IronSights

Threats & attacks

Credential harvesting

The process of capturing login credentials — usernames and passwords — through phishing sites, malware, data breaches, or other means, typically for use in account takeover or sale on dark web markets.

Also known ascredential theftcredential compromisestolen credentials

In plain English

Credential harvesting is how attackers collect passwords at scale. Whether through a convincing fake login page, a keylogger installed via malware, or purchasing a dump from a previous data breach, attackers collect credentials and try them against corporate systems — often months or years after the original breach.

Keep learning

More terms in the IronSights Glossary.