Legit or Scam
Technology & AI

Credential Harvesting

Updated June 1, 2026Also called: credential theft, credential phishing

Collecting usernames and passwords through fake login pages or forms, usually to take over accounts.

Credential harvesting funnels victims to a counterfeit login screen — a fake company portal, a bogus onboarding site — and captures whatever they type. Stolen credentials are then reused across other services, since many people repeat passwords.

Enabling two-factor authentication and using a password manager sharply limits the damage of harvested credentials.

Red flags

  • A login page reached via an emailed link rather than the official site
  • URL doesn't match the real service's domain
  • Being asked to “verify” your password unexpectedly

Deep-dive guide

Job Board Credential Phishing: Fake Login Pages That Steal Your Accounts

Frequently asked questions

What do scammers do with harvested logins?

They take over the account, drain or misuse it, and try the same email-and-password combination on other sites. That's why reused passwords are so dangerous and two-factor authentication matters.

Related terms

Spot it before it costs you

Legit or Scam turns terms like this into instinct. Drop into real-world offers, recruiter DMs, and texts, and see how many you can call correctly.

Play Legit or Scam

Educational content only — not legal, financial, or security advice. Scenarios and company names are illustrative.