TrustSink Attack Lets Rogue MFA Providers Steal Passwords in Microsoft Entra ID
Security firm Varonis has disclosed a technique called TrustSink that exploits Microsoft Entra ID's External Authentication Methods feature to steal user passwords during sign-in. An attacker with sufficient privileges, such as a Global Administrator, can register a malicious external MFA provider that intercepts the authentication flow and presents a fake Microsoft password screen to the target user. The rogue provider captures the plaintext password, then returns a valid signed token to Entra so the login completes successfully without raising any visible alert to the user. Varonis demonstrated the attack in a test tenant, though no real-world exploitation has been confirmed as of the disclosure date of September 16, 2026. Recommended mitigations include restricting authentication method modification privileges, monitoring policy changes and consent grants, and adopting phishing-resistant credentials such as FIDO2 or Windows Hello for Business.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in