University of Pennsylvania Data Breach Exposes SSO Security Vulnerabilities Affecting 1.2 Million Individuals
The University of Pennsylvania experienced a significant data breach in 2025 due to a compromised single sign-on (SSO) account. Attackers gained access to a PennKey SSO account, which allowed them to infiltrate internal systems such as VPN, Salesforce, Qlik, SAP, and SharePoint. This breach resulted in the theft of data belonging to 1.2 million individuals. While SSO offers benefits like reduced password sprawl and centralized access policies, its security depends on robust protection. The incident highlights the need for strong passwords, with NIST recommending at least 15 characters for single-factor authentication and 8 characters for passwords used with multi-factor authentication (MFA). Organizations must also secure identity provider (IdP) administrator accounts, signing certificates, keys, and OAuth secrets, as well as review consent grants and delegated permissions to mitigate risks associated with compromised SSO credentials.