How can credentials be stolen?¶
There are several routes, and each tends to leave a different evidence trail.
The main mistake is to start with a later unauthorised login and assume you already know how the credential was obtained.
Work the other way around: what authentication material was used, and which theft routes are actually supported by the evidence?
Common routes¶
Credentials or session material may be obtained through:
- phishing;
- malware;
- keylogging;
- browser/session theft;
- password-manager compromise;
- data breaches;
- password reuse;
- social engineering;
- insecure storage;
- account-recovery abuse;
- remote access.
Each route leaves different artefacts¶
| Possible route | Useful evidence may include |
|---|---|
| Phishing | Message, fake page, browser and hosting records |
| Malware/keylogger | Process, file, input and network artefacts |
| Browser/session theft | Cookies, tokens, browser profile and local process evidence |
| Data breach | Known exposed credential set and breach provenance |
| Password reuse | Same credential reused across services and historical exposure |
| Social engineering/recovery | Calls, messages, provider recovery events and factor changes |
That expected evidence helps test the hypothesis.
Do not infer the route from the outcome¶
Suppose a provider shows a successful login from an unfamiliar location.
That may be consistent with:
- stolen password;
- stolen session;
- legitimate remote access;
- shared account;
- existing trusted device;
- recovery process;
- compromised endpoint.
The login does not tell you which route supplied the access.
Start from the first suspicious activity¶
A useful sequence is:
Sometimes the compromise can be proved while the theft route remains unknown. That is an acceptable conclusion if the evidence stops there.
The practical point is: test credential-theft routes against the evidence they should leave. Do not convert a later unauthorised login into an assumed phishing or password-theft story.