> The attack is known as Session Hijacking. Session Hijacking is so dangerous as it bypasses many of the usual protections that websites have. One of these is two factor authentication.
This is why upon noticing you've been compromised, you log out of all devices. Only gotcha there is a bad actor can still do authenticated actions even after you done a global logout. So if anyone's building apps with login functionality, always check if the user is allowed to do actions even after global logouts.