
TrustSink is an attack technique that abuses Microsoft Entra ID’s federated trust model. It uses a rogue MFA provider to intercept user credentials during legitimate login attempts. The attack captures plaintext passwords in real time without the user’s knowledge. Attackers can then take over accounts and gain unauthorized access to corporate resources. Review it now to mitigate you and your clients’ risk.
What is the threat?
TrustSink allows attackers to harvest Microsoft Entra ID passwords by inserting a rogue MFA provider into the authentication process. When users log in through legitimate portals, their credentials pass through the malicious MFA provider. This allows attackers to capture plaintext passwords without triggering alerts or raising suspicion.
The attack is especially dangerous because it abuses trusted relationships within federated identity systems. As a result, attackers can gain persistent access to corporate environments, cloud resources, and sensitive data while remaining difficult to detect.
Why is it noteworthy?
TrustSink is noteworthy because it weaponizes trusted authentication infrastructure instead of relying on phishing pages. By operating within legitimate authentication workflows, the attack remains largely invisible to users and many traditional security tools.
The technique exploits the trust organizations place in federated identity providers and MFA systems, which are typically viewed as security controls rather than potential attack vectors. Because credentials are captured during valid login sessions, organizations may not see failed authentication attempts or other common warning signs. This makes TrustSink a significant evolution in identity-based attacks, particularly for organizations with complex federation environments.
What is the exposure or risk?
Organizations that use Microsoft Entra ID with federated identity configurations face elevated risk from TrustSink. Once attackers capture credentials through a rogue MFA provider, they can authenticate as legitimate users and access sensitive resources, cloud applications, and corporate data.
Stolen credentials can also support lateral movement, privilege escalation, and long-term persistence across connected systems. Because the attack uses trusted authentication pathways, compromised accounts may remain undetected for extended periods. This gives threat actors time to conduct reconnaissance, steal data, or deploy ransomware.
Organizations with weak federation governance, limited monitoring of external identity providers, or overly permissive trust relationships face the greatest risk. Potential impacts include data breaches, regulatory violations, financial losses, and reputational damage. The risk is particularly high for organizations that handle sensitive customer information or operate in regulated industries.
What are the recommendations?
Barracuda recommends the following actions to reduce risk:
- Regularly review and validate all external identity providers and MFA configurations in Microsoft Entra ID.
- Implement strict conditional access policies to restrict authentication from untrusted or unauthorized identity providers.
- Enable advanced logging and alerting for unusual authentication activity and federation changes.
- Limit the number of users who can configure federation settings or external MFA providers.
- Adopt a zero-trust security model that continuously verifies users, devices, and identity providers before granting access.
- Deploy FIDO2 security keys or certificate-based authentication to reduce reliance on vulnerable MFA methods.
References
For more information about these recommendations, review the following resources:
If you have any questions about this Cybersecurity Threat Advisory, don’t hesitate to get in touch with Barracuda Managed XDR’s Security Operations Center.
This post originally appeared on Smarter MSP.

