Credential theft and phishing: why password changes may be insufficient
Recover passwords, sessions, API keys and third-party grants together after suspected credential theft.
Contents of this article
Inventory every credential type
Passwords, browser sessions, deployment tokens, cloud keys and application grants can all authorize access. A password change may not revoke existing sessions. Identify revocation controls, key inventories and recovery owners for critical accounts.
Verify through a trusted channel
Verify urgent billing, domain or security messages through a saved console URL or trusted support channel. If credentials were submitted, preserve the time and page details and begin account recovery without supplying further codes or files.
Revoke, rotate and investigate
Use a trusted device to change passwords, revoke sessions and rotate affected keys. Review new authentication devices, grants and changes to DNS, origins, billing and permissions. Track automation dependencies and verify that old keys no longer work.
Protect both login traffic and privileged access
Use account and behavior signals to limit abusive sign-in attempts without blanket bans on shared IPs. Apply suitable MFA, least privilege and individual administrative accounts. Edge controls support request filtering; identity recovery remains an application responsibility.
References
OWASP credential stuffing prevention
