<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq" -->

---
title: Rogue external MFA providers can steal passwords during...
description: Varonis Threat Labs disclosed an attack technique called TrustSink that abuses Microsoft Entra&#x27;s external MFA provider feature to steal user passwords during...
canonical: https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Rogue external MFA providers can steal passwords during logins | daily.dev
og:description: Varonis Threat Labs disclosed an attack technique called TrustSink that abuses Microsoft Entra&#x27;s external MFA provider feature to steal user passwords during...
og:url: https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq
og:image: https://api.daily.dev/og/posts/UemKvH6kq.png
og:image:alt: Rogue external MFA providers can steal passwords during logins
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Rogue external MFA providers can steal passwords during logins

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 4 min read · 0 upvotes · 0 comments

## Summary

Varonis Threat Labs disclosed an attack technique called TrustSink that abuses Microsoft Entra's external MFA provider feature to steal user passwords during legitimate login flows. An attacker who already controls a highly privileged Entra account (Global Administrator or Authentication Policy Administrator) can register a rogue External Authentication Method that displays a convincing fake Microsoft password prompt after the user's first factor, capturing the password in plaintext, then returns a valid signed token so the login completes without error. The rogue provider stays registered and recaptures passwords even after users reset them, so it must be removed before rotating credentials. The technique builds on prior research by Dirk-Jan Mollema on rogue external MFA providers satisfying MFA checks with forged signed tokens. It is a post-compromise technique, not an initial-access exploit. Varonis recommends auditing Authentication Methods Policy changes, limiting standing admin privileges, and adopting phishing-resistant methods like FIDO2 or Windows Hello for Business.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/rogue-external-mfa-providers-can-steal-passwords-during-logins>

## Questions this post answers

### What is the TrustSink attack against Microsoft Entra external MFA providers?

TrustSink is a post-compromise technique discovered by Varonis Threat Labs in which an attacker who already controls a Global Administrator or Authentication Policy Administrator account registers a rogue external MFA provider in Entra. The provider injects a fake Microsoft password prompt during the legitimate MFA step, captures the password in plaintext, then returns a valid signed token so the login completes normally without any visible error.

_Security teams tracking identity-provider attack techniques like this can follow developments on daily.dev._

### If a user resets their password after being phished by a rogue Entra MFA provider, does that stop the attacker from stealing the new password?

No, resetting the password alone does not help. Because the rogue external MFA provider stays registered in the tenant's Authentication Methods Policy, it remains in the authentication flow and recaptures the replacement password the next time the user signs in. Administrators must remove the malicious provider, its application, keys, and redirect URIs before rotating any affected credentials.

_Admins responding to credential-theft incidents can track remediation guidance like this on daily.dev._

### What privileges does an attacker need to carry out the TrustSink Entra MFA attack?

The attacker needs to already control a Global Administrator or Authentication Policy Administrator account in Microsoft Entra, since registering the malicious external authentication method requires modifying the Authentication Methods Policy and creating an application, service principal, and consent grant. This makes TrustSink a post-compromise technique rather than an initial-access exploit.

_Teams hardening Entra privilege models can keep up with attacks like this via daily.dev._

## Similar posts on daily.dev

- [MFA's Weakest Link: Account Recovery Is the New Attack Path](https://daily.dev/posts/mfa-s-weakest-link-account-recovery-is-the-new-attack-path-lsgvf4iqr) · BleepingComputer · 0 upvotes · 0 comments
- [How to Prevent Vishing Attacks Targeting Okta and other IDPs](https://daily.dev/posts/how-to-prevent-vishing-attacks-targeting-okta-and-other-idps-clrcoqufm) · Security Boulevard · 0 upvotes · 0 comments
- [Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass](https://daily.dev/posts/device-code-phishing-turning-a-convenience-feature-into-an-mfa-bypass-ahmi9uip7) · Trend Micro · 0 upvotes · 0 comments
- [Password spraying attacks surge 155x as hackers exploit MFA gaps](https://daily.dev/posts/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps-itszhorqa) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#cloud](https://daily.dev/tags/cloud), [#authentication](https://daily.dev/tags/authentication), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Rogue external MFA providers can steal passwords during logins","url":"https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq"},"datePublished":"2026-09-22T21:48:00.842Z","dateModified":"2026-09-22T22:08:58.676Z","description":"Varonis Threat Labs disclosed an attack technique called TrustSink that abuses Microsoft Entra's external MFA provider feature to steal user passwords during...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c9e09a72ddf8acd24552b0a48f053ef9?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/c9e09a72ddf8acd24552b0a48f053ef9?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,cloud,authentication,phishing","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Rogue external MFA providers can steal passwords during logins"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/rogue-external-mfa-providers-can-steal-passwords-during-logins-uemkvh6kq#faq","mainEntity":[{"@type":"Question","name":"What is the TrustSink attack against Microsoft Entra external MFA providers?","acceptedAnswer":{"@type":"Answer","text":"TrustSink is a post-compromise technique discovered by Varonis Threat Labs in which an attacker who already controls a Global Administrator or Authentication Policy Administrator account registers a rogue external MFA provider in Entra. The provider injects a fake Microsoft password prompt during the legitimate MFA step, captures the password in plaintext, then returns a valid signed token so the login completes normally without any visible error. Security teams tracking identity-provider attack techniques like this can follow developments on daily.dev."}},{"@type":"Question","name":"If a user resets their password after being phished by a rogue Entra MFA provider, does that stop the attacker from stealing the new password?","acceptedAnswer":{"@type":"Answer","text":"No, resetting the password alone does not help. Because the rogue external MFA provider stays registered in the tenant's Authentication Methods Policy, it remains in the authentication flow and recaptures the replacement password the next time the user signs in. Administrators must remove the malicious provider, its application, keys, and redirect URIs before rotating any affected credentials. Admins responding to credential-theft incidents can track remediation guidance like this on daily.dev."}},{"@type":"Question","name":"What privileges does an attacker need to carry out the TrustSink Entra MFA attack?","acceptedAnswer":{"@type":"Answer","text":"The attacker needs to already control a Global Administrator or Authentication Policy Administrator account in Microsoft Entra, since registering the malicious external authentication method requires modifying the Authentication Methods Policy and creating an application, service principal, and consent grant. This makes TrustSink a post-compromise technique rather than an initial-access exploit. Teams hardening Entra privilege models can keep up with attacks like this via daily.dev."}}]}
```

