Cybersecurity Threat Advisory: TrustSink Turns Microsoft Entra ID's MFA Against You to Steal Passwords
Threat update
Researchers have demonstrated a new attack technique called TrustSink that abuses the multi-factor authentication (MFA) features in Microsoft Entra ID, the identity service behind Microsoft 365. An attacker who gains control of a high-level admin account can quietly add a fake MFA provider to the tenant. From then on, every time a user signs in, that fake provider captures their password in plain text while the login completes normally. Organizations that use Microsoft 365 should review their Entra ID authentication settings and lock down admin accounts now.
Technical Detail and Additional Info
What is the threat?
TrustSink was developed and disclosed by Varonis Threat Labs in September 2026. It does not rely on a software bug. Instead, it misuses a legitimate Entra ID feature called External Authentication Methods (EAM), which lets organizations plug in third-party MFA providers. Entra ID trusts whatever answer that external provider sends back, and TrustSink exploits that trust.
The attack works in four stages:
- Admin takeover: The attacker first compromises a privileged account, specifically a Global Administrator or Authentication Policy Administrator.
- Rogue provider registered: Using that account, the attacker registers a malicious app as an external MFA method in the tenant's authentication policy.
- Fake password prompt: When a user signs in and MFA is triggered, they are sent to the attacker's provider, which shows a near-perfect copy of the Microsoft password page. The user re-enters their password, and it is sent to the attacker along with a timestamp and the user's IP address.
- Login completes normally: At the same time, the rogue provider sends Entra ID a signed message saying MFA succeeded. The user lands in their app as expected and has no reason to suspect anything went wrong.
As Varonis put it, "every sign-in completed normally while our server received passwords with timestamps and source IP addresses."
Why is it noteworthy?
Most credential theft depends on tricking users with phishing emails or fake websites. TrustSink is different because the trap sits inside the organization's own, legitimate Microsoft sign-in process. Users are on the real Microsoft login page and pass through an MFA step their company appears to require, so there is nothing unusual for them to notice.
The technique is also persistent. Resetting a user's password does not help while the rogue provider is still registered, because it simply captures the new password at the next login. That gives an attacker who briefly held admin access a long-lasting way back in, even after the original compromise appears to be cleaned up.
What is the exposure or risk?
Any organization using Microsoft Entra ID is potentially exposed, but risk is highest where:
- Several people hold permanent Global Administrator or Authentication Policy Administrator rights
- Admin accounts are not protected with phishing-resistant MFA
- Changes to authentication policies and external identity providers are not monitored
- Federation and third-party MFA configurations are rarely reviewed
A successful TrustSink attack can lead to:
- Ongoing theft of employee passwords, including passwords reused on other systems
- Unauthorized access to email, files, cloud apps, and sensitive business data
- Long periods of undetected access and movement across the environment
- Data breaches with regulatory, legal, and reputational consequences
- A foothold for business email compromise or ransomware deployment
What are the recommendations?
LBT Technology Group recommends the following actions:
- Audit your external authentication methods now. In the Entra admin center, review the Authentication Methods Policy for any external MFA providers. Remove anything your organization did not deliberately set up, along with its related apps and service principals.
- Clean up before resetting passwords. If you find a suspicious provider, remove it first, then reset passwords for affected users. Resetting passwords while it is still in place only hands the attacker the new ones.
- Protect and reduce admin accounts. Keep the number of Global and Authentication Policy Administrators to a minimum, use dedicated admin accounts, and use just-in-time access (Privileged Identity Management) instead of permanent admin rights.
- Move to phishing-resistant MFA. Use FIDO2 security keys, Windows Hello for Business, or certificate-based authentication, starting with administrators.
- Tighten Conditional Access. Apply strict Conditional Access policies to admin roles and sensitive apps, such as requiring compliant devices and trusted locations.
- Monitor authentication changes. Alert on changes to the Authentication Methods Policy, new external authentication configurations, and newly created apps or service principals. Review sign-in logs for unfamiliar MFA issuer URLs.
- Review federation and trust settings regularly. Treat every external identity or MFA provider as a high-value configuration that needs an owner and periodic review.
Not sure who has admin rights in your Microsoft 365 tenant, or whether a rogue MFA provider is hiding in your settings? Contact LBT Technology Group for a no-pressure Microsoft 365 security review.
References
For more in-depth information about the recommendations, please visit the following links:
- Abrams, Lawrence. "Rogue external MFA providers can steal passwords during logins." BleepingComputer, September 22, 2026.
- SC Staff. "New TrustSink attack steals passwords via rogue MFA provider." SC Media, September 24, 2026.
- Dutta, Tushar Subhra. "TrustSink Attack Uses Rogue MFA Provider to Steal Microsoft Entra Passwords During Legitimate Logins." Cyber Security News, September 28, 2026.
