Skip to content
Tech News
← Back to articles

Varonis details TrustSink attack abusing Microsoft Entra external MFA providers

read original get YubiKey 5C NFC Security Key → more articles
GoKawiil Brief

Varonis Threat Labs disclosed a technique called TrustSink in which an attacker with a highly privileged Entra account registers a rogue external MFA provider that inserts a fake password prompt into legitimate login flows, capturing users' plaintext passwords. The rogue provider still returns a valid signed token to Entra, so the sign-in completes normally with no visible error, and resetting a stolen password does not remove the malicious provider from the authentication flow. Varonis says the method could work with any authentication system using this external MFA model but demonstrated it specifically against Microsoft Entra.

Why It Matters

GoKawiil's interpretation of the reporting above, not reported fact.

Because the attack requires prior privileged access, it functions as a persistence and credential-harvesting mechanism rather than an initial breach vector, potentially letting attackers quietly collect fresh passwords even after incident responders think they've remediated a compromise. The finding suggests organizations relying on external MFA integrations may need additional monitoring of registered authentication providers, since standard password resets alone would not eliminate the threat.

Key Takeaways
Worth a Look

YubiKey 5C NFC Security Key — This attack shows why phishable password prompts and token-based MFA can be undermined by rogue providers. A hardware security key like the YubiKey 5C NFC uses phishing-resistant FIDO2 authentication, so credentials can't be captured through fake login flows. It's a practical step for individuals and admins wanting stronger protection beyond app-based or provider-based MFA.

See YubiKey 5C NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-22

Published there as: “Rogue external MFA providers can steal passwords during logins”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.