Rogue External MFA Providers Exploited to Steal Passwords During Login
Researchers warn of attack vector targeting multi-factor authentication integrations

Key Takeaways
- Attack requires privileged access to register external MFA providers.
- Rogue MFA providers can intercept passwords during legitimate login attempts.
- The vulnerability stems from administrative abuse rather than a software bug.
- No patch is currently available; mitigation focuses on restricting registration privileges.
- Organizations should audit and restrict who can register external MFA providers.
Quick answers
- What happened?
- Security researchers have identified a vulnerability in external Multi-Factor Authentication (MFA) provider integrations that allows threat actors with privileged access to register rogue MFA services. These rogue providers can intercept and steal user passwords during legitimate login attempts, exploiting the trust established between the login flow and the external MFA service.
- What should defenders do?
- Restrict privileged access to MFA provider registration and configuration. Implement strict allowlisting of approved external MFA vendors. Monitor for unexpected or unauthorized MFA provider registrations. Validate the integrity and certificates of external MFA services integrated into the login flow.
According to a report by BleepingComputer, security researchers discovered that attackers who gain privileged access to MFA administration consoles can register external MFA providers under their control. When legitimate users attempt to authenticate, the system redirects them to these rogue providers, which capture credentials under the guise of performing multi-factor authentication. The attack leverages the existing integration between the organization's login system and external MFA services, turning a security feature into a vector for credential theft. The researchers noted that the attack does not require exploitation of a software bug in the primary application, but rather the abuse of administrative privileges to enroll malicious MFA services. The full technical details of the interception mechanism and the specific MFA platforms affected remain under investigation and have not been fully disclosed in the initial report. No confirmed instances of this attack being observed in the wild have been reported to date, though the researchers demonstrated the feasibility of the technique.
Security Details
The attack vector involves threat actors with privileged access registering rogue external MFA providers. These rogue services intercept user credentials during legitimate login flows, exploiting the trust relationship between the authentication system and the external MFA service. The mechanism leverages administrative privileges to enroll malicious providers, turning the MFA process into a credential harvesting mechanism.
Mitigation
Restrict privileged access to MFA provider registration and configuration. Implement strict allowlisting of approved external MFA vendors. Monitor for unexpected or unauthorized MFA provider registrations. Validate the integrity and certificates of external MFA services integrated into the login flow.
Sources
BleepingComputer
Rogue external MFA providers can steal passwords during logins
Sep 22, 2026 · 21:45
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




