Skip to content
Skip to main content
First Response & Preservation Operational Explainer

What should be preserved before a victim changes credentials?

Preserve the current sessions, linked devices, recovery routes and security history before changing credentials, unless immediate harm makes that short delay unsafe.

Record how access currently works

Capture the service, account ID, username, contact identifiers and login state. Record active sessions, recent sign-ins, device and location labels, recovery addresses and numbers, multi-factor methods, application passwords, administrator roles and delegated access. Ask when problems began and what changes the victim has already made.

This baseline helps distinguish suspicious access from effects created by the protective action. A password change may terminate some sessions and alert another user, while tokens, linked applications or recovery mechanisms can remain valid.

Change credentials through a safe route

Where protection is necessary, use a trusted device and network where possible. Record the authority, operator, time, provider route, security challenges, confirmations and resulting session changes. Review recovery details, authenticator applications, security keys and delegated access rather than assuming one password controls every route.

Protect the new credential from reuse and insecure notes. Ensure the victim has a safe alternative contact route in case of lockout or notification to another user.

Key takeaway

Capture the account's existing access routes before a justified credential change, then verify and document which sessions and recovery mechanisms the change actually affected.

Reference: FRP-181First Response & Preservation