Technology

Billions of Stolen Browser Cookies Expose Users to Account Hijacking

Experts warn that authentication cookies have become more valuable to cybercriminals than passwords, allowing attackers to hijack online accounts without logging in. The post Billions of Stolen Browser Cookies Expose...

AAdmin
August 5, 2026
3 min read
Billions of Stolen Browser Cookies Expose Users to Account Hijacking

Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account hijacking, according to a report released Monday by a VPN service provider.

From June 2025 through June 2026, NordVPN researchers analyzed more than 52.4 billion browser cookies found in infostealer logs offered for sale on dark web forums and Telegram marketplaces.

Although a small percentage of the stolen cookies remained active, live authentication cookies can give attackers immediate access to online accounts.

"This scale shows why browser cookies have become such a valuable target," Domantas Lapinskas wrote in a NordVPN blog.

He noted that advertising and tracking cookies accounted for the largest share of the stolen cookies in the study, although experts say authentication cookies — while far less common — pose the greatest security risk.

"We all know that cookies are valuable because some of them keep you logged in," said Rich Pleeth, co-founder of Finmile , an AI logistics SaaS company in London.

"But if a criminal steals the right cookie, they may be able to access your email, bank, or company account without needing your password, and sometimes without triggering two-factor authentication," he told TechNewsWorld.

A session cookie serves as proof to the server that a user has already authenticated, explained Sila Özeren Hacioglu, an associate security research engineer at Picus Security , a global cyberattack simulation company.

"When you log in with a password and clear MFA [multi-factor authentication], the site issues a session cookie so it stops asking who you are," she told TechNewsWorld. "If an attacker steals that cookie and replays it from their own browser, the server sees a valid, already-authenticated session — no password, no MFA prompt, no passkey challenge."

"That's why we now say 'the cookie is the new password,'" she added.

Hacioglu maintained that infostealers target cookies precisely because they short-circuit every login-time control. "NordVPN's newest dataset found that cookie records appeared 4.6 times more frequently than passwords, payment-card details and files combined," she said. "This might be evidence that operators are now prizing session data over credentials."

"Cookies from Google and Microsoft accounts are doubly valuable," she continued, "because those same identities are the single-sign-on and MFA gateway to dozens of downstream services."

"Most cookies are commercially worthless to infostealers," she explained. "A tracking cookie describes you, an authentication cookie vouches for you. Only the second category matters, and it's a small fraction of any enormous haul."

"That's why the headline 'billions stolen' is misleading," she argued. "Volume isn't the story. A handful of live session tokens is."

A stolen session cookie is the digital equivalent of stealing someone's already-swiped keycard rather than picking a lock, contended Francis West , CEO of Security Everywhere, a cybersecurity company in Hemel Hempstead, England.

"This is exactly why we’re seeing infostealer malware increasingly target browsers specifically," he told TechNewsWorld. "A single infected device can yield dozens of live sessions — email, banking, cloud storage, corporate SaaS tools — all at once, and stolen cookie batches are now actively traded on criminal marketplaces."

Over the last two years, stealing session cookies has moved from a secondary benefit of credential…