SUBSCRIBE
Tech Journal Now
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Reading: Billions of Stolen Browser Cookies Expose Users to Account Hijacking
Share
Tech Journal NowTech Journal Now
Font ResizerAa
  • News
  • Reviews
  • Guides
  • AI
  • Best Buy
  • Games
  • Software
Search
  • Home
  • News
  • AI
  • Reviews
  • Guides
  • Best Buy
  • Software
  • Games
  • More Articles
Have an existing account? Sign In
Follow US
© Foxiz News Network. Ruby Design Company. All Rights Reserved.
Tech Journal Now > News > Billions of Stolen Browser Cookies Expose Users to Account Hijacking
News

Billions of Stolen Browser Cookies Expose Users to Account Hijacking

News Room
Last updated: August 5, 2026 12:23 pm
News Room
Share
9 Min Read
SHARE

Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account hijacking, according to a report released Monday by a VPN service provider.

From June 2025 through June 2026, NordVPN researchers analyzed more than 52.4 billion browser cookies found in infostealer logs offered for sale on dark web forums and Telegram marketplaces.

Although a small percentage of the stolen cookies remained active, live authentication cookies can give attackers immediate access to online accounts.

“This scale shows why browser cookies have become such a valuable target,” Domantas Lapinskas wrote in a NordVPN blog.

He noted that advertising and tracking cookies accounted for the largest share of the stolen cookies in the study, although experts say authentication cookies — while far less common — pose the greatest security risk.

“We all know that cookies are valuable because some of them keep you logged in,” said Rich Pleeth, co-founder of Finmile, an AI logistics SaaS company in London.

“But if a criminal steals the right cookie, they may be able to access your email, bank, or company account without needing your password, and sometimes without triggering two-factor authentication,” he told TechNewsWorld.

A session cookie serves as proof to the server that a user has already authenticated, explained Sila Özeren Hacioglu, an associate security research engineer at Picus Security, a global cyberattack simulation company.

“When you log in with a password and clear MFA [multi-factor authentication], the site issues a session cookie so it stops asking who you are,” she told TechNewsWorld. “If an attacker steals that cookie and replays it from their own browser, the server sees a valid, already-authenticated session — no password, no MFA prompt, no passkey challenge.”

“That’s why we now say ‘the cookie is the new password,'” she added.

Session Data Prized Over Credentials

Hacioglu maintained that infostealers target cookies precisely because they short-circuit every login-time control. “NordVPN’s newest dataset found that cookie records appeared 4.6 times more frequently than passwords, payment-card details and files combined,” she said. “This might be evidence that operators are now prizing session data over credentials.”

“Cookies from Google and Microsoft accounts are doubly valuable,” she continued, “because those same identities are the single-sign-on and MFA gateway to dozens of downstream services.”

“Most cookies are commercially worthless to infostealers,” she explained. “A tracking cookie describes you, an authentication cookie vouches for you. Only the second category matters, and it’s a small fraction of any enormous haul.”

“That’s why the headline ‘billions stolen’ is misleading,” she argued. “Volume isn’t the story. A handful of live session tokens is.”

A stolen session cookie is the digital equivalent of stealing someone’s already-swiped keycard rather than picking a lock, contended Francis West, CEO of Security Everywhere, a cybersecurity company in Hemel Hempstead, England.

“This is exactly why we’re seeing infostealer malware increasingly target browsers specifically,” he told TechNewsWorld. “A single infected device can yield dozens of live sessions — email, banking, cloud storage, corporate SaaS tools — all at once, and stolen cookie batches are now actively traded on criminal marketplaces.”

Over the last two years, stealing session cookies has moved from a secondary benefit of credential theft to the primary objective of stealer malware, added Adrian Cheek, a senior cybercrime researcher at Flare, a threat intelligence company in Montreal.

“It also breaks the standard incident response sequence,” he told TechNewsWorld. “Rotating a password has no effect on a stolen cookie. The session stays live until it is explicitly revoked or expires on its own.”

Fast and Quiet Malware

Cheek explained that cookies are overwhelmingly stolen by infostealer malware running on a victim’s device. “The malware is fast and quiet,” he said. “It requires no administrative privileges and does not need to persist.”

“A single execution reads every browser profile on the machine and exits,” he continued. “The resulting stealer log is a ZIP archive containing cookies, saved credentials, autofill data, browsing history, installed software, clipboard contents, and a screenshot of the desktop taken at the moment of compromise.”

