Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account hijacking, according to a report released Monday by a VPN service provider.
From June 2025 through June 2026, NordVPN researchers analyzed more than 52.4 billion browser cookies found in infostealer logs offered for sale on dark web forums and Telegram marketplaces.
Although a small percentage of the stolen cookies remained active, live authentication cookies can give attackers immediate access to online accounts.
“This scale shows why browser cookies have become such a valuable target,” Domantas Lapinskas wrote in a NordVPN blog.
He noted that advertising and tracking cookies accounted for the largest share of the stolen cookies in the study, although experts say authentication cookies — while far less common — pose the greatest security risk.
“We all know that cookies are valuable because some of them keep you logged in,” said Rich Pleeth, co-founder of Finmile, an AI logistics SaaS company in London.
“But if a criminal steals the right cookie, they may be able to access your email, bank, or company account without needing your password, and sometimes without triggering two-factor authentication,” he told TechNewsWorld.
A session cookie serves as proof to the server that a user has already authenticated, explained Sila Özeren Hacioglu, an associate security research engineer at Picus Security, a global cyberattack simulation company.
“When you log in with a password and clear MFA [multi-factor authentication], the site issues a session cookie so it stops asking who you are,” she told TechNewsWorld. “If an attacker steals that cookie and replays it from their own browser, the server sees a valid, already-authenticated session — no password, no MFA prompt, no passkey challenge.”
“That’s why we now say ‘the cookie is the new password,'” she added.
Session Data Prized Over Credentials
Hacioglu maintained that infostealers target cookies precisely because they short-circuit every login-time control. “NordVPN’s newest dataset found that cookie records appeared 4.6 times more frequently than passwords, payment-card details and files combined,” she said. “This might be evidence that operators are now prizing session data over credentials.”
“Cookies from Google and Microsoft accounts are doubly valuable,” she continued, “because those same identities are the single-sign-on and MFA gateway to dozens of downstream services.”
“Most cookies are commercially worthless to infostealers,” she explained. “A tracking cookie describes you, an authentication cookie vouches for you. Only the second category matters, and it’s a small fraction of any enormous haul.”
“That’s why the headline ‘billions stolen’ is misleading,” she argued. “Volume isn’t the story. A handful of live session tokens is.”
A stolen session cookie is the digital equivalent of stealing someone’s already-swiped keycard rather than picking a lock, contended Francis West, CEO of Security Everywhere, a cybersecurity company in Hemel Hempstead, England.
“This is exactly why we’re seeing infostealer malware increasingly target browsers specifically,” he told TechNewsWorld. “A single infected device can yield dozens of live sessions — email, banking, cloud storage, corporate SaaS tools — all at once, and stolen cookie batches are now actively traded on criminal marketplaces.”
Over the last two years, stealing session cookies has moved from a secondary benefit of credential theft to the primary objective of stealer malware, added Adrian Cheek, a senior cybercrime researcher at Flare, a threat intelligence company in Montreal.
“It also breaks the standard incident response sequence,” he told TechNewsWorld. “Rotating a password has no effect on a stolen cookie. The session stays live until it is explicitly revoked or expires on its own.”
Fast and Quiet Malware
Cheek explained that cookies are overwhelmingly stolen by infostealer malware running on a victim’s device. “The malware is fast and quiet,” he said. “It requires no administrative privileges and does not need to persist.”
“A single execution reads every browser profile on the machine and exits,” he continued. “The resulting stealer log is a ZIP archive containing cookies, saved credentials, autofill data, browsing history, installed software, clipboard contents, and a screenshot of the desktop taken at the moment of compromise.”
“Fake recruitment exercises and trojanized software projects are another increasingly common lure, particularly for developers and other technical users,” added Bogdan Botezatu, senior director for threat research and reporting at Bitdefender, a global cybersecurity technology company.
“A very popular delivery mechanism called ‘ClickFix’ helps cybercriminals install infostealers by impersonating Captcha boxes that manipulate a user’s clipboard to run dangerous commands in the system terminal,” he told TechNewsWorld.
He also noted that cookies can be captured through malicious browser extensions, compromised websites, or adversary-in-the-middle phishing pages that relay a real login and intercept the resulting session. “Modern HTTPS makes simple interception over the local network much less useful than infecting the endpoint or manipulating the authentication process itself,” he explained.
More Than Antivirus Needed
NordVPN also reported finding stolen cookies from devices that had security software installed. Among stealer logs that identified installed security software, 96.3% named Windows Defender, while the rest referenced commercial antivirus suites, it noted.
“Antivirus can detect and remove most infostealer strains,” Paul Bischoff, a consumer privacy advocate at Comparitech, a reviews, advice and information website for consumer security products, told TechNewsWorld.
“However,” he added, “they do not make you immune.”
Antivirus remains important, but it is not an airtight control, cautioned Deric Palmer, chief digital risk officer at the ASC3ND Technologies Group, a cybersecurity and IT modernization firm in Washington, D.C.
“Infostealers frequently change their code, delivery methods and behavior to evade signature-based detection, and users may override security warnings or install malicious software themselves,” he told TechNewsWorld.
He recommended antivirus should be treated as one layer alongside prompt patching, endpoint monitoring, browser controls, application allowlisting and safer user behavior.
A more durable fix to the problem is making the stolen cookie useless, argued Chris Boehm, chief technology officer for Zero Networks, a provider of automated microsegmentation, zero trust networking, identity-based access control, and secure remote access in Tel Aviv, Israel.
“That’s what Google shipped in Chrome 146, with Device Bound Session Credentials, tying the session to a key inside the TPM or Secure Enclave,” he told TechNewsWorld. “Sites have to adopt it on their end, so coverage will take time.”
Strong Passwords, MFA Not Enough
ASC3ND’s Palmer contended that cookie theft exposes a blind spot in how people think about account security. “Strong passwords and multi-factor authentication protect the login process, but they may not stop an attacker who steals the authenticated session after the login has already occurred,” he observed.
“The industry needs to place greater emphasis on short-lived sessions, device-bound authentication, continuous risk evaluation and rapid session revocation,” he said.
“Most people assume cookie consent banners are a safety feature, but those come from European law under the ePrivacy Directive and GDPR, and they govern what a website may place on your device rather than what malware takes off your laptop,” added Zero Networks’ Boehm.
“The industry spent 15 years telling people a strong password plus MFA meant they were safe, and this data shows that advice was incomplete,” he noted. “Attackers stopped attacking the front door and started stealing the proof that you already walked through it.”





