Collecting usernames and passwords through fake login pages or forms, usually to take over accounts.
Credential harvesting funnels victims to a counterfeit login screen — a fake company portal, a bogus onboarding site — and captures whatever they type. Stolen credentials are then reused across other services, since many people repeat passwords.
Enabling two-factor authentication and using a password manager sharply limits the damage of harvested credentials.
Red flags
- A login page reached via an emailed link rather than the official site
- URL doesn't match the real service's domain
- Being asked to “verify” your password unexpectedly
Deep-dive guide
Job Board Credential Phishing: Fake Login Pages That Steal Your Accounts
Frequently asked questions
What do scammers do with harvested logins?
They take over the account, drain or misuse it, and try the same email-and-password combination on other sites. That's why reused passwords are so dangerous and two-factor authentication matters.