What is credential harvesting?
Credential harvesting is a type of cyber attack where threat actors steal user credentials, typically usernames and passwords.
Azərbaycanca: Kredensialların yığılması (credential harvesting) hücumu - təhlükəsizlik təhdidləri tərəfindən istifadəçilərin giriş məlumatlarının (adətən istifadəçi adı və parol) oğurlanması prosesidir.
How it works
Credential harvesting attacks are often carried out through phishing, malware, or exploiting vulnerabilities in public or corporate networks. Threats can also steal user credentials through specially crafted captive portal sites.
Defense checklist5
- 01
Implement Multi-Factor Authentication (MFA)
- 02
Educate users about suspicious emails and links
- 03
Conduct regular security audits on networks and systems
- 04
Enforce a strong password policy
- 05
Use Endpoint Detection and Response (EDR) solutions
Real-world evidence
The incidents Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting () and CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials () demonstrate large-scale credential harvesting operations. The first case involved a threat actor collecting.env files from multiple victims, and the second involved Midnight Blizzard (Storm-2945) stealing Microsoft 365 credentials via hotel Wi-Fi captive portals.
Sources
- RT by @TheDFIRReport: We identified an exposed server that provided unusual visibility into a large-scale, multi-victim exploitation and collection operation. Artifacts on the host showed that Claude Code and OpenClaw were embedded in the operator's day-to-day workflow, supporting troubleshooting, orchestration, and refinement of the collection pipeline. Logs indicated more than 900 confirmed compromises, with tens of thousands of harvested .env files spanning AI, cloud, payments, databases, messaging and more. Read the full report: https://thedfirreport.com/2026/04/22/bissa-scanner-exposed-ai-assisted-mass-exploitation-and-credential-harvesting/x_thedfirreport
- Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvestingdfirreport
- CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentialszscaler
Other attack types
See also6
This guide is AI-written from the real incident sources skopnix collected — the examples above are drawn from those cited items, nothing is invented.