Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Compromised credentials can open the door, but they can also help an attacker explore accounts, expand access, establish persistence, move between systems and cloud resources, and reach or exfiltrate data. Incident reports show different possible chains—not a single sequence that every attack follows.

What happens after an attacker gets your credentials?

A valid username and password, session, or other authentication material may let an attacker act as a legitimate user. What happens next depends on the identity’s permissions, the systems it can reach, and whether the attacker can avoid detection. The examples below come from specific incident reports; they illustrate possible activity, not how often it occurs or a universal attack sequence.

How credential abuse can progress

1. Initial access: use credentials—or steal them after getting in

In a 2020 federal-agency incident, CISA reported that actors used valid credentials for multiple Office 365 users and domain administrator accounts. Investigators could not determine how the credentials were first acquired. CISA noted exploitation of a vulnerable Pulse Secure VPN as a possibility, not an established finding. CISA’s incident report therefore shows credential-based access without establishing the original route by which the credentials were obtained.

The order can also run the other way: an attacker may enter through a software vulnerability and then steal credentials. In a 2022 advisory, CISA described a case in which exploitation of an unpatched VMware Horizon server provided initial access, followed by movement to a domain controller and credential compromise. CISA’s advisory is a reminder that a compromised password is not necessarily the first event in an intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Microsoft’s account of the Storm-2949 campaign describes social engineering involving self-service password reset and fraudulent MFA prompts, followed by access to identities and attempts to expand access. This is Microsoft’s analysis of that campaign, not evidence that an MFA prompt is suspicious by itself. Microsoft Threat Intelligence’s Storm-2949 analysis was published May 18, 2026.

2. Discovery: learn what the identity can reach

After authenticating, an intruder may inspect email, files, directories, user roles, applications, or cloud resources to identify useful information and additional routes. In the CISA federal-agency case, the report records email and SharePoint activity as well as Active Directory enumeration. Microsoft’s Storm-2949 analysis describes Microsoft Graph API queries to enumerate users and applications, followed by activity across Microsoft 365 and Azure. These examples show how an account can become a vantage point for learning about a wider environment.

A normal-looking sign-in or use of a legitimate administrative feature does not, by itself, prove compromise. Microsoft notes that attackers may abuse legitimate features and blend into expected administration. Assess activity in context and correlate identity events with endpoint, cloud, network, and data-access records.

Rank #2
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-C Type TrustKey T120
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T120. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T120 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-C port : Insert the T120 security key into the USB-C port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

3. Persistence: create a way to return

An attacker may try to preserve access even after a password changes. Possible routes include adding an authentication method, changing or creating accounts, adding credentials to a service principal, or planting tooling on a system. In the Storm-2949 account, Microsoft says the actor attempted to add credentials to a service principal and repeatedly compromised additional cloud accounts. In a separate investigation of a third-party compromise, Microsoft described web-based footholds and attempts to reestablish persistence after initial detection. Those are campaign-specific findings, not a claim that every compromised account has a hidden back door.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This is why credential remediation belongs within containment and eradication, rather than standing alone as a password reset.

4. Lateral movement: use access to cross boundaries

Reused or harvested credentials can help an attacker move from one account or host to another. Microsoft’s investigation of a third-party service-provider compromise describes credential interception on domain infrastructure and later use of harvested credentials to move across devices, including sensitive assets. In its Storm-2949 analysis, Microsoft describes movement among cloud resources and endpoint environments through legitimate administrative features.

Rank #3
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

CISA’s FY22 Ransomware Vulnerability Assessment analysis reported Pass the Hash in 27% of assessment instances and RDP in 17% of instances as lateral-movement methods used by the assessment team. Those percentages describe CISA’s assessment sample, not the share of all attacks or organizations. CISA’s FY22 RVA analysis provides that specific context.

5. Data access and impact: reach information or systems

Expanded access can lead to file access, data collection or exfiltration, more credential harvesting, and control of additional systems. Microsoft’s Storm-2949 analysis describes data access and exfiltration from Microsoft 365 and Azure services. In the 2020 federal-agency incident, CISA reported that actors used a created local account for collection, exfiltration, persistence, and command-and-control activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to investigate suspected credential abuse

Treat an unusual sign-in, unexpected account change, or suspicious connection as an investigative lead—not proof on its own. Build a timeline across identity, endpoint, network, cloud control-plane, and data-access activity to determine which accounts and systems were affected and what they did. CISA’s Cybersecurity Incident and Vulnerability Response Playbooks organize evidence by incident phase and identify useful sources, including email, web proxy, server, authentication, domain-controller, host, internal-network, and application logs.

Rank #4
OnlyKey Duo - The Best Protection for All of Your USB-C and USB-A Devices
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTION – Locking your device means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN – No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!
  • Initial access: Review email, web-proxy, server, and authentication records for unexpected access or activity.
  • Credential access: Examine authentication and domain-controller logs for unusual credential use.
  • Persistence: Check host events and authentication records for unexpected account, credential, or access changes.
  • Lateral movement: Correlate internal-network, host, and application logs. CISA identifies workstation-to-workstation communication, unexpected credential or account use, and activity from systems not intended to be internet-accessible as indicators to investigate.
  • Cloud and data access: Compare identity activity with cloud operations and access to services, files, and other data. Microsoft’s Storm-2949 analysis illustrates why events across these domains may need to be considered together.

The evidence sources are investigative starting points. Their value comes from correlating activity across systems and establishing what happened in the particular environment.

What to do when compromise is suspected

  1. Contain affected systems. CISA’s 2022 advisory recommends immediately isolating affected systems. Consider the systems and accounts involved rather than assuming the password alone defines the scope.
  2. Preserve evidence. Collect and review relevant logs and artifacts; capture memory and forensic images where appropriate before evidence is lost.
  3. Investigate connected systems. CISA recommends examining connected systems, including domain controllers, and auditing privileged accounts.
  4. Include identity remediation in the broader response. Investigate account and authentication changes and whether access was established through other accounts, credentials, or tooling; a reset by itself may not remove persistence.
  5. Consider specialist support. CISA’s advisory suggests considering a third-party incident-response organization when responding to a suspected compromise.

These actions are drawn from CISA’s 2022 advisory. The exact response should reflect the incident and the systems involved.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to reduce the risk of credential abuse

No single control eliminates every path shown in these cases. CISA’s StopRansomware Guide advises using phishing-resistant MFA for services such as email and VPN, applying identity and access management to roles and privileges, and considering credential-monitoring services. Microsoft’s Entra identity guidance discusses passkeys and FIDO2 security keys as authentication options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

When assessing controls, consider the whole access path rather than focusing only on passwords:

  • Authentication strength: Determine where password-only access remains and where MFA or phishing-resistant authentication is appropriate.
  • Identity coverage: Include users, administrators, service principals, and workload identities in access decisions.
  • Privilege and reach: Limit each identity to the systems, applications, data, and subscriptions it needs.
  • Visibility: Check whether monitoring covers authentication, endpoints, network movement, cloud operations, and data access.
  • Recovery readiness: Make sure responders can revoke sessions and authentication methods, reset credentials, preserve evidence, contain affected systems, and investigate persistence.

A FIDO2 security key is one possible phishing-resistant authentication method; check that it works with the identity provider and that account recovery is workable before relying on it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.