Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is credential theft?

Credential theft is the unauthorised acquisition of material that can be used to authenticate or continue access.

That can mean more than a password.

Useful authentication material may include:

  • username/password;
  • one-time code;
  • session cookie;
  • access or refresh token;
  • API key;
  • recovery link;
  • trusted-device state.

The stolen item changes what access is possible

A stolen old password may no longer work.

A stolen session cookie may permit access without another password.

A captured recovery link may allow the attacker to change the account.

So first identify what material was actually obtained.

Different theft routes leave different evidence

Route Evidence you might expect
Phishing Message, fake page, browser and server records
Malware/keylogger Process, file, input and network artefacts
Browser/session theft Cookie/token and local-browser evidence
Password-manager compromise Vault/app/device and access records
Data breach Exposed credential set and breach provenance
Social engineering Calls, messages, recovery/provider records

Do not label every account compromise “phishing” without evidence for that route.

Theft and use are separate events

TheftAuthentication material leaves legitimate controlWhat exactly was obtained?
PossessionSomeone can potentially use itMaterial may be stale or incomplete.
UseService accepts accessAuthentication/session records show what happened.

The person who stole the credential and the person who later used it may also be different.

The practical point is: identify the exact authentication material and theft route first. Then prove any later account use independently from provider and session records.

Reference: CIM-044Cyber Incidents & Offender Methods