Attack technique

Credential Harvesting

Credential harvesting is the theft of usernames, passwords, and other login data, usually through fake login pages or deceptive messages, so attackers can access accounts and systems.

Definition

Credential harvesting is the practice of collecting login credentials such as usernames, passwords, one-time codes, and session tokens through deceptive or fraudulent means. Attackers typically lure a victim to a counterfeit login page or trick them into entering details into an attacker-controlled form or message. The harvested credentials are then used to access email, banking, internal systems, or cloud services, or sold to other criminals. Credential harvesting is the goal behind a large share of phishing activity and is often the first step in account takeover, fraud, and wider network intrusion.

Most credential harvesting starts with a message that creates urgency or trust: an email, SMS, WhatsApp message, or voice call claiming to be from IT, a bank, a payroll system, or a familiar cloud provider. The link leads to a page that closely imitates a real login screen. When the victim types in their details, the page silently sends them to the attacker rather than the legitimate service. More advanced kits use reverse-proxy techniques (adversary-in-the-middle) that relay the login to the real site in real time, capturing the password and the resulting session token. This is significant because a stolen session can bypass some multi-factor authentication, so even careful users can be caught.

A common example: an employee at an Indonesian bank receives an email warning that their Microsoft 365 mailbox is full and will be locked. The link opens a pixel-perfect copy of the Microsoft sign-in page hosted on a lookalike domain. The employee enters their work password and the code from their authenticator app. Within minutes the attacker logs in, reads internal email, and sends invoice-redirection requests to finance. The same pattern appears in quishing (QR code) attacks, smishing, and fake HR or government portals.

Credential harvesting matters because identity is the new perimeter. One set of valid credentials can expose customer data, enable wire fraud, and trigger reportable incidents under frameworks such as OJK regulations, UU PDP Law 27/2022, and ISO 27001. Defenses combine phishing-resistant multi-factor authentication (such as passkeys or FIDO2 security keys), strict checking of sender and URL, conditional access policies, fast credential revocation, and ongoing security awareness training so people recognise and report fake login pages before they enter anything.

At a glance

Severity
High
Prevalence
Very common
Primary targets
Email, banking, and cloud service logins
Also known as
Credential phishing

How it works

  1. 1

    Lure: a message claiming to be from IT, a bank, or a cloud provider creates urgency or trust to prompt a click.

  2. 2

    Fake page: the link leads to a page that closely imitates a real login screen.

  3. 3

    Capture: when the victim enters their details, the page silently sends them to the attacker instead of the legitimate service.

  4. 4

    Session hijack: advanced kits use reverse-proxy techniques to relay the login in real time, capturing both the password and the session token, which can bypass some multi-factor authentication.

  5. 5

    Exploitation: the harvested credentials are used to access accounts directly or sold to other criminals, often triggering account takeover.

Warning signs

  • Login page URL that does not match the real service's domain
  • Message creating urgency about mailbox size, account suspension, or expiry
  • Login prompt appearing after clicking a link from an unexpected message
  • Requests for a one-time code immediately after entering a password
  • Slightly different branding, layout, or wording compared to the real login page

How to defend

  • Use phishing-resistant multi-factor authentication such as passkeys or FIDO2 keys
  • Check the URL carefully before entering any login details
  • Never follow login links from unsolicited messages; navigate directly instead
  • Apply conditional access policies that flag unusual login locations or devices
  • Report suspected fake login pages and rotate credentials immediately if entered

Real-world example

An employee at an Indonesian bank receives an email warning that their Microsoft 365 mailbox is full and will be locked. The link opens a pixel-perfect copy of the real sign-in page on a lookalike domain. The employee enters their password and authenticator code, and within minutes the attacker is reading internal email and sending invoice-redirection requests to finance.

How Claro helps

Claro lets security teams measure how their workforce responds to credential harvesting under realistic conditions. Phishing simulations can deploy fake but safe login pages across email, vishing, and WhatsApp channels, recording who clicks, who submits credentials, and who reports the attempt, without ever storing the real password. Each risky action triggers just-in-time micro-training that shows the specific warning signs the user missed, and the results feed individual and organisation-wide risk scores plus compliance evidence aligned to OJK, PDP, and ISO 27001. Over time this turns credential harvesting from an invisible exposure into a measurable, improvable behaviour.

Frequently asked questions

What is the difference between credential harvesting and account takeover?

Credential harvesting is the act of stealing login details, typically through fake login pages or deceptive messages. Account takeover is what happens next: using those stolen credentials to gain unauthorized control of the account. Credential harvesting is usually the first step toward account takeover.

Can multi-factor authentication stop credential harvesting?

It significantly reduces the risk, but advanced adversary-in-the-middle techniques can relay a real-time login and capture the resulting session token, bypassing weaker forms of MFA. Phishing-resistant methods like passkeys or FIDO2 security keys offer much stronger protection.

How can I tell a fake login page from a real one?

Check the URL carefully for misspellings or an unfamiliar domain, look for a padlock and valid certificate, and be suspicious of any login prompt that arrived after clicking a link in an unsolicited message. When in doubt, navigate to the service directly rather than clicking the link.

What should I do if I entered my password on a suspicious page?

Change that password immediately on the real service, enable or review multi-factor authentication, and report the incident to your security team so they can check for unauthorized access and revoke any active sessions.

Reduce your human risk

Claro measures and lowers the risk these terms describe, in English and Bahasa Indonesia.

Request a demo