Glossary

What is credential harvesting?

Credential harvesting is an attack that collects usernames, passwords and sometimes one-time codes by luring people to a fake login page.

Also known as
Credential phishing, credential capture
Channel
Email, SMS, chat apps, QR codes
Typical goal
Working logins for email, cloud or finance systems
Related term
Phishing

How it works

A copied page,
a real password.

  1. 01

    Build the page

    The attacker copies a familiar sign-in page and hosts it on a look-alike address.

  2. 02

    Send the lure

    A message gives a reason to sign in: a shared file, a mailbox warning, a payroll update.

  3. 03

    Capture

    The victim enters their details.

  4. 04

    Reuse

    The attacker signs in as the victim, then reads mail, moves money or phishes colleagues from a trusted account.

How to spot it

Look at the address
before you type.

A fake login page can look pixel-perfect. The address bar is where it usually gives itself away.

CHECKLIST

Warning signs

  • Login prompt after clicking a link or scanning a code
  • Web address that isn’t your usual sign-in page
  • Asks for a one-time code you didn’t request
  • Page appears for a document you weren’t expecting
  • Your password manager doesn’t offer to fill it

Report it, then change your password as your security team advises.

Questions buyers ask

Frequently asked questions.

What is the difference between phishing and credential harvesting?

Phishing is the lure. Credential harvesting is one goal of it: collecting login details through a fake page. Not all phishing aims at credentials.

Does multi-factor authentication stop credential harvesting?

It makes stolen passwords much harder to use, but some fake pages also capture one-time codes in real time. Phishing-resistant sign-in methods and user vigilance both help.

What should I do if I entered my password on a fake page?

Report it to your security team straight away through your organisation’s process, and change the password from a trusted device as they advise.

Let’s connect the dots

See the human risk.
Change what happens next.

Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.

Book a demo