York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Penn Breach Shows How One Stolen SSO Login Can Sink a Pennsylvania Business

York Computer

This week, security outlets are re-circulating the University of Pennsylvania breach as the textbook example of how single sign-on (SSO) can turn one stolen password into a company-wide catastrophe. A July 29 analysis walks through how attackers used a single compromised PennKey account to reach VPN, Salesforce, SAP, SharePoint, and Qlik — and why the same failure mode applies to any small business running Microsoft 365, Google Workspace, or a similar SSO setup.

What actually happened at Penn

On October 30, 2025, a threat actor gained unauthorized access to the University of Pennsylvania's internal systems by compromising an employee's PennKey Single Sign-On account, which enabled access to multiple critical platforms including Salesforce Marketing Cloud, Qlik, SAP, and SharePoint, resulting in the exfiltration of sensitive data belonging to approximately 1.2 million donors, alumni, and students.

Penn later confirmed the entry point. In its statement, the university said access to these systems occurred due to a sophisticated identity impersonation commonly known as social engineering. In plain English: someone tricked an employee out of their login, and that single login was the master key to everything.

The compromised data includes names, dates of birth, addresses, phone numbers, estimated net worth, donation history, and demographic information such as religion, race, and sexual orientation. After the compromised account was revoked, the attacker leveraged persistent access to Salesforce Marketing Cloud to send offensive mass emails to the Penn community — proving the attackers still had a foothold even after the front door was shut.

Why this matters to a small business in York County

You may look at Penn and think "they're a huge university, I'm a 12-person shop, this isn't me." It absolutely is. If your team logs into Microsoft 365 once and gets email, Teams, SharePoint, OneDrive, and third-party apps without logging in again, you are running the same SSO model Penn was.

Single sign-on simplifies access by letting users log into multiple systems with one set of credentials, and while that delivers clear benefits, the convenience can also concentrate risk, as the 2025 University of Pennsylvania breach showed. One phished password. One reused password from a personal breach. One employee who approves an MFA prompt they didn't request. That's all it takes.

The attackers at Penn didn't exploit some exotic zero-day. They tricked a human. That's the same playbook being run against small-business owners every single week — fake Microsoft login pages, fake DocuSign notices, fake voicemail links, fake shared-file emails. A tightly-run managed IT and cybersecurity stack is what turns a single stolen password into a locked-out account instead of a $500,000 incident.

What your MSP should be doing this week

If you outsource IT — to us or anyone else — here's the short list you should be able to get a straight answer on:

**Phishing-resistant MFA on every account.** MFA should be consistently enforced across all users and access scenarios, moving beyond less secure methods like SMS codes toward phishing-resistant options like Microsoft Authenticator with number matching, Windows Hello, or FIDO2 security keys. SMS codes are no longer enough.

**Conditional access policies.** Your MSP should block logins from countries you don't do business in, require compliant devices, and flag "impossible travel" — a login from York at 9 a.m. and one from Eastern Europe at 9:15 should trigger an automatic lockout.

**Session and token monitoring.** Penn's attackers kept access even after the account was locked because they still had valid session tokens. Your provider should be revoking sessions, not just resetting passwords, when something looks off.

**Least-privilege access.** The Penn employee's account had reach into Salesforce, SAP, SharePoint, and VPN. Ask your MSP: does our office manager's account really need admin rights to everything? For most small businesses, the answer is no — and cleaning that up is exactly the kind of unglamorous work covered under day-to-day co-managed IT support.

**Security awareness training with teeth.** Not a once-a-year video. Ongoing simulated phishing, with follow-up coaching for anyone who clicks.

What York Businesses Should Do

York County businesses running Microsoft 365 should treat this as a prompt to ask their IT provider two questions this week: is phishing-resistant MFA turned on for every user, and are conditional access rules in place? If York Computer isn't already your provider, ask whoever is — and if the answer is vague, that's your answer.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles