Opens in a new tab

Table of Contents

Explore AI Summary

Share post on:

What is Credential Harvesting, and How Does it Work?

Credential harvesting is the moment a phishing attempt turns into a real problem. It’s where a fraudster actually collects a working username and password,…

Sift Author Logo
Ben Price
black-dot
Press-Release-Tile-Image-Color-Pills_Blue

Credential harvesting is the moment a phishing attempt turns into a real problem. It’s where a fraudster actually collects a working username and password, ready to use immediately or sell to someone else. Understanding how modern harvesting techniques work and how far they have moved past the fake login page is the first step toward catching them before an account is compromised.

What credential harvesting is

Credential harvesting is the practice of tricking someone into voluntarily entering their login credentials into a page, form, or prompt controlled by a fraudster, who then captures and stores that information for later use. It’s typically the payoff stage of a phishing campaign where the email, text message, or QR code gets the victim to click on it, and the harvesting page is where the actual theft takes place.

Unlike credential stuffing, which uses previously breached credentials, or password spraying, which guesses at credentials, harvesting captures a real, current password directly from the account owner, often without the victim realizing anything happened. That immediacy is what makes harvested credentials especially valuable to fraudsters, since there is no delay between theft and a still-valid login.

How harvesting pages have gotten harder to spot

The classic version of credential harvesting, involving a crude fake login page with obvious typos, has largely given way to far more convincing infrastructure. Microsoft’s own data illustrates the shift: by March 2026, the company reported that credential phishing had grown to 94% of all payload-based attacks it tracked, while traditional malware delivery had fallen to just 5 to 6%. In other words, the overwhelming majority of what looks like a phishing attack today is not trying to install anything on the victim’s device. It is trying to harvest a login.

Adversary-in-the-middle, or AiTM, attacks represent the most sophisticated version of this shift. Instead of a static fake page, the attacker runs a live proxy between the victim and the real login service. The victim sees an authentic-looking login screen, because it genuinely is relaying the real one, enters their password, and even approves a multifactor authentication prompt, all while the proxy silently captures the resulting session token in the background. That session token can be just as valuable as the password itself, since it can sometimes grant access without needing to log in again at all.

Harvesting has also expanded well past email. Security firm KnowBe4 recently documented a persistent QR code phishing campaign targeting Australian organizations that used compromised Microsoft 365 accounts to distribute auto-generated PDF documents. Each PDF contained a QR code that, when scanned, directed victims to a Microsoft 365 credential harvesting page, and the campaign then propagated itself by reaching out to the compromised account’s own contact list.

Why credential harvesting is so effective right now

Credential harvesting is now even more successful than it used to be due to several compounding forces.

Harvesting pages are now easier than ever before to build and hard to trace back to their source, because phishing kits package the entire fake login experience, complete with brand impersonation, into a deployable toolkit that requires little technical skill to use. Many of these kits also add evasion techniques, such as CAPTCHA challenges that block automated security scanners while still letting real victims through, or IP filtering that hides the malicious page from anyone outside the intended target list.

The migration to QR codes and mobile-first scanning also creates a structural blind spot. When someone scans a QR code from a printed document or a physical sign using a personal phone, that phishing page loads outside the corporate network entirely, bypassing the email security gateways and web filtering that would normally catch a malicious link sent by email.

And because harvesting increasingly captures session tokens rather than just passwords, even organizations with strong multifactor authentication are not automatically protected. An AiTM attack that successfully relays a legitimate MFA approval defeats the very control most teams rely on as their last line of defense.

What actually reduces credential harvesting risk

Hope isn’t completely lost though, because there are actually a few defenses that meaningfully cut into how often credential harvesting succeeds.

Phishing-resistant multifactor authentication, such as passkeys or hardware security keys, defeats AiTM attacks specifically because these methods cryptographically verify the actual domain being logged into. If the domain does not match, authentication will fail, even if the victim has been completely fooled by the visual copy of the page. Monitoring for anomalous session behavior after login catches harvested session tokens being reused from an unexpected device or location. And treating QR codes, calendar invites, and other non-email channels as part of the phishing threat surface, rather than just an afterthought, closes the blind spot that email-focused security tools miss entirely.

This is also where behavioral signals earn their keep. A session that starts with a technically valid login but comes from a device, network, or pattern of activity the real account owner has never shown before is exactly the kind of mismatch Account Defense is built to catch. 

Sift works by assessing thousands of signals across the user journey and aggregates them into a Sift Score from 1 to 100, where 1 indicates a trustworthy user and 100 indicates likely fraud, updating in real time. That continuous evaluation matters most in exactly the cases where the password and even the MFA prompt checked out, but the session behind them did not belong to the real user.

If your team needs help stopping credential harvesting threats on your platform, then Sift might be the perfect solution. Read more about how Sift can help.

Frequently asked questions

Is credential harvesting the same thing as phishing?

Credential harvesting is the final stage of a phishing attack. Phishing describes the broader deception, whether by email, text, or QR code, that lures a victim toward a malicious page. Credential harvesting is the act of capturing the login information once the victim arrives there.

Can multifactor authentication stop credential harvesting?

Standard MFA, such as a one-time code or push notification, can be defeated by adversary-in-the-middle attacks that relay the approval in real time. Phishing-resistant MFA methods, like passkeys or hardware security keys, are far more effective because they verify the actual domain cryptographically rather than relying on the user to notice something is wrong.

Why are QR codes increasingly used for credential harvesting?

QR codes let attackers route victims to a malicious page from a personal device or a printed document, bypassing corporate email security and web filtering entirely. Because the scan often happens on a phone outside the corporate network, the usual layers of defense never get a chance to inspect the link.

Dare to grow differently.

Flip the switch on fraud-fueled fear. Make risk work for your business and scale securely into new markets with Sift’s AI-powered platform.

see sift in action
  • remitly
  • swan
  • yelp-white
  • taptap
  • remitly
  • swan
  • yelp-white
  • taptap