. It then returns a valid signed token to Entra, allowing the login to complete normally without alerting the user. The rogue provider persists in the authentication flow, capturing replacement passwords on subsequent logins until explicitly removed. The attack exploits the trust Microsoft places in configured external MFA providers and requires modification of the Authentication Methods Policy and creation of associated applications and consent grants.

Potential Impact

An attacker who has already compromised a highly privileged Microsoft Entra account can steal user passwords during legitimate login attempts by inserting a rogue external MFA provider. This allows persistent credential theft even after password resets, potentially leading to further account compromise and lateral movement within the organization. The attack does not provide initial access but enables ongoing credential harvesting from targeted users.

Defensive Guidance

Organizations should promptly remove any suspicious external MFA providers and their associated applications, keys, and redirect URIs before resetting affected users' passwords. Limit standing Global Administrator and Authentication Policy Administrator privileges to reduce risk. Employ phishing-resistant authentication methods such as FIDO2 or Windows Hello for Business to mitigate this attack vector. Monitor changes to the Authentication Methods Policy for unauthorized modifications. Since this is a post-compromise technique, focus on preventing initial privilege escalation and promptly detecting and responding to high-privilege account compromises.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins/","fetched":true,"fetchedAt":"2026-09-22T22:02:47.095Z","wordCount":1047}

Threat ID: 6ab2fb07f7a7c54106d67606

Added to database: 09/22/2026, 22:02:47 UTC

Last enriched: 09/22/2026, 22:02:52 UTC

Last updated: 09/23/2026, 02:59:21 UTC

Views: 11

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses