Rotating credentials does nothing when the attacker already owns the code that decides who gets to log in.