What is credential theft?¶
Credential theft is the unauthorised acquisition of material that can be used to authenticate or continue access.
That can mean more than a password.
Useful authentication material may include:
- username/password;
- one-time code;
- session cookie;
- access or refresh token;
- API key;
- recovery link;
- trusted-device state.
The stolen item changes what access is possible¶
A stolen old password may no longer work.
A stolen session cookie may permit access without another password.
A captured recovery link may allow the attacker to change the account.
So first identify what material was actually obtained.
Different theft routes leave different evidence¶
| Route | Evidence you might expect |
|---|---|
| Phishing | Message, fake page, browser and server records |
| Malware/keylogger | Process, file, input and network artefacts |
| Browser/session theft | Cookie/token and local-browser evidence |
| Password-manager compromise | Vault/app/device and access records |
| Data breach | Exposed credential set and breach provenance |
| Social engineering | Calls, messages, recovery/provider records |
Do not label every account compromise “phishing” without evidence for that route.
Theft and use are separate events¶
The person who stole the credential and the person who later used it may also be different.
The practical point is: identify the exact authentication material and theft route first. Then prove any later account use independently from provider and session records.