TrustSink attack steals Microsoft Entra ID credentials through rogue MFA providers
A newly discovered attack technique called TrustSink exploits Microsoft Entra ID’s federated trust model to steal user credentials. The method involves inserting a rogue multi-factor authentication (MFA) provider into the login process, allowing attackers to intercept plaintext passwords during legitimate authentication attempts. This approach operates within trusted authentication workflows, making it difficult for users and many security tools to detect.
The TrustSink attack bypasses traditional phishing tactics by weaponizing legitimate authentication infrastructure. Once credentials are captured, attackers can impersonate users, access sensitive corporate resources, and move laterally across connected systems. Organizations using Microsoft Entra ID with federated identity configurations are particularly vulnerable, especially those with weak governance or insufficient monitoring of external identity providers.
The stolen credentials can lead to data breaches, regulatory violations, and reputational damage. The attack was first reported by Smarter MSP, highlighting the need for stronger cloud security measures and better monitoring of federated identity providers to mitigate such risks.