Threats

What is credential harvesting? How phishing steals logins

Phish Plug ResearchSeptember 18, 20268 min read

Behind most phishing is one simple goal: get you to type your password somewhere the attacker controls. That is credential harvesting — the engine that powers account takeover, fraud and data breaches. Understand how the pipeline works and you can see exactly where to break it.

The anatomy of a harvesting attack

A credential-harvesting operation usually runs in four moves:

  1. Lure — an email, text or ad creates urgency: "your account is locked," "confirm your details," "unusual sign-in." It carries a link.
  2. Fake login page — the link leads to a convincing clone of a real sign-in screen, often on a lookalike domain and frequently cloaked so scanners see a harmless page.
  3. Capture — the victim types their real username and password. The page sends them instantly to the attacker, sometimes while showing a fake error to buy time.
  4. Use — the credentials are used for takeover, sold in bulk, or replayed against other services, since many people reuse passwords.

The victim never sees anything go wrong. The page may even forward them to the real site afterwards, so the login 'works' and nothing feels off — while the attacker already has the password.

Why it is so effective

Credential harvesting works because it attacks people, not systems. A perfect clone of a login page needs no software vulnerability — just a plausible reason to visit and a page that looks right. Three factors make it worse:

  • Cloaking hides the fake page from automated scanners, so it stays online longer.
  • Lookalike domains make the address bar look close enough to pass a glance.
  • Password reuse means one harvested login often unlocks several accounts.

Does two-factor stop it?

Two-factor authentication raises the bar, and you should use it. But modern phishing kits increasingly harvest one-time codes as well, relaying them to the real site in real time before they expire. Phishing-resistant methods such as passkeys help more. Still, the most direct defence is not leaving the fake page online in the first place.

Breaking the pipeline

Every stage is a chance to intervene, but the highest-leverage move is removing the harvesting page itself:

  1. Detect the fake login page early — ideally from the lookalike domain before the campaign scales.
  2. Prove the impersonation, including any cloaking, with dual-profile capture and raw headers.
  3. Take it down via the host, registrar and safe-browsing feeds, so the link dies and browsers warn users.
  4. Track to confirmed removal, then watch for the next variant — harvesting operations rarely stop at one page.

Phish Plug targets the harvesting page directly: it finds the clone, proves the cloaking that hides it, and files the takedown to cut the credential pipeline at its source.

The takeaway

Credential harvesting is the quiet engine behind most phishing damage: a believable login page, a moment of urgency, and your customers' passwords are gone. You cannot patch human trust, but you can remove the page that exploits it. Find the clone, prove it, take it down — and keep watching for the next one.

Put detection and takedowns on autopilot

Run a free clone check on one domain — Phish Plug proves the cloaking and builds the case for you.