Attacker registers with the victim's email before the victim does. The victim's own SSO login then activates the attacker's account. Both end up sharing the same account.
Register with the target email and any password. Do not click the verification link that appears.
The victim discovers the service and uses SSO. They have never registered before. Use the same email as step 1.
Log out the victim session above, then log in as the attacker. Both parties now share the same account.