← Blog · · df00tech

Rogue External MFA Providers Can Be Used to Steal Passwords at Login

security-news technique

Researchers have demonstrated an attack in which an attacker with privileged access to an identity system registers a rogue external MFA (multi-factor authentication) provider. Once configured, that malicious provider can intercept and steal users' passwords during otherwise legitimate login attempts, according to reporting from BleepingComputer.

Why It Matters

Federated and "bring your own MFA" configurations are common in enterprise identity platforms, and external MFA integrations are often treated as trusted, low-scrutiny extensions of the authentication flow. If an attacker can register or tamper with an external MFA provider, they gain a position to harvest credentials directly from the login path itself — turning a security control into a credential-theft mechanism. This is particularly concerning for organizations that delegate MFA configuration to non-security teams or that don't tightly control who can register new identity provider integrations.

The attack requires privileged access to configure the rogue provider, so this is primarily a risk amplifier for privilege-escalation and insider-threat scenarios rather than an unauthenticated, internet-facing exploit.

What Defenders Should Watch For

  • Audit who has permission to register, modify, or approve external/federated MFA and identity providers in your identity platform (e.g., Entra ID, Okta, or similar).
  • Review change logs and admin audit trails for newly added or modified MFA provider configurations, especially outside change-management windows.
  • Treat MFA provider registration as a privileged operation requiring approval workflows and alerting, not a routine self-service setting.
  • Consider hunting for anomalous authentication flows tied to newly added external MFA providers, and validate that any external MFA integrations in use are ones your team explicitly approved.
  • Restrict and tightly scope the admin roles capable of making identity-provider or MFA configuration changes, following least-privilege principles.

Developing Story

Details on the specific identity platforms affected, proof-of-concept availability, and vendor responses were not fully specified in initial reporting. This is a developing technique disclosure rather than a patched vulnerability, so organizations should monitor for follow-up guidance. Read the original report at BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.