As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account, underscoring the concentrated risks associated with this convenient authentication method.Attackers gained access to a PennKey SSO account, which then allowed them to infiltrate internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. This breach resulted in the theft of data belonging to 1.2 million individuals. While SSO offers benefits like reduced password sprawl and centralized access policies, its security hinges on robust protection. The university's incident highlights the need for strong passwords, with NIST recommending at least 15 characters for single-factor authentication and 8 characters for passwords used with multi-factor authentication (MFA). Furthermore, MFA should be consistently enforced across all users and access scenarios, moving beyond less secure methods like SMS codes towards phishing-resistant options such as FIDO2 security keys. Organizations must also secure the identity provider (IdP) administrator accounts, signing certificates, keys, and OAuth secrets, as well as review consent grants and delegated permissions to mitigate risks associated with compromised SSO credentials.Source: Bleeping Computer





