logo

Even Orgs With SSO Are Vulnerable to Identity-Based Attacks

ID: 90d722a0-120b-529a-8c6f-95681490ec78

STIX ID: report--90d722a0-120b-529a-8c6f-95681490ec78

Feed Name: Dark Reading

Date Published: 2024-10-15

Date Updated: 2026-04-21

Author: Edge Editors

...
...

Push Security’s analysis of 300,000 accounts highlights identity as a prime attack surface: 61% rely only on SSO, 29% on passwords only, and 10% on both; 63% use MFA, yet almost all methods are phishable and about 1% of SSO accounts use phishing-resistant MFA. Key risks include 80% of password-only accounts lacking MFA, 40% of SSO+password accounts without MFA, and identity provider accounts where 17% lack MFA and 10% reuse passwords—exposing organizations to credential stuffing, brute-force, MFA fatigue, and attacker-in-the-middle phishing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.