Urgency-based credential theft manufactures a false emergency or artificial deadline so a target discloses credentials, one-time codes, or authenticating information before they have time to stop, think, or verify. It is less a distinct delivery channel than a pressure layer bolted onto nearly every credential-phishing effort: the attacker fabricates a stake and a clock.
The stake is loss — “your account will be closed,” “a fraudulent charge is posting,” “you missed a package.” The clock is a countdown — “within 24 hours,” “before this call ends.” Because independent verification is the single behavior that defeats most social engineering, compressing or eliminating the time to verify is the operative move, not the specific story told. It appears everywhere: email and SMS that drive clicks to credential-capture pages; vishing “agents” who talk over hesitation and insist a code be read back “to secure the account right now”; and adversary-in-the-middle kits that rush a victim through a real login and a live-relayed one-time passcode before it expires.
The defining diagnostic is inverted in its clearest form: honest security processes tolerate your slowing down to verify; this technique punishes it.