The Link Source Logo
    The Link Source
    Back to Blog
    Cybersecurity7 min readSeptember 24, 2026

    Changing Your Password Isn't Enough Anymore: Why Attackers Keep Access After a Reset

    Changing Your Password Isn't Enough Anymore: Why Attackers Keep Access After a Reset

    A company that wasn't even our client called us out of the blue after an attacker had access to their email for 10 days — even after a password change. Here's why resetting a password no longer kicks attackers out, and the steps you must take to fully secure a compromised account.

    A company we'd never worked with before called us out of the blue. They had no existing relationship with The Link Source — no managed services, no security software, no ongoing IT support. But they'd just discovered a security incident that had been quietly unfolding for over 10 days. An attacker had gained access to an employee's email account — and nobody noticed. No alerts. No suspicious activity flags. Just silent, persistent access to every email, contact, and attachment that passed through that inbox for nearly two weeks.

    When the breach was finally discovered, the first response was exactly what you'd expect: change the password immediately. They did. And then they assumed the problem was solved.

    It wasn't.

    Even after the password was changed, the attacker still had access. The account was still compromised. The intruder was still reading emails. How? Because in today's cloud-connected world, a password is just one door — and attackers don't always need it to stay inside.

    The Problem: Passwords Are No Longer the Only Key

    For decades, the reflex response to any account compromise was simple: reset the password. It worked because most systems used a single authentication method. Change the password, and the old one stops working. Problem solved.

    That world doesn't exist anymore. Modern cloud platforms like Microsoft 365 and Google Workspace use a layered authentication model. Your password is just one piece of it. When an attacker compromises an account, they rarely just sit there using your password. They plant additional access methods — methods that survive a password change entirely.

    How Attackers Stay In After a Password Reset

    1. Active Session Tokens

    When you log into your email, the platform issues a session token — a temporary digital key that says "this device is authenticated, no need to ask for the password again." These tokens can remain valid for hours or even days. When you change your password, the old session tokens may not be automatically invalidated. The attacker's existing session stays active, and they keep reading your email as if nothing happened.

    2. OAuth Tokens and Registered Apps

    This is the big one — and it's exactly what happened in this company's case. Attackers can register a third-party application inside your account using OAuth. This grants the app a token that allows it to access your mailbox, calendar, and files independently of your password. These tokens can last for months. Changing your password does nothing to revoke them. The attacker's app keeps pulling data in the background, completely silently.

    3. Inbox Rules and Email Forwarding

    Attackers frequently create hidden inbox rules that automatically forward incoming emails to an external address — or delete security alerts so you never see them. These rules persist across password changes. Even if you lock the front door, the secret mailbox the attacker built inside is still running.

    4. Mailbox Delegates and Folder Permissions

    In business environments, employees often grant delegate access to shared mailboxes or calendars. An attacker who gains access can grant their own external account full mailbox permissions. That permission survives a password reset and gives them a permanent backdoor.

    5. MFA Token Hijacking

    If the attacker was able to intercept or register a new MFA device during the compromise, they can continue generating valid authentication codes even after you change your password. They effectively become a second "you" that the system trusts.

    The Full Account Recovery Checklist

    Changing the password is step one — not the only step. If an account has been compromised, you need to perform a full session and access audit. Here's what that looks like:

    Step 1: Reset the Password

    Yes, still do this. Use a strong, unique password that hasn't been used anywhere else. But understand this is the beginning, not the end.

    Step 2: Revoke All Active Sessions

    In Microsoft 365, an administrator can use the admin center or PowerShell to sign the user out of all sessions everywhere. In Google Workspace, admins can revoke tokens and force re-sign-in. This kills the session tokens the attacker is relying on. Do not skip this step.

    Step 3: Review and Remove Registered Apps and OAuth Tokens

    This is critical. Go through every third-party application that has been granted access to the account. Remove anything unfamiliar, anything the user doesn't recognize, and anything that looks suspicious. In this company's case, this is where the persistent access was hiding — a registered app token that survived the password change.

    Step 4: Audit Inbox Rules

    Check for hidden forwarding rules, auto-delete rules, or rules that move security alerts to a buried folder. Delete any rule the user didn't create personally. Attackers are clever — they'll name rules things like "RSS Feeds" or "Junk Mail" to make them look harmless.

    Step 5: Remove Mailbox Delegates and Folder Permissions

    Review who has access to the compromised mailbox. Remove any delegate permissions that weren't explicitly authorized. Check shared calendar permissions too.

    Step 6: Reset or Re-register MFA

    Require the user to re-register for multi-factor authentication. Remove all existing MFA methods and start fresh. This ensures the attacker can't use a hijacked MFA device to get back in.

    Step 7: Review Sign-In Logs

    Pull the sign-in logs for the compromised account going back at least 30 days. Look for logins from unexpected locations, unfamiliar IP addresses, or impossible travel (a login in Houston and one in Eastern Europe 10 minutes apart). This tells you how long the attacker had access and what they may have touched.

    Step 8: Check for Data Exfiltration

    Review mailbox audit logs for large downloads, mass email forwarding, or access to sensitive folders. Determine what data the attacker may have accessed or stolen during the compromise window.

    Step 9: Notify Affected Parties

    If the attacker had access to sensitive client data, financial information, or confidential communications, you may have a legal obligation to notify affected parties. Don't skip this — the breach notification clock starts when you discover the incident, not when you finish investigating.

    Step 10: Enable Continuous Monitoring

    After recovery, set up alerts for suspicious sign-in activity, new app registrations, and rule creation on the account. The goal is to never again go 10 days without noticing a compromise.

    How to Prevent This From Happening in the First Place

    Reactive cleanup is expensive and stressful. The better path is prevention:

    • Enforce MFA everywhere: Not just email — every application that supports it. Phishing-resistant MFA (like FIDO2 security keys) is even better.
    • Use conditional access policies: Block logins from unexpected countries, require MFA for new devices, and restrict access to trusted locations when possible.
    • Monitor for new app registrations: Set up alerts so IT is notified the moment a new OAuth app is granted access to any mailbox.
    • Conduct regular mailbox audits: Periodically review inbox rules, delegates, and app permissions across all accounts — not just when there's a problem.
    • Enable mailbox audit logging: Make sure audit logging is turned on for all mailboxes so you have a record if you ever need to investigate.
    • Train employees to report suspicious activity: Missing emails, unexpected rules, or login prompts they didn't initiate are all red flags.

    The Bottom Line

    This company learned a hard lesson: in the age of cloud email and OAuth tokens, changing a password is like changing the lock on your front door while the attacker is still sitting in your living room with a spare key they made themselves. Password resets are necessary but insufficient. Full account recovery requires revoking sessions, purging registered apps, auditing rules, and resetting MFA — every single time.

    If your business uses Microsoft 365 or Google Workspace and you've never had someone audit your accounts for hidden OAuth tokens, inbox rules, or delegate permissions, now is the time. The attacker who gets in quietly is the one who does the most damage — because by the time you notice, they've had access for days. At The Link Source, we help Houston businesses implement the monitoring, policies, and response procedures that catch compromises early and recover accounts completely. Contact us today to find out how secure your email environment really is.

    Ready to Get Help with Your IT?

    Don't wait for a tech issue to become a business problem. Reach out to our Houston-based team today.

    Need Help with your IT?

    Book a free strategy session with our Houston-based experts to discuss your specific needs and challenges.

    Select a Date & Time

    Pick an available day and time slot below

    SuMoTuWeThFrSa
    Avatar
    Hi there! Have a question? Chat with us here.