Compromised password response

Compromised Password: What Your Business Should Do Next

A password reset is only the beginning. When a credential is exposed, the business must also consider active sessions, connected applications, mailbox rules, reused passwords and the way the account was compromised.

Executive summary

A Stolen Password Can Remain Useful After It's Changed

Attackers may use a password to sign in, create forwarding rules, authorize a malicious application, register another MFA method or steal a session token. That means the response must address the account, the device and the surrounding identity environment, not just the password field.

Contain access

Disable or restrict the account when unauthorized activity is suspected.

Revoke sessions

Force sign-out and invalidate active tokens, not only the password.

Find the cause

Determine whether phishing, malware, reuse or another failure exposed the credential.

Immediate response

Seven Steps to Take After a Password Is Compromised

Notify IT or the security provider

Don't handle a work-account compromise only as a personal password reset. The company needs a record of what happened and may need to preserve logs.

Disable or restrict the account

Temporarily block access when there's evidence of unauthorized sign-in or active abuse.

Reset the password from a trusted device

Create a new, unique password through an approved business password manager. Don't make a small variation of the exposed password.

Revoke active sessions and tokens

Force sign-out across devices and review connected applications. A session token stolen by malware can keep an attacker signed in even after the password changes, so this step is not optional.

Review MFA methods and recovery information

Remove unfamiliar phone numbers, devices, passkeys, security keys and recovery addresses.

Inspect the account and device

Check mailbox rules, sent messages, login history, administrative changes and the device for malware or infostealers.

Find every place the password was reused

Change reused credentials immediately, beginning with email, financial systems, remote access, payroll and administrator accounts.

Why session revocation is its own step: Modern infostealer malware targets session tokens as often as passwords. A token stolen from a browser can let an attacker continue using an account they were already signed into, including one protected by MFA, without needing the new password at all. Revoking sessions and reviewing connected apps closes that gap in a way a password reset alone doesn't.

When to escalate

Signs the Incident Is Bigger Than One Password

  • Unexpected MFA prompts or new authentication methods
  • Mailbox forwarding or deletion rules
  • Invoices, payment instructions or payroll changes sent from the account
  • Sign-ins from unfamiliar locations or devices
  • Security alerts involving session cookies or tokens
  • Malware, browser credential theft or unauthorized software on the device
  • The same password was used for administrator, vendor or personal accounts

Early containment can prevent a credential incident from growing into business email compromise, fraud, ransomware or a reportable data breach. Waiting for certainty before acting gives an attacker more time to move.

Free policy toolkit

Put Better Authentication Rules in Writing

Free Editable Download

Business Password and Authentication Policy Toolkit

Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.

Download the Word Toolkit
Frequently asked questions

Questions Business Leaders Ask

Is changing the password enough?

Not always. Active sessions, tokens, connected applications, mailbox rules and added MFA methods may allow continued access after a password change.

Should the employee reset the password before calling IT?

The employee should contact IT or the security provider immediately. The safest sequence depends on whether the account is actively being abused and whether evidence must be preserved.

What if the password was reused?

Every account using the same or a similar password should be changed, beginning with email, remote access, financial systems and administrator accounts.

Does changing the password stop an attacker who stole a session token?

No. A stolen session token lets an attacker reuse an already-authenticated session even after the password changes. Sessions and tokens must be revoked separately.

Related resources

Continue Building a Stronger Password Program

STACK Cybersecurity

Protect Accounts Before Stolen Credentials Become a Business Crisis

STACK Cybersecurity helps businesses respond quickly to a compromised account, from session revocation and MFA review through full investigation and incident documentation.

Talk With STACK Cybersecurity