Credential Harvesting

Credential harvesting is the systematic collection of user names, passwords, and multi-factor authentication codes through phishing or malicious software. In financial markets, this information is used to gain unauthorized access to exchange accounts, enabling attackers to trade against the victim's balance or withdraw funds.

Attackers often use sophisticated landing pages that mirror the look and feel of major exchanges to capture these details in real time. Defense relies on using hardware-based security keys for two-factor authentication, which are resistant to traditional phishing.

Additionally, maintaining unique passwords across all financial platforms is a basic but effective deterrent. Vigilance against unexpected login requests is the final line of defense against these persistent threats.

Compliance Officer Roles
Cross Border Financial Law
Internal Investigation Procedures
Wallet Drainer Scripts
Conflict of Laws in DeFi
Lookback Put Options
Compliance Costs
Interoperable Messaging Standards