Posts

Showing posts with the label what happens after password reset compromised account

You Changed the Password. You Reset MFA. The Attacker May Still Be Logged In. NIST Just Explained Why

Image
Fresh Guidance Identity & Access September 2026  ·  8 min read You discover an employee's account has been compromised. You do exactly what you've been told to do — change the password, reset MFA, have them sign back in. Problem solved. Except the attacker may never have needed the password again. Somewhere in the background, your cloud service may already have handed them something more useful: a token that says, in effect, this person has already proven who they are. Let them in. Six days ago, the US government's standards agency finalized an entire technical guide around exactly that problem. Every response plan in this series eventually says some version of the same thing: if an account is compromised, change the password and reset multi-factor authentication. That advice is correct, and it remains the right first move. It's also, on its own, sometimes incomplete — and the reason why has just been laid out...