Why this matters
When an account is compromised, the instinct is to reset the password. That does not end the sessions and refresh tokens the attacker already holds, and it does nothing about the app they consented to, the inbox rule forwarding mail, or the new MFA method they registered.
Infostealers steal session cookies, not just passwords. The order matters: block sign-in, revoke every session, then clean up persistence, then restore access with phishing-resistant MFA.