“Fake recruitment exercises and trojanized software projects are another increasingly common lure, particularly for developers and other technical users,” added Bogdan Botezatu, senior director for threat research and reporting at Bitdefender, a global cybersecurity technology company.

“A very popular delivery mechanism called ‘ClickFix’ helps cybercriminals install infostealers by impersonating Captcha boxes that manipulate a user’s clipboard to run dangerous commands in the system terminal,” he told TechNewsWorld.

He also noted that cookies can be captured through malicious browser extensions, compromised websites, or adversary-in-the-middle phishing pages that relay a real login and intercept the resulting session. “Modern HTTPS makes simple interception over the local network much less useful than infecting the endpoint or manipulating the authentication process itself,” he explained.

More Than Antivirus Needed

NordVPN also reported finding stolen cookies from devices that had security software installed. Among stealer logs that identified installed security software, 96.3% named Windows Defender, while the rest referenced commercial antivirus suites, it noted.

“Antivirus can detect and remove most infostealer strains,” Paul Bischoff, a consumer privacy advocate at Comparitech, a reviews, advice and information website for consumer security products, told TechNewsWorld.

“However,” he added, “they do not make you immune.”

Antivirus remains important, but it is not an airtight control, cautioned Deric Palmer, chief digital risk officer at the ASC3ND Technologies Group, a cybersecurity and IT modernization firm in Washington, D.C.

“Infostealers frequently change their code, delivery methods and behavior to evade signature-based detection, and users may override security warnings or install malicious software themselves,” he told TechNewsWorld.

He recommended antivirus should be treated as one layer alongside prompt patching, endpoint monitoring, browser controls, application allowlisting and safer user behavior.

A more durable fix to the problem is making the stolen cookie useless, argued Chris Boehm, chief technology officer for Zero Networks, a provider of automated microsegmentation, zero trust networking, identity-based access control, and secure remote access in Tel Aviv, Israel.

“That’s what Google shipped in Chrome 146, with Device Bound Session Credentials, tying the session to a key inside the TPM or Secure Enclave,” he told TechNewsWorld. “Sites have to adopt it on their end, so coverage will take time.”

Strong Passwords, MFA Not Enough

ASC3ND’s Palmer contended that cookie theft exposes a blind spot in how people think about account security. “Strong passwords and multi-factor authentication protect the login process, but they may not stop an attacker who steals the authenticated session after the login has already occurred,” he observed.

“The industry needs to place greater emphasis on short-lived sessions, device-bound authentication, continuous risk evaluation and rapid session revocation,” he said.

“Most people assume cookie consent banners are a safety feature, but those come from European law under the ePrivacy Directive and GDPR, and they govern what a website may place on your device rather than what malware takes off your laptop,” added Zero Networks’ Boehm.

“The industry spent 15 years telling people a strong password plus MFA meant they were safe, and this data shows that advice was incomplete,” he noted. “Attackers stopped attacking the front door and started stealing the proof that you already walked through it.”

Read the full article here

You Might Also Like

Former pro athlete bets big on ‘Barkie’ and AI as a caddie – GeekWire

Amazon helps fund free shuttle service for Bellevue light rail riders – GeekWire

VC is changing dramatically — what’s a founder to do?  – GeekWire

Anthropic expands in Seattle as AI boom offers hope for struggling office market – GeekWire

Next-gen battery startup Sila raises $300M to expand manufacturing plant in Washington state – GeekWire

Share This Article
Facebook Twitter Email Print
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Trending Stories

Microsoft moves to limit AI use by its employees

August 5, 2026
News

Live dating show reveals Seattle’s relationship with tech is still complicated – GeekWire

August 5, 2026
Games

Destiny 2 players are learning how to crack into its infamous content vault by tinkering with old builds

August 5, 2026
News

Washington state’s next-gen ferry era kicks off with 3 new hybrid boats in $1.15B deal – GeekWire

August 5, 2026
Games

Grand Theft Auto 6 publisher is holding an investors call at a very unusual time this week

August 5, 2026
News

Google to cut 52 employees in Washington state – GeekWire

August 5, 2026

Always Stay Up to Date

Subscribe to our newsletter to get our newest articles instantly!

Follow US on Social Media

Facebook Youtube Steam Twitch Unity

2024 © Prices.com LLC. All Rights Reserved.

Tech Journal Now

Quick Links

  • Privacy Policy
  • Terms of use
  • For Advertisers
  • Contact
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?