• Home
  • News
  • World
  • Business
  • Politics
  • Tech
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Travel
  • More
    • Web stories
    • Trending
    • Press Release

Subscribe to Updates

Get the latest USA News and updates directly to your inbox.

What's On
Mahomes Mountain: Is Patrick Mahomes Still NFL’s Best QB? Nick Wright Tiers QBs

Mahomes Mountain: Is Patrick Mahomes Still NFL’s Best QB? Nick Wright Tiers QBs

August 13, 2026
Lindsay Clancy sobs loudly, says “I can’t do it” amid gruesome murder trial testimony

Lindsay Clancy sobs loudly, says “I can’t do it” amid gruesome murder trial testimony

August 13, 2026
Historic Valbonne estate loved by Duran Duran is now up for sale

Historic Valbonne estate loved by Duran Duran is now up for sale

August 13, 2026
Why Jon Hamm Changed His Mind About Having Kids Since He Met Wife Anna Osceola (Exclusive)

Why Jon Hamm Changed His Mind About Having Kids Since He Met Wife Anna Osceola (Exclusive)

August 13, 2026
Wake Up With BroadwayWorld August 13, 2026- Betsy Wolfe & Ethan Slater Talk LITTLE SHOP OF HORRORS and More

Wake Up With BroadwayWorld August 13, 2026- Betsy Wolfe & Ethan Slater Talk LITTLE SHOP OF HORRORS and More

August 13, 2026
Facebook X (Twitter) Instagram
Just In
  • Mahomes Mountain: Is Patrick Mahomes Still NFL’s Best QB? Nick Wright Tiers QBs
  • Lindsay Clancy sobs loudly, says “I can’t do it” amid gruesome murder trial testimony
  • Historic Valbonne estate loved by Duran Duran is now up for sale
  • Why Jon Hamm Changed His Mind About Having Kids Since He Met Wife Anna Osceola (Exclusive)
  • Wake Up With BroadwayWorld August 13, 2026- Betsy Wolfe & Ethan Slater Talk LITTLE SHOP OF HORRORS and More
  • Billions of Stolen Browser Cookies Fuel Account Hijacking Risks
  • Harvard-China links unearthed as Congress finds 140 papers co-authored by CCP military universities
  • 10 NFL Players Positioning Themselves For A Breakthrough 2026 Season
  • Privacy Policy
  • Advertise
  • Contact
US Times MirrorUS Times Mirror
Newsletter
  • Home
  • News
  • World
  • Business
  • Politics
  • Tech
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Travel
  • More
    • Web stories
    • Trending
    • Press Release
 Weather Login
US Times MirrorUS Times Mirror
Home » Billions of Stolen Browser Cookies Fuel Account Hijacking Risks
Tech

Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

staffstaffAugust 13, 20261 ViewsNo Comments
Facebook Twitter WhatsApp Telegram Pinterest Email
Billions of Stolen Browser Cookies Fuel Account Hijacking Risks

Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account hijacking, according to a report released Monday by a VPN service provider.

From June 2025 through June 2026, NordVPN researchers analyzed more than 52.4 billion browser cookies found in infostealer logs offered for sale on dark web forums and Telegram marketplaces.

Although a small percentage of the stolen cookies remained active, live authentication cookies can give attackers immediate access to online accounts.

“This scale shows why browser cookies have become such a valuable target,” Domantas Lapinskas wrote in a NordVPN blog.

He noted that advertising and tracking cookies accounted for the largest share of the stolen cookies in the study, although experts say authentication cookies — while far less common — pose the greatest security risk.

“We all know that cookies are valuable because some of them keep you logged in,” said Rich Pleeth, co-founder of Finmile, an AI logistics SaaS company in London.

“But if a criminal steals the right cookie, they may be able to access your email, bank, or company account without needing your password, and sometimes without triggering two-factor authentication,” he told TechNewsWorld.

A session cookie serves as proof to the server that a user has already authenticated, explained Sila Özeren Hacioglu, an associate security research engineer at Picus Security, a global cyberattack simulation company.

“When you log in with a password and clear MFA [multi-factor authentication], the site issues a session cookie so it stops asking who you are,” she told TechNewsWorld. “If an attacker steals that cookie and replays it from their own browser, the server sees a valid, already-authenticated session — no password, no MFA prompt, no passkey challenge.”

“That’s why we now say ‘the cookie is the new password,'” she added.

Session Data Prized Over Credentials

Hacioglu maintained that infostealers target cookies precisely because they short-circuit every login-time control. “NordVPN’s newest dataset found that cookie records appeared 4.6 times more frequently than passwords, payment-card details and files combined,” she said. “This might be evidence that operators are now prizing session data over credentials.”

“Cookies from Google and Microsoft accounts are doubly valuable,” she continued, “because those same identities are the single-sign-on and MFA gateway to dozens of downstream services.”

“Most cookies are commercially worthless to infostealers,” she explained. “A tracking cookie describes you, an authentication cookie vouches for you. Only the second category matters, and it’s a small fraction of any enormous haul.”

“That’s why the headline ‘billions stolen’ is misleading,” she argued. “Volume isn’t the story. A handful of live session tokens is.”

A stolen session cookie is the digital equivalent of stealing someone’s already-swiped keycard rather than picking a lock, contended Francis West, CEO of Security Everywhere, a cybersecurity company in Hemel Hempstead, England.

“This is exactly why we’re seeing infostealer malware increasingly target browsers specifically,” he told TechNewsWorld. “A single infected device can yield dozens of live sessions — email, banking, cloud storage, corporate SaaS tools — all at once, and stolen cookie batches are now actively traded on criminal marketplaces.”

