Compromised Password: What Your Business Should Do Next
A password reset is only the beginning. When a credential is exposed, the business must also consider active sessions, connected applications, mailbox rules, reused passwords and the way the account was compromised.
A Stolen Password Can Remain Useful After It's Changed
Attackers may use a password to sign in, create forwarding rules, authorize a malicious application, register another MFA method or steal a session token. That means the response must address the account, the device and the surrounding identity environment, not just the password field.
Contain access
Disable or restrict the account when unauthorized activity is suspected.
Revoke sessions
Force sign-out and invalidate active tokens, not only the password.
Find the cause
Determine whether phishing, malware, reuse or another failure exposed the credential.
Seven Steps to Take After a Password Is Compromised
Notify IT or the security provider
Don't handle a work-account compromise only as a personal password reset. The company needs a record of what happened and may need to preserve logs.
Disable or restrict the account
Temporarily block access when there's evidence of unauthorized sign-in or active abuse.
Reset the password from a trusted device
Create a new, unique password through an approved business password manager. Don't make a small variation of the exposed password.
Revoke active sessions and tokens
Force sign-out across devices and review connected applications. A session token stolen by malware can keep an attacker signed in even after the password changes, so this step is not optional.
Review MFA methods and recovery information
Remove unfamiliar phone numbers, devices, passkeys, security keys and recovery addresses.
Inspect the account and device
Check mailbox rules, sent messages, login history, administrative changes and the device for malware or infostealers.
Find every place the password was reused
Change reused credentials immediately, beginning with email, financial systems, remote access, payroll and administrator accounts.
Why session revocation is its own step: Modern infostealer malware targets session tokens as often as passwords. A token stolen from a browser can let an attacker continue using an account they were already signed into, including one protected by MFA, without needing the new password at all. Revoking sessions and reviewing connected apps closes that gap in a way a password reset alone doesn't.
Signs the Incident Is Bigger Than One Password
- Unexpected MFA prompts or new authentication methods
- Mailbox forwarding or deletion rules
- Invoices, payment instructions or payroll changes sent from the account
- Sign-ins from unfamiliar locations or devices
- Security alerts involving session cookies or tokens
- Malware, browser credential theft or unauthorized software on the device
- The same password was used for administrator, vendor or personal accounts
Early containment can prevent a credential incident from growing into business email compromise, fraud, ransomware or a reportable data breach. Waiting for certainty before acting gives an attacker more time to move.
Put Better Authentication Rules in Writing
Free Editable Download
Business Password and Authentication Policy Toolkit
Download the editable Microsoft Word toolkit and customize it for your systems, policies, MFA, passkeys, shared accounts, vendor access and offboarding.
Download the Word ToolkitQuestions Business Leaders Ask
Is changing the password enough?
Not always. Active sessions, tokens, connected applications, mailbox rules and added MFA methods may allow continued access after a password change.
Should the employee reset the password before calling IT?
The employee should contact IT or the security provider immediately. The safest sequence depends on whether the account is actively being abused and whether evidence must be preserved.
What if the password was reused?
Every account using the same or a similar password should be changed, beginning with email, remote access, financial systems and administrator accounts.
Does changing the password stop an attacker who stole a session token?
No. A stolen session token lets an attacker reuse an already-authenticated session even after the password changes. Sessions and tokens must be revoked separately.
Continue Building a Stronger Password Program
Protect Accounts Before Stolen Credentials Become a Business Crisis
STACK Cybersecurity helps businesses respond quickly to a compromised account, from session revocation and MFA review through full investigation and incident documentation.
Talk With STACK Cybersecurity