When a breach exposes both passwords and authentication tokens, you face one of the highest-risk scenarios for account takeover. Passwords let attackers log in, while tokens—including session cookies, refresh tokens, “remember me” tokens, and sometimes app-specific tokens—can let them stay logged in even after you change your password. The right response is fast, structured, and thorough. Use the steps below to cut off attacker access, restore secure control, and watch for fallout across your digital life.
First, Understand the Risk
Exposed passwords can be tried immediately across many sites (credential stuffing). Exposed authentication tokens can bypass your next login entirely, keeping an attacker inside your account until you explicitly revoke their sessions. Because tokens may grant access without a password or 2FA, you must do more than just change your password—you must terminate all sessions and rotate every credential the account uses.
Immediate Actions (Minutes Matter)
- Go straight to the affected service’s Security or Account settings. Look for “Log out of all devices,” “Sign out everywhere,” “Terminate sessions,” or “Revoke tokens.” Run that first to cut off active attacker access.
- Change the account password to a unique, strong password. Use at least 14–16 characters. If possible, generate it with a password manager and store it there.
- Rotate app passwords and connected tokens. If the service supports app-specific passwords, API keys, personal access tokens, or OAuth connections, revoke and recreate them. Re-link trusted apps after the reset.
- Re-enroll multi-factor authentication (MFA) securely. If you used SMS codes, switch to an authenticator app or a hardware security key if supported. Remove any unknown MFA devices. Save new backup codes securely.
- Update account recovery settings. Confirm your recovery email and phone are yours, remove any you don’t recognize, and add a second trusted recovery option.
- Check account details for tampering. Verify display name, forwarding rules, inbox filters, shipping addresses, payment methods, and security questions. Undo anything unfamiliar.
- Review recent activity and alerts. Note suspicious logins, IPs, devices, and changes. Capture screenshots for your records.
If Email Is Involved, Prioritize It
Your primary email account is the reset key to almost everything. If those credentials or tokens were exposed, lock it down before anything else.
- Terminate all email sessions and change the password.
- Remove unknown recovery emails, phone numbers, and third-party app access (OAuth).
- Delete malicious filters and forwarding rules that silently copy your mail.
- Enable strong MFA and store backup codes safely.
Systematic Credential Rotation Across Accounts
Once the exposed account is secure, assume the password may have been reused elsewhere and that attackers may already be trying it on other services.
- Inventory affected accounts. Start with financial, email, cloud storage, social media, and any account sharing the same or similar password.
- Change reused passwords to unique ones. Use a password manager to generate and save unique credentials for every site.
- Enable MFA on every important account. Prefer authenticator apps or hardware keys over SMS where possible.
- Force logout where available. Many platforms let you sign out from all devices—use it after each password change.
- Revoke and recreate tokens. For developer, cloud, or productivity platforms, rotate API keys, refresh tokens, automation keys, and app passwords.
What “Authentication Tokens” Includes (And How to Kill Them)
Different services use different token types. Look for these terms in your account’s security settings and revoke them:
- Active sessions or devices: Force sign-out everywhere.
- Remembered browsers/devices: Clear trusted device lists.
- OAuth grants: Remove third-party app connections and re-authorize only the ones you use.
- App-specific passwords: Revoke and generate new ones after you change the main password.
- API keys and personal access tokens: Rotate keys and secrets; update any scripts or apps that rely on them.
- Backup codes: Regenerate them after changing MFA; store securely.
Strengthen MFA the Right Way
MFA is still essential, but you may need to reconfigure it after a breach:
- Best options: Hardware security key (FIDO2/U2F) or an authenticator app (TOTP).
- Avoid only-SMS MFA when possible: It’s better than nothing, but susceptible to SIM-swap and phishing.
- Remove old devices and regenerates codes: Eliminate attacker footholds and stale recovery factors.
Check Devices and Browsers
If tokens were stolen from your device (malware, malicious extensions), attackers could keep exfiltrating new ones.
- Run a reputable anti-malware scan on computers and phones used to access the breached account.
- Update your OS and browsers to the latest versions; apply security patches.
- Audit browser extensions and remove any you don’t need or don’t fully trust.
- Consider signing out of browsers and clearing cookies for the affected sites after you’ve changed credentials and forced logouts.
Monitor for Account Takeover and Fraud
Attackers often pivot from an initial compromise to financial or identity fraud. After you lock down access, continue monitoring.
- Watch for new login alerts or password reset emails you didn’t request.
- Check financial accounts and payment methods for unfamiliar charges or added payees.
- Enable transaction and login notifications wherever available.
- Consider a credit freeze with all three major bureaus if sensitive personal data was exposed alongside credentials.
If You Reuse Passwords, Break the Pattern Now
Credential stuffing targets reused passwords. Move to unique passwords everywhere to neutralize this risk.
- Adopt a password manager to generate and store strong, unique passwords.
- Prioritize critical accounts first (email, financial, cloud storage, work accounts), then work through the rest.
- Use passphrases for accounts that don’t work well with managers, and avoid reuse even for “unimportant” sites.
Records to Keep
Documenting what happened helps if issues appear later or you need support from a provider or law enforcement.
- Dates and times you discovered the breach and took each action.
- Screenshots of suspicious sessions, devices, forwarding rules, or transactions.
- Support ticket numbers or chat transcripts with the affected service.
- A list of accounts where you changed passwords, enabled MFA, or revoked tokens.
For broader guidance on what to retain, see: What Records Should You Save After a Data Breach in Case Problems Appear Later?
Handling “No Obvious Fraud” Right Now
Even if you don’t see immediate damage, exposed passwords and tokens warrant full containment and monitoring. Quiet compromises often surface weeks later as attackers resell access or try again.
For step-by-step actions when there’s no visible fraud yet, see: What Should You Do After a Data Breach If You See No Fraud Yet?
When to Contact Support or Law Enforcement
- Account provider support: If you can’t access your account, if you see new MFA devices you can’t remove, or if session revocation doesn’t work, open an urgent security ticket.
- Financial institutions: Report unauthorized charges immediately; request card replacement and account monitoring.
- Law enforcement or your state attorney general: Consider reporting significant identity theft or ongoing financial harm, keeping your documentation handy.
Prevent the Next Incident
- Unique passwords + MFA as standard practice.
- Use phishing-resistant habits: type URLs directly, beware of login links in messages, and verify security notices in the account dashboard.
- Reduce exposed personal data on people-search sites and public profiles to limit targeting and social engineering.
- Regularly review security settings and connected app permissions across major accounts.
Optional Next Step: Monitor Your Financial Identity
After a serious credential exposure, ongoing monitoring can help you catch abnormal activity quickly. If you want a consolidated place to track credit changes and identity-related activity, you can evaluate SmartCredit as an optional next step: SmartCredit for privacy, credit monitoring, and identity protection.
Conclusion
When a breach exposes both passwords and authentication tokens, treat it like an active intrusion: terminate all sessions, change passwords to unique ones, rotate every token and app password, and strengthen MFA. Secure your primary email first, then work outward to other important accounts. Scan your devices, watch for follow-on fraud, and keep thorough records. With decisive steps in the first hours and steady monitoring after, you can shut attackers out, limit damage, and reestablish a safer foundation for your digital life.
Good to Know
Attackers often use stolen session tokens first because they work even after a password change; forcing logout on all devices and revoking connected app sessions is the fastest way to cut off access.