An Employee's Password Turned Up in an Infostealer Log — Here's What to Do Next
Infostealer malware doesn't just harvest passwords — it can also grab browser cookies and authentication tokens, effectively capturing a logged-in session. That means even if a compromised account has multi-factor authentication enabled, an attacker holding a valid session token may not need to pass MFA at all to take it over.
Security researchers at Flare outline a practical response process for defenders who spot employee credentials surfacing in these logs. The key steps: quickly figure out which exposed accounts and sessions are still active, prioritize based on access level and business risk, and revoke or rotate credentials and sessions before an attacker acts on them.
The underlying message is that finding a leaked password is just the start of the investigation, not the end of it.