52 billion reasons to worry: Your browser data is the new goldmine for hackers

New research from cybersecurity firm NordVpn has revealed the staggering scale of cookie theft, identifying more than 52.4 billion stolen cookies in historical data from infostealers (malware that steals sensitive information) over a single year. …

52 billion reasons to worry: Your browser data is the new goldmine for hackers

New research from cybersecurity firm NordVpn has revealed the staggering scale of cookie theft, identifying more than 52.4 billion stolen cookies in historical data from infostealers (malware that steals sensitive information) over a single year. A cookie is a small text file that websites save on your computer or smartphone when you visit them. It mainly serves to remember your information and preferences to make browsing more convenient.

Browser cookies have now become the go-to currency for cybercriminals, appearing 4.6 times more often than all other types of stolen data combined, including passwords, files and credit cards.

Stolen cookies allow attackers to bypass login screens entirely. By reusing a session cookie that is still active, a hacker can impersonate an already authenticated user without ever having to know his or her password: a technique known as session hijacking.

“We are seeing a radical change in the way hackers act. It is no longer simply a matter of forcing a password, but of stealing the digital key already inserted and turned in the lock”, explains Marijus Briedis, Chief Technology Officer of NordVpn.

In the crosshairs are the accounts you use every day

The most frequently stolen records do not concern banking credentials, but rather the most popular everyday platforms. At the top of the ranking is Google, with 11.78 million stolen records, followed by Facebook (8.10 million) and Microsoft (7.85 million). Social and entertainment platforms have also been hit hard. Services such as Twitch, Netflix, YouTube, Reddit and Bing frequently appeared among the cases detected, confirming that even accounts used for browsing, watching streaming content and for entertainment represent valuable loot for attackers.

Cookie theft knows no boundaries

Cookie theft has been detected in over 250 countries and territories. India leads the way, with 4.68 billion stolen cookies, followed by Brazil (2.83 billion), the United States (2.43 billion), Indonesia (2.10 billion) and the Philippines (1.93 billion). If we compare the data to the size of the population, Uruguay, Peru and Chile show the highest concentration of stolen cookies per inhabitant.

Italy ranks 20th globally, with 574 million cookies identified in the datasets examined.

Expert advice

Since more than 96% of the infection logs analyzed came from devices with active security software, the study highlights how traditional protection must now go hand in hand with rapid response capacity. Marijus Briedis recommends logging out of open sessions and clearing your browser cache to make stolen digital keys unusable before criminals can exploit them.

“Logging out of the affected accounts and regenerating that session can significantly reduce the damage,” says Briedis.

Electronic card scams: how to reduce risks and costs on holiday