Rogue External MFA Providers Can Steal Passwords in Login Attacks
Researchers show that attackers with privileged access can register a malicious external MFA provider that harvests passwords during otherwise legitimate logins.
Security researchers have demonstrated an attack that lets hackers with privileged access register a rogue external multi-factor authentication (MFA) provider. When a user attempts a legitimate login, the malicious provider intercepts and steals their password without raising obvious red flags.
The attack does not bypass MFA in the usual sense. Instead, it exploits the trust placed in external MFA providers: once an attacker controls such a provider inside the victim's environment, they can harvest credentials during routine authentication flows.
The researchers' goal was to show that organizations need to scrutinize not just MFA adoption, but also the providers and integrations they allow. The findings suggest that privileged access to an identity infrastructure can be turned into a credential-stealing mechanism, even when users believe they are logging in normally.
More in Security & Privacy
Canada Probes IDScan After Breach of 153M Driver's Licenses
Privacy Commissioner opens investigation into IDScan.net's security practices and breach notifications after stolen ID scans of 153 million people appeared on the dark web.
AI Relay Servers Mask Chinese Access to US Frontier Models
More than 80,000 AI relay servers are helping users in China hide their identities while accessing cutting-edge US AI models, likely to clone them.
Sweden Fines Miljödata $183,000 for Breach Affecting 2.2 Million
Sweden's privacy regulator penalized IT provider Miljödata for security failures linked to a breach that exposed 2.2 million people's data.
Rogue AI Incidents Push Safety Debate From Theory to Practice
A wave of misalignment reports is forcing AI labs, enterprises, and governments to confront real-world control and security gaps.