If anyone (including hvus) is reading this, it isn't hard at all to prevent multiple sessions with the same username (just a 5-minute hack). But if you need to allow users the autonomous ability to check for security breach, you can try
extensions.joomla.org/extensions/access-a-security/site-access/11987
I haven't tried the yKhoon Advanced Lock Account. No reviews for it yet, so I'm not sure if it works.