What should be preserved before a victim changes credentials?¶
Before a victim changes credentials, preserve the evidence that shows the current account state, access routes and potential compromise.
Avoid this assumption: A password change should happen immediately in every case. It may alert another user, terminate sessions, alter security history or remove access to useful live information.
Record the service, account ID, username, email address, phone number and current login state.
Capture active sessions, linked devices, recovery details, multi-factor methods, recent sign-ins and security alerts.
Preserve any unfamiliar device, location, application password, administrator role or delegated access already visible.
Record the victim’s account of when access problems began and what changes they have already made.
Where harm is continuing, credential change may still be necessary. Preserve the visible state first where this can be done without unacceptable delay.
Use an approved safe device and trusted network where possible.
Record who authorised the change, who performed it, the exact time and the provider route used.
Capture every notification, confirmation, security challenge and resulting session change.
Do not reuse a password from another account or store the new credential in ordinary notes.
Consider whether recovery email addresses, phone numbers, authentication apps, security keys and linked sessions also need review.
Do not assume changing one password removes every access route.
Record whether the victim has a safe alternative contact route in case the credential change locks them out or alerts the other user.
Operational takeaway¶
Preserve sessions, devices, recovery routes and security alerts before credential change, then document the complete protective action and its effect on account access.