Reimaging removes software, not stolen credentials

Rebuilding a machine gets rid of the malware. It does not get rid of what the malware took.

Passwords, session tokens and certificates harvested from that device remain valid afterwards, so the attacker walks back in through the front door of a clean machine. Response has to include rotating what was exposed, and the order matters: rebuild first and reset afterwards and you may hand the new credentials straight over.

More on Endpoint security