Rogue external MFA providers can steal passwords during logins

Executive Summary

Researchers demonstrated that an attacker with privileged access can register a malicious external MFA provider. When users log in, the rogue provider captures their passwords, enabling credential theft while appearing legitimate.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-22T21:45:45+00:00 - Category: threat-intel

Original Description: Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]

"You, yourself, as much as anybody in the entire universe, deserve your love and affection."

— Buddha
Source: Bleeping Computer