Identity, SSO/MFA

University of Pennsylvania breach highlights SSO security risks

(Adobe Stock)

As detailed in Bleeping Computer, the University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account, underscoring the concentrated risks associated with this convenient authentication method.

Attackers gained access to a PennKey SSO account, which then allowed them to infiltrate internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint. This breach resulted in the theft of data belonging to 1.2 million individuals. While SSO offers benefits like reduced password sprawl and centralized access policies, its security hinges on robust protection. The university's incident highlights the need for strong passwords, with NIST recommending at least 15 characters for single-factor authentication and 8 characters for passwords used with multi-factor authentication (MFA). Furthermore, MFA should be consistently enforced across all users and access scenarios, moving beyond less secure methods like SMS codes towards phishing-resistant options such as FIDO2 security keys. Organizations must also secure the identity provider (IdP) administrator accounts, signing certificates, keys, and OAuth secrets, as well as review consent grants and delegated permissions to mitigate risks associated with compromised SSO credentials.

Source: Bleeping Computer

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds