Wednesday, 23 September 2026

Search
Latent Digest

TECHNOLOGY, TRACKED ACROSS DISCIPLINES

Security & Privacy

Rogue External MFA Providers Can Steal Passwords in Login Attacks

Researchers show that attackers with privileged access can register a malicious external MFA provider that harvests passwords during otherwise legitimate logins.

· 1 min read · 1 source

Security researchers have demonstrated an attack that lets hackers with privileged access register a rogue external multi-factor authentication (MFA) provider. When a user attempts a legitimate login, the malicious provider intercepts and steals their password without raising obvious red flags.

The attack does not bypass MFA in the usual sense. Instead, it exploits the trust placed in external MFA providers: once an attacker controls such a provider inside the victim's environment, they can harvest credentials during routine authentication flows.

The researchers' goal was to show that organizations need to scrutinize not just MFA adoption, but also the providers and integrations they allow. The findings suggest that privileged access to an identity infrastructure can be turned into a credential-stealing mechanism, even when users believe they are logging in normally.

Source

  1. 01Rogue external MFA providers can steal passwords during loginsBleepingComputer

More in Security & Privacy