THREATOPS
THREAT OPSThreat News › TrustSink: How a Rogue External MFA Provider Steals Passwords

TrustSink: How a Rogue External MFA Provider Steals Passwords

medvaronis_blogPublished 2026-09-16

<p><a href="https://www.varonis.com/varonis-threat-labs?hsLang=en">Varonis Threat Labs</a> identified a credential-phishing technique we call TrustSink. It turns a trusted external authentication provider into a persistent credential trap within a legitimate sign-in flow.</p> <p>While the technique can work in any provider, we demonstrated TrustSink end-to-end using Microsoft Entra. An attacker w

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.varonis.com/blog/trustsink