52 Billion Reasons for Concern: Browser Data Is a Real Gold Mine for Criminals

New research by the cybersecurity company NordVPN has revealed the vast scale of cookie theft. Historical infostealer data identified more than 52.4 billion stolen cookies within a single year. Browser cookies have become the primary currency for cybercriminals and are 4.6 times more common than all other types of stolen data combined—including passwords, files, and payment cards.

depositphotos/joruba75

Stolen Cookies allow attackers to completely bypass login screens. By reusing an active session—Cookies An attacker can impersonate a logged-in user without knowing the user's password—a technique known as session hijacking.

 "»We're seeing a fundamental shift in how hackers operate. It's no longer just about cracking a password. Instead, cybercriminals are aiming to steal the digital key that's already in the lock," explains Marijus Briedis, Chief Technology Officer at NordVPN.

Everyday accounts are the goal

The most frequently stolen login credentials were not for bank accounts, but for common everyday platforms. Google tops the list with 11.78 million stolen records, followed by Facebook (8.10 million) and Microsoft (7.85 million).

Further findings from NordVPN’s «Hijacked Session Alert» feature show that, in addition to the usual targets, entertainment and social media platforms are also heavily affected by session compromise—Cookies are affected. Services such as Twitch, Netflix, YouTube, Reddit, and Bing frequently appeared in the datasets. This clearly shows that even accounts used for leisure and entertainment are extremely attractive to cybercriminals.

Cookie theft knows no bounds

Cases of cookie theft have been reported in more than 250 countries and regions. India tops the list with 4.68 billion stolen Cookies, followed by Brazil (2.83 billion), the United States (2.43 billion), Indonesia (2.10 billion), and the Philippines (1.93 billion). Relative to their populations, Uruguay, Peru, and Chile had the highest density of stolen Cookies per person.

The DACH Comparison:

  • Germany ranks 18th worldwide, with 670,203,114 Cookies were found in the analyzed datasets.
  • Austria ranks 69th, with 66,512,877 stolen Cookies.
  • 88th place goes to Switzerland, with 48,043,790 stolen Cookies.

Since more than 96 % of the infection cases occurred on devices with active security software, the study highlights that conventional protective measures must be supplemented by proactive actions. Marijus Briedis therefore recommends logging out of accounts when not in use, regularly clearing the browser cache, and using session monitoring tools. This helps invalidate the «digital keys» before attackers can exploit them for their own purposes.

«The theft of Cookies makes it clear that cybersecurity isn't just about prevention. »It also depends on how quickly you respond when something goes wrong. If a session cookie is stolen, you can significantly limit the damage by logging out of the affected accounts and refreshing the session,” adds Briedis.

Source: nordvpn.com

(Visited 68 times, 1 visits today)

More articles on the topic

SECURITY NEWS

Stay informed about current security topics - practical and reliable. Receive exclusive content directly to your inbox. Don't miss any updates.

Register now!
register
You can unsubscribe at any time!
close-link