Single Sign-On (SSO) and its Intersection with Phishing Attacks: An Investigation
Nareen Azad Khurshid · 2025
Users are increasingly prompted to click login links and login buttons from their emails and on websites, as services offer alternative login methods extending beyond traditional usernames and passwords. Single sign-on (SSO) simplifies password management by allowing users to login to services, like Spotify, Slack, Zoom, GitHub, Airbnb, and many more, using external identity providers (IDPs) like Google, Facebook, and Apple, to authenticate users using their already existing email address and accounts. We define a new phishing attack which is specifically targeted to SSO users, exploiting the “login with XYZ” button or link that takes the user to the malicious website. We then explore the possible consequences, specifically susceptibility to this new SSO-based phishing attack, questioning whether developing the habit of clicking on these buttons makes them disproportionately susceptible to this new type of phishing. To accomplish this, we created a user-study that included instances of SSO-based phishing.