The Good Tech Companies · Sep 17, 2026 · 16:23
Listen in the Podli app 🎧
Follow your favourite podcasts, listen offline and in the car with CarPlay and Android Auto, and always pick up where you left off. Free to try.
This story was originally published on HackerNoon at: https://hackernoon.com/trustsink-how-a-rogue-external-mfa-provider-steals-passwords.
Learn how TrustSink abuses rogue Entra external authentication providers to capture passwords and why removing the provider matters after a reset.
Check more stories related to undefined at: https://hackernoon.com/c/undefined.
You can also check exclusive content about #trustsink-credential-phishing, #entra-id-credential-theft, #rogue-mfa-provider, #persistent-credential-phishing, #entra-authentication-security, #entra-rogue-authentication, #rogue-authentication-provider, #good-company, and more.
This story was written by: @varonis. Learn more about this writer by checking @varonis's about page,
and for more stories, please visit hackernoon.com.
TrustSink is a credential-phishing technique that abuses a rogue External Authentication Method in Microsoft Entra to capture plaintext passwords inside a legitimate sign-in flow. The provider can display a convincing password prompt while returning a valid signed token to complete authentication. Because the rogue provider remains registered after a password reset, defenders must monitor authentication policy changes, app registrations, service principals, sign-in logs, and other indicators of unauthorized identity infrastructure.
Episodes: The Good Tech Companies