Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issuesVolume 342, Issue 3IT Vendor NewsVaronis

TrustSink: How a Rogue External MFA Provider Steals Passwords

Varonis, Wednesday, September 16th, 2026

Varonis researchers detail TrustSink, an attack in which a rogue external MFA provider harvests credentials.

Varonis Threat Labs discloses TrustSink, a technique where an attacker registers or abuses an external multi-factor authentication provider to capture user passwords.

The post explains the trust relationships that make the federation path exploitable and how the harvesting occurs in the authentication flow.

It details indicators defenders can hunt for in identity provider configuration and logs. Mitigations focus on restricting and auditing which external authentication providers a tenant will trust.

more →  ·  More from Varonis →