In every online-enabled system, fake accounts run rampant. If we're using primarily SSO for verifying a user's individuality, even the strongest SSO accounts integrations for identity verification ( i.e. banks) could be fraudulently acquired.
For example, as an individual in the US, I could have bank accounts with 3 banks, each with SSO. I could sell access to two of those accounts to others, who could then use those accounts to bolster the identity of a fake account.