Risk level: critical. Can you change it: yes. Found in 10 breaches in this directory.
What this data is
Strings a service issues after you log in, session cookies, API keys, refresh tokens or reset links, that prove to the server you are already signed in.
The risk on its own
This is one of the worst fields to see in a breach because a valid token is a live session, not a clue. Whoever holds it is treated as already logged in, which means your password does not stop them and your two-factor code is never requested. Until the token is revoked or expires, the account is effectively shared.
The risk combined with other data
With your email address attached, the attacker knows exactly which account the token opens. From inside a live session they can read your data, add their own recovery address and change the password to lock you out. If the token belongs to a work system, the breach reaches your employer as well.
How criminals use it
An attacker imports the stolen session cookie into their own browser and lands inside your account without a login prompt.
A leaked API key is used to pull your entire account data through the service interface.
A refresh token silently mints new sessions for weeks, so removing one device does not remove the attacker.
The intruder changes the recovery email and phone from within the session, leaving you unable to reset the account.
What to do now
Sign out of all devices from the account security settings, which is the only action that actually kills existing sessions.
Change the password afterwards, in that order, so any surviving session is invalidated.
Revoke and reissue every API key and app password the account has, and delete third party app connections you do not recognise.
Check the recovery email address and phone number on the account and remove anything you did not add.
Turn on two-factor authentication with an authenticator app or a passkey, then review the login history for unfamiliar locations.
If the token belonged to a work account, report it to your employer immediately so they can revoke it centrally.
Frequently asked questions
I changed my password. Am I safe?
Not necessarily. Some services keep existing sessions alive after a password change, so you must also use sign out of all devices or revoke sessions.
Does two-factor authentication stop a stolen token?
No. The token represents a session that already passed the two-factor check, which is exactly why this class is treated as critical.
Do tokens expire on their own?
Some do within hours, others last months, and refresh tokens can keep renewing. Never rely on expiry, revoke them.
Breach data sourced from Have I Been Pwned, used under CC BY 4.0. Additional breach metadata provided by XposedOrNot. DataExposed is an independent service and is not affiliated with or endorsed by either.