• Menu Item
  • STORIES
    • TECH
    • AUTOMOTIVE
    • GUIDES
    • OPINIONS
  • REVIEWS
    • READERS’ CHOICE
    • ALL REVIEWS
    • ━
    • SMARTPHONES
    • CARS
    • HEADPHONES
    • ACCESSORIES
    • LAPTOPS
    • TABLETS
    • WEARABLES
    • SPEAKERS
    • APPS
  • SCREEN
    • TV & MOVIES REVIEWS
    • SPOTLIGHT
  • GAMING
    • GAMING NEWS
    • GAMING REVIEWS
  • +
    • OUR STORY
    • GET IN TOUCH
  • n
  • m
  • Menu Item
  • STORIES
    • TECH
    • AUTOMOTIVE
    • GUIDES
    • OPINIONS
  • REVIEWS
    • READERS’ CHOICE
    • ALL REVIEWS
    • ━
    • SMARTPHONES
    • CARS
    • HEADPHONES
    • ACCESSORIES
    • LAPTOPS
    • TABLETS
    • WEARABLES
    • SPEAKERS
    • APPS
  • SCREEN
    • TV & MOVIES REVIEWS
    • SPOTLIGHT
  • GAMING
    • GAMING NEWS
    • GAMING REVIEWS
  • +
    • OUR STORY
    • GET IN TOUCH
  • n
  • m
Follow US

52 billion stolen cookies reveal a growing shift in cybercriminal tactics

JANE A.
JANE A.
39 minutes ago

Cybercriminals are shifting their focus away from passwords and toward browser session data, according to new research from NordVPN, which says it identified more than 52.4 billion stolen browser cookies in historical infostealer datasets collected over a one-year period. The findings highlight how session hijacking has become a growing concern for both consumers and businesses, allowing attackers to access online accounts without ever knowing a user’s password.

The research suggests browser cookies now represent one of the most valuable pieces of information harvested by malware operators. In the datasets analyzed, cookie records appeared 4.6 times more frequently than passwords, payment card details, files, and other stolen information combined. Rather than breaking into accounts through traditional credential theft, attackers increasingly rely on active session cookies that effectively prove a user has already authenticated.

That shift has practical consequences. If an attacker obtains a valid session cookie, they may be able to access an account immediately, bypassing login screens and, in some cases, even multi-factor authentication. Security researchers commonly refer to this technique as session hijacking, and it has become a recurring feature of modern infostealer campaigns.

The study also illustrates how widespread the problem has become. NordVPN’s researchers traced stolen cookie records across more than 250 countries and territories. India accounted for the largest volume of records in the dataset, followed by Brazil, the United States, Indonesia, and the Philippines.

For the United Arab Emirates, the report identified approximately 210.5 million cookie records, placing the country 39th globally in the analyzed data. The figures represent cumulative cookie records rather than unique users or individual devices, meaning they should not be interpreted as the number of compromised people.

The types of accounts appearing in the stolen datasets also challenge common assumptions about cybercrime. While financial services remain attractive targets, the research found that everyday consumer platforms featured prominently among compromised records. Google, Facebook, and Microsoft appeared most frequently, while entertainment and social platforms including Netflix, Twitch, YouTube, Reddit, Discord, Roblox, and Instagram were also represented. These services may not contain financial information directly, but they often provide access to personal data, subscription services, and linked accounts that can be exploited or resold.

Perhaps one of the more notable findings is that traditional endpoint protection alone may not be enough. According to the analyzed logs, more than 96% of infections occurred on devices where security software was already active. While that does not necessarily indicate antivirus products failed, it reflects the evolving nature of infostealer malware, which increasingly focuses on stealing authenticated browser sessions rather than defeating security software outright.

NordVPN says users should respond quickly if they suspect browser data has been compromised by signing out of affected accounts, clearing browser data, and forcing new authenticated sessions. Those steps invalidate previously issued session cookies, reducing the window of opportunity for attackers.

The findings are based on historical infostealer data analyzed through the NordStellar platform between June 9, 2025, and June 8, 2026, alongside a limited set of anonymized insights from NordVPN’s hijacked session alert system collected earlier this year. While the research does not measure the total number of compromised users, it reflects a broader trend across the cybersecurity industry: protecting passwords is no longer enough when attackers increasingly target the browser sessions that keep users logged in.

Share
What do you think?
Happy0
Sad0
Love0
Surprise0
Cry0
Angry0
Dead0

WHAT'S HOT ❰

Google Health explores visual summaries for medical test results
WhatsApp tests new Mac update channels for beta users
FITBIT data can now sync directly with Apple Health on iPhone
Apple refreshes Accessories Store with smarter browsing
Wikipedia expands iOS app with interactive Random Article widget
Follow US
AbsoluteGeeks.com was assembled during a caffeine incident.
© Absolute Geeks Media FZE LLC 2014–2026.
Proudly made in Dubai, UAE ❤️
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?