Over the last two years, stealing session cookies has moved from a secondary benefit of credential theft to the primary objective of stealer malware, added Adrian Cheek, a senior cybercrime researcher at Flare, a threat intelligence company in Montreal.

“It also breaks the standard incident response sequence,” he told TechNewsWorld. “Rotating a password has no effect on a stolen cookie. The session stays live until it is explicitly revoked or expires on its own.”

Fast and Quiet Malware

Cheek explained that cookies are overwhelmingly stolen by infostealer malware running on a victim’s device. “The malware is fast and quiet,” he said. “It requires no administrative privileges and does not need to persist.”

“A single execution reads every browser profile on the machine and exits,” he continued. “The resulting stealer log is a ZIP archive containing cookies, saved credentials, autofill data, browsing history, installed software, clipboard contents, and a screenshot of the desktop taken at the moment of compromise.”

“Fake recruitment exercises and trojanized software projects are another increasingly common lure, particularly for developers and other technical users,” added Bogdan Botezatu, senior director for threat research and reporting at Bitdefender, a global cybersecurity technology company.

“A very popular delivery mechanism called ‘ClickFix’ helps cybercriminals install infostealers by impersonating Captcha boxes that manipulate a user’s clipboard to run dangerous commands in the system terminal,” he told TechNewsWorld.

He also noted that cookies can be captured through malicious browser extensions, compromised websites, or adversary-in-the-middle phishing pages that relay a real login and intercept the resulting session. “Modern HTTPS makes simple interception over the local network much less useful than infecting the endpoint or manipulating the authentication process itself,” he explained.

More Than Antivirus Needed

NordVPN also reported finding stolen cookies from devices that had security software installed. Among stealer logs that identified installed security software, 96.3% named Windows Defender, while the rest referenced commercial antivirus suites, it noted.

“Antivirus can detect and remove most infostealer strains,” Paul Bischoff, a consumer privacy advocate at Comparitech, a reviews, advice and information website for consumer security products, told TechNewsWorld.

“However,” he added, “they do not make you immune.”

Antivirus remains important, but it is not an airtight control, cautioned Deric Palmer, chief digital risk officer at the ASC3ND Technologies Group, a cybersecurity and IT modernization firm in Washington, D.C.

“Infostealers frequently change their code, delivery methods and behavior to evade signature-based detection, and users may override security warnings or install malicious software themselves,” he told TechNewsWorld.

He recommended antivirus should be treated as one layer alongside prompt patching, endpoint monitoring, browser controls, application allowlisting and safer user behavior.

A more durable fix to the problem is making the stolen cookie useless, argued Chris Boehm, chief technology officer for Zero Networks, a provider of automated microsegmentation, zero trust networking, identity-based access control, and secure remote access in Tel Aviv, Israel.

“That’s what Google shipped in Chrome 146, with Device Bound Session Credentials, tying the session to a key inside the TPM or Secure Enclave,” he told TechNewsWorld. “Sites have to adopt it on their end, so coverage will take time.”

Strong Passwords, MFA Not Enough

ASC3ND’s Palmer contended that cookie theft exposes a blind spot in how people think about account security. “Strong passwords and multi-factor authentication protect the login process, but they may not stop an attacker who steals the authenticated session after the login has already occurred,” he observed.

“The industry needs to place greater emphasis on short-lived sessions, device-bound authentication, continuous risk evaluation and rapid session revocation,” he said.

“Most people assume cookie consent banners are a safety feature, but those come from European law under the ePrivacy Directive and GDPR, and they govern what a website may place on your device rather than what malware takes off your laptop,” added Zero Networks’ Boehm.

“The industry spent 15 years telling people a strong password plus MFA meant they were safe, and this data shows that advice was incomplete,” he noted. “Attackers stopped attacking the front door and started stealing the proof that you already walked through it.”

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram WhatsApp Email

Related News

Multi-Model AI Could Improve Enterprise Trust

Multi-Model AI Could Improve Enterprise Trust

Elon Musk’s Moneyless Future Faces a Reality Check

Elon Musk’s Moneyless Future Faces a Reality Check

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

AI Rules to Protect Kids Risk Repeating Social Media Mistakes

Zuckerberg Makes His Case for Superintelligence for All

Zuckerberg Makes His Case for Superintelligence for All

An Upgrade I Never Expected

An Upgrade I Never Expected

Add A Comment

Leave A Reply Cancel Reply

Latest News

Review: Record Shares of Voters Turned Out for 2020 election

Review: Record Shares of Voters Turned Out for 2020 election

January 11, 2021
EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

January 11, 2021
World’s Most Advanced Oil Rig Commissioned at ONGC Well

World’s Most Advanced Oil Rig Commissioned at ONGC Well

January 11, 2021
Melbourne: All Refugees Held in Hotel Detention to be Released

Melbourne: All Refugees Held in Hotel Detention to be Released

January 11, 2021

Subscribe to News

Get the latest USA News and updates directly to your inbox.

Editor's Picks
Review: Record Shares of Voters Turned Out for 2020 election

Review: Record Shares of Voters Turned Out for 2020 election

January 11, 2021
EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

EU: ‘Addiction’ to Social Media Causing Conspiracy Theories

January 11, 2021
World’s Most Advanced Oil Rig Commissioned at ONGC Well

World’s Most Advanced Oil Rig Commissioned at ONGC Well

January 11, 2021
Facebook X (Twitter) Pinterest WhatsApp TikTok Instagram
2026 © US Times Mirror. All Rights Reserved.
  • Privacy Policy
  • Terms
  • Advertise
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?