When a security breach strikes—whether through an info-stealer malware infection, a sophisticated session-cookie hijacking attack, or a major identity credential leak—the immediate human reaction is often panic. Flustered victims frequently take counterproductive actions: attempting to reset passwords from infected machines, deleting log evidence, or failing to terminate active authenticated cloud sessions. Having a structured, battle-tested personal Incident Response Runbook transforms panic into methodical, forensic containment.

Phase 1: Immediate Triage and Hardware Isolation

If a workstation or mobile device is suspected of active malware compromise, the first and most critical action is containment:

  1. Sever All Network Interfaces Immediately:
    • Disconnect physical Ethernet cables.
    • Disable Wi-Fi and Bluetooth.
    • Do NOT simply reboot the machine; sophisticated modern malware maintains persistence mechanisms that execute on shutdown or startup.
  2. Do Not Reset Credentials from the Suspect Device:
    • If an active keylogger or remote access trojan (RAT) resides in memory, typing new passwords merely hands the attacker your new credentials in real time.
    • All subsequent remediation must occur from a known-clean, physically separate device (such as an updated smartphone using cellular data, not local home Wi-Fi).
Incident Stage Priority Actions Common Critical Mistakes
0–15 Minutes (Containment) Sever device network links; switch to clean cellular device Resetting passwords on compromised machine; powering down without taking inventory
15–60 Minutes (Identity Securing) Revoke all active cloud sessions; rotate Master Password; enforce FIDO2 WebAuthn Changing secondary accounts before securing primary recovery email and SIM
1–24 Hours (Financial Shielding) Freeze credit bureaus; inspect bank auto-forwards; audit OAuth authorizations Assuming password change invalidates stolen browser session cookies
24–72 Hours (Forensic Remediation) Clean install OS via USB media; audit device backups; submit formal theft reports Using "System Restore" which often retains polymorphic malware artifacts

Phase 2: Securing the Root of Identity

Attackers prioritize taking over the core hubs of your digital existence: your primary email account and password manager. If an attacker controls your primary email, they can unilaterally reset access across your entire banking and SaaS ecosystem.

From your known-clean secondary device:

  1. Terminate All Active Web and API Sessions:
    • In Google, Microsoft, or Apple account settings, execute "Sign Out of All Sessions" or "Revoke All Device Tokens." This immediately invalidates stolen session cookies and OAuth refresh tokens.
  2. Rotate Primary Master Credentials:
    • Change your primary email password and password manager master password using unique, random 20+ character passphrases.
  3. Upgrade to Hardware-Bound Authentication (FIDO2 / Passkeys):
    • Remove SMS-based two-factor authentication and generic authenticator apps where possible. Enroll hardware security keys (YubiKey / Nitrokey). Hardware tokens are cryptographically bound to the domain URL, rendering them mathematically immune to adversary-in-the-middle phishing proxies.
  4. Audit Account Recovery and Forwarding Rules:
    • Attackers frequently configure silent auto-forwarding email rules or register foreign secondary recovery phone numbers. Inspect your email inbox filter settings for hidden forwarding rules designed to intercept financial security codes.

Phase 3: Financial Lockdown and Credit Freezes

If identity credentials (such as national ID, Social Security Number, or bank account details) were exposed, implement a complete financial freeze immediately:

  • Credit Bureau Freezes: Place formal security freezes with all major consumer credit reporting agencies (in the US: Equifax, Experian, TransUnion, plus Innovis and ChexSystems). A credit freeze prevents anyone—including you—from opening new credit accounts, loans, or utility lines until you explicitly unlock the file with a secure PIN. Freezing credit is federally mandated to be 100% free.
  • Banking Fraud Alerts: Notify your financial institutions to place high-risk fraud alerts on your checking and investment accounts, requiring verbal callback verification for any wire transfers or beneficiary adjustments.

Phase 4: Clean Rebuild and Post-Incident Audit

Never attempt to "clean" a deeply compromised operating system with commercial anti-virus utilities once elevated root or administrative privileges have been breached. Modern polymorphic rootkits and UEFI malware can survive standard file deletions.

  • Perform a Clean Wipe: Flash a fresh OS installation image to a USB flash drive from an uncompromised computer. Boot the compromised machine into BIOS/UEFI, format all internal NVMe/SSD partitions entirely, and reinstall the operating system from scratch.
  • Audit Cloud App Authorizations: In your Google, GitHub, and Microsoft dashboards, audit third-party "Connected Apps." Revoke permissions for any third-party tools or integrations you do not explicitly recognize.