top of page
Search

Billions of stolen cookies threaten online accounts

  • Aug 5
  • 1 min read

Cybercriminals are stealing browser cookies on a massive scale. A NordVPN study found more than 52.4 billion stolen cookies between June 2025 and June 2026.

Most are used for advertising and tracking and have little value to attackers. However, authentication cookies can allow criminals to access already logged-in accounts without a password and, in some cases, without triggering MFA again.

The main source of cookie theft is infostealer malware, which can also collect passwords, autofill data, and browsing history. Cookies can also be stolen through malicious browser extensions and phishing websites.

Experts warn that antivirus software, strong passwords, and MFA alone are not enough. Better protection requires regular software updates, device and application controls, shorter sessions, and technologies that bind authentication to a specific device.

The real threat is not billions of cookies, but a small number of active session cookies that can give attackers direct access to online accounts.


 
 
bottom of page