University of Pennsylvania SSO Breach Exposes 1.2 Million Records
ID: cb463418-be74-5cbb-8f43-e2a78b184d0a
STIX ID: report--cb463418-be74-5cbb-8f43-e2a78b184d0a
Feed Name: ThreatCluster
In 2025 the University of Pennsylvania experienced a large-scale breach after attackers compromised a PennKey single sign-on (SSO) account, enabling access to internal systems including VPN, Salesforce, Qlik, SAP, and SharePoint and affecting about 1.2 million individuals; the report highlights SSO-specific risks and urges adoption of NIST-recommended strong password policies, consistent MFA (including FIDO2 keys), and tighter protection of identity provider admin accounts and permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
