Cyber Thieves Target Browser Cookies: A Growing Concern for Online Security
A new report has revealed that online thieves are increasingly stealing browser cookies, which puts users at risk of serious issues like identity theft and account hacks. This alarming finding comes from NordVPN, a popular VPN service.
A Massive Data Analysis
Between June 2025 and June 2026, researchers at NordVPN examined over 52.4 billion browser cookies found in logs sold on dark web sites and Telegram channels. While only a few of these stolen cookies were still active, the few live authentication cookies can provide attackers immediate access to user accounts.
Domantas Lapinskas from NordVPN stated that the significant number of stolen cookies highlights their value to cybercriminals. Although most of the stolen cookies were for tracking and advertising, authentication cookies—the ones that keep users logged in—represent the highest security threat.
Rich Pleeth, co-founder of a logistics software company in London, pointed out that if a thief takes the right cookie, they may gain access to personal accounts, including email and banking, without needing a password—or even triggering two-factor authentication.
What Makes Cookies So Dangerous?
When users log in to a site, a session cookie is created to avoid repeated logins. Sila Özeren Hacioglu from a cybersecurity firm explained that if someone steals this session cookie, they can pose as the genuine user without needing any further authentication.
Özeren emphasized that cookies have become more valuable than traditional passwords. In fact, NordVPN’s research indicated that cookies appeared in data logs four times more often than passwords, showing how hackers now prioritize session data over credentials.
Google and Microsoft cookies are especially prized because they provide access to multiple services with just one set of credentials. Most stolen cookies, however, are not valuable to criminals; it’s only the small number of authentication cookies that truly matter.
How Thieves are Stealing Cookies
Cybercriminals increasingly use malware that operates on victims’ devices to steal cookies. This malware is fast, discreet, and can extract information without needing special permissions. Adrian Cheek, a cybercrime researcher, noted that this method allows thieves to harvest multiple accounts at once, including email and banking.
Additional methods of cookie theft include fake job offers targeting developers, malicious browser extensions, and compromised websites that collect session data during legitimate logins.
Antivirus Software Alone Isn’t Enough
Although many infected computers had security software installed, a staggering 96.3% identified Windows Defender as their antivirus. While antivirus programs can detect some types of malware, they don’t provide full protection.
Experts, including Deric Palmer from a cybersecurity firm, emphasized that users should not solely rely on antivirus. Effective online safety should involve multiple layers of security, such as regular updates, strict browser settings, and responsible user behavior.
Rethinking Account Security
Cookie theft shows that relying solely on strong passwords and multi-factor authentication is no longer sufficient. Palmer suggests that the industry needs to focus on creating shorter session durations and continuously evaluating risks.
There is also a misconception that cookie consent banners are enough for safety. These banners are primarily a legal requirement, not a complete security net against cookie theft.
Overall, the landscape of online security is changing, and both users and companies need to adapt their strategies to combat these threats effectively.
