Skip to main content

Credential harvesting

Credential harvesting is the large-scale collection of usernames and passwords, usually through phishing pages that imitate a real login, for use in fraud or account takeover.

How it works

A harvesting page copies a brand login screen and captures whatever the victim types, sometimes relaying it to the real site in real time to defeat multi-factor authentication. The stolen credentials are then used directly, sold, or fed into credential-stuffing tools against other services.

These pages are mass-produced with phishing kits and hosted on lookalike or compromised domains.

How it relates to brand impersonation

Credential harvesting is the payoff of most brand-impersonation phishing: your login page, faked, to steal your customers access. Taking the page down stops the collection.

How nebty helps

nebty detects harvesting pages impersonating your login and takes them down on demand, with blacklisting in parallel so users are warned during the takedown.

Takedown service

Why MFA is not a complete answer

Harvesting used to be simple: a fake login captured a username and password, and turning on multi-factor authentication largely defeated reuse of what was stolen. Attackers adapted. Modern harvesting kits relay the login to the real site in real time, so the victim completes the genuine MFA step and the kit captures the resulting session token, which logs the attacker in with MFA already satisfied. That is why phishing-resistant methods like passkeys and hardware keys matter, since they bind the login to the real domain and will not authenticate against a lookalike. For everyone else, the page itself is the weak point: it lives on a lookalike or compromised domain that monitoring can detect, and taking it down, with blacklisting in parallel, stops the collection regardless of which MFA the victims were using.

A concrete example

A harvesting page goes live at solara-finance-login.com, a clone of the Solara Finance sign-in, fed by a text-message campaign. Over one weekend it collects several hundred credential pairs, each relayed to the real site in real time so victims complete their genuine MFA step without noticing. By Monday the stolen sessions are being used to change payout details. The response has three parts: blacklist the URL so browsers warn immediately, take the domain down, and force resets on every account that logged in during the window.

How to spot and stop it

  1. Move staff and, where possible, customers to phishing-resistant authentication such as passkeys. They refuse to authenticate against a lookalike domain.
  2. Monitor for cloned login pages on lookalike domains. The page must exist before the campaign starts, which is your detection window.
  3. When a harvest is confirmed, blacklist and take down the page, then reset credentials and sessions for the exposure window rather than waiting for fraud reports.

Frequently asked questions

What happens to harvested credentials?

They get used directly for account takeover, sold in bulk on underground markets, or fed into credential stuffing against other services. Since many people reuse passwords, one harvested login often opens accounts far beyond the site that was cloned.

Does multi-factor authentication protect against credential harvesting?

Against the classic fake login, yes. Modern kits relay the login in real time and steal the session after the victim completes MFA, so code-based factors no longer guarantee safety. Passkeys and hardware keys resist this, because they are bound to the real domain.

See who is impersonating your brand

The free nebty report scans the web for lookalike domains and fake profiles targeting your brand, with no obligation.

Get your free report