TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model by using a rogue MFA provider to intercept user credentials during legitimate login attempts. The attack captures plaintext passwords in real time without the user’s knowledge, allowing attackers to take over accounts and gain unauthorized access to corporate resources, as first reported by Smarter MSP.
The TrustSink attack allows threat actors to harvest Microsoft Entra ID passwords by inserting a rogue MFA provider into the authentication process. This method weaponizes trusted authentication infrastructure instead of relying on phishing pages. By operating within legitimate authentication workflows, the attack remains largely invisible to users and many traditional security tools. Organizations that use Microsoft Entra ID with federated identity configurations face elevated risk. Once attackers capture credentials, they can authenticate as legitimate users and access sensitive resources, cloud applications, and corporate data. Stolen credentials can also support lateral movement, privilege escalation, and long-term persistence across connected systems. Organizations with weak federation governance or limited monitoring of external identity providers face the greatest risk, potentially leading to data breaches, regulatory violations, and reputational damage.
Source: Smarter MSP
