Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is credential harvesting?

Credential harvesting is the collection of authentication material for possible later use.

That may include:

  • usernames;
  • passwords;
  • one-time codes;
  • session cookies;
  • tokens;
  • recovery information.

The key investigative question is what material was obtained, how was it collected, and was it later used?

Fake forms are only one route

Credentials can be collected through:

  • fake login pages;
  • malware;
  • keylogging;
  • browser theft;
  • password-manager compromise;
  • malicious applications;
  • data breaches;
  • social engineering;
  • reused credentials from elsewhere.

Do not assume the collection method just because you later see suspicious account access.

Separate collection from later access

A useful sequence is:

CollectionCredential entered or stolenWhat material was exposed?
TransmissionData leaves the victim deviceDid it reach an external endpoint?
ReceiptAttacker-side system gets the dataInfrastructure evidence may support this.
UseAccount access followsAuthentication and session records show later activity.

Those stages can all exist — or stop at any point.

Later compromise does not prove this was the route

If the account is compromised later, the credentials could have come from:

  • an older breach;
  • password reuse;
  • malware;
  • another phishing event;
  • authorised sharing;
  • a stolen session.

So compare the timing and technical records before linking the two.

Look at what was actually captured

A page may collect only a password.

Another may collect a password plus one-time code.

Some attacks aim for session tokens instead.

That changes what later access may look like.

The practical point is: credential harvesting is about collecting authentication material. Establish the collection route, what was obtained and how later account activity connects to it rather than working backwards from the compromise.

Reference: CIM-036Cyber Incidents & Offender Methods