What is credential harvesting?¶
Credential harvesting is the collection of authentication material for possible later use.
That may include:
- usernames;
- passwords;
- one-time codes;
- session cookies;
- tokens;
- recovery information.
The key investigative question is what material was obtained, how was it collected, and was it later used?
Fake forms are only one route¶
Credentials can be collected through:
- fake login pages;
- malware;
- keylogging;
- browser theft;
- password-manager compromise;
- malicious applications;
- data breaches;
- social engineering;
- reused credentials from elsewhere.
Do not assume the collection method just because you later see suspicious account access.
Separate collection from later access¶
A useful sequence is:
Those stages can all exist — or stop at any point.
Later compromise does not prove this was the route¶
If the account is compromised later, the credentials could have come from:
- an older breach;
- password reuse;
- malware;
- another phishing event;
- authorised sharing;
- a stolen session.
So compare the timing and technical records before linking the two.
Look at what was actually captured¶
A page may collect only a password.
Another may collect a password plus one-time code.
Some attacks aim for session tokens instead.
That changes what later access may look like.
The practical point is: credential harvesting is about collecting authentication material. Establish the collection route, what was obtained and how later account activity connects to it rather than working backwards from the compromise.