Avatier

Attack vector

SSO, IdP, or federation compromise

SSO, IdP or federation compromise is an attack on the identity provider itself rather than on one account. By taking over an administrator, adding a rogue federated domain or stealing a token-signing key, an attacker can mint trusted sign-ins for any user in any connected application. One break at the center can open every door downstream.

The identity provider itself as the target.

How attackers use it

Attackers target the people and systems that run single sign-on: IdP administrators, federation settings and the certificates that sign tokens. Inside the network, Active Directory acts as the identity provider, so cracked service account passwords or stolen password hashes let an attacker sign in as other domain users. With that control they can add their own trusted identity source, change MFA policy or forge sign-in tokens that every connected app accepts. The resulting logins look valid, because the system that vouches for identity is the one that was compromised.

What breach letters say

None of the 2,161 California breach filings in the ledger (January 1, 2023 – August 14, 2026) names this vector. That says what notification letters disclose, not how often it happens.

See the Identity Attack Ledger

How to stop it

Harden the identity provider with phishing-resistant MFA and separate accounts for identity administrators, alerts on any change to federation trust or signing keys, and protected storage for those keys. Treat the identity provider as tier-zero infrastructure.

Terms under this vector

  • Golden SAML

    Golden SAML is an attack in which someone who has stolen an identity provider's token-signing key forges SAML authentication tokens.

  • Kerberoasting

    Kerberoasting is an Active Directory attack in which any signed-in domain user requests Kerberos service tickets for service accounts, then cracks those tickets offline to recover the accounts' passwords.

  • Pass-the-hash

    Pass-the-hash is an attack that signs in to Windows systems using a stolen password hash instead of the password itself.

Threat actors tied to it

  • Akira

    Profile with government sources

Last reviewed Oct 2, 2026