pwnsy

Session Kill Switch

Sign out everywhere, in the right order, after malware or a stolen cookie. 🔒 saved in this browser only
Step 0: clean the device first.

Work from a clean device. Pick the infected one above for reset steps and a matching checklist.

Checklist

0 / 0
Why a password change is not enough

A site gives your browser a session cookie or token after sign-in. Infostealers copy those. Whoever holds one is signed in as you, with no password or MFA prompt, until the session is revoked.

Some services end sessions on a password change. Many do not, and almost none touch OAuth grants, API tokens, app passwords or linked devices. Tags on each entry show which of these it covers, and the yellow line says what a password change leaves behind.

Links go to each provider's settings page as of October 2026. If a page moves, the menu path still names the setting. More: what an infostealer takes, session hijacking, credential stuffing.