Scam alertGlobal
“But I Had 2FA Turned On” — the Malware That Steals Your Logged-In Session
Posted 6 Oct 2026
The usual mental model of a hacked account is someone guessing or phishing a password, then defeating the second factor. A large and growing share of takeovers skip both steps entirely.
When you log in and tick “remember me”, your browser stores a session cookie that proves you already authenticated. Infostealer malware — picked up from a cracked program, a fake software installer, a malicious browser extension, or a download link in a sponsored search result — copies those cookies, along with saved passwords and autofill data, and uploads them. The attacker loads your session into their own browser and lands inside your account already signed in. There is no password prompt, no code to intercept, and no approval for you to decline.
That is why so many victims say the same thing: they had two-factor authentication switched on. It was never challenged. The logs show a normal, authenticated session, which is also why these intrusions are noticed late.
The detail that matters most for recovery is counter-intuitive: changing your password does not necessarily evict them. On many services an existing session stays valid through a password change. You have to explicitly revoke active sessions — the “sign out of all devices” control — and you have to clean the machine first, or the fresh credentials are stolen along with the old ones.
What to Do
- Recovering an account? Do it in this order: clean or reset the device, then sign out of all sessions and devices, then change the password, then regenerate backup codes. A password change alone can leave the attacker logged in.
- Treat cracked software, “free” premium installers, and unfamiliar browser extensions as the main delivery route. Most infostealer infections are installed by the user, deliberately, believing it is something else.
- Be wary of sponsored results at the top of a search for a popular app — malicious lookalike download pages buy those slots. Go to the vendor's own site by typing the address.
- Review connected apps, app passwords, and forwarding rules on your email after any incident — these survive a password reset and are a common way back in.
- Move high-value accounts to passkeys or a hardware security key where offered. They resist phishing, though no login method protects a session already stolen off your machine.
- Keep the number of accounts that stay permanently signed in on a shared or family computer as small as you can.
- Money gone? Phone your bank or exchange's fraud line now, then report it — identitytheft.gov and ic3.gov in the US, Action Fraud in the UK, 1930 / cybercrime.gov.in in India, Scamwatch in Australia.