A new study by cybersecurity company NordVPN has revealed that researchers identified more than 52.4 billion stolen cookies over a one-year period. The data, analyzed between June 9, 2025, and June 8, 2026, indicates that browser data has become a primary target for cybercriminals.
The Scale of Stolen Cookies
The analysis showed that these stolen cookies appeared 4.6 times more often than passwords, files, and payment card records combined. This shift highlights how attackers are moving away from traditional credential cracking toward session hijacking. By using active session data, unauthorized users can access accounts without needing passwords.
Saudi Arabia ranked 31st globally in the dataset, with 261,666,917 stolen cookies identified, averaging 7.44 per person. Globally, India led the dataset with 4.68 billion records, followed by Brazil with 2.83 billion, and the United States with 2.43 billion. When adjusted for population, Uruguay, Peru, and Chile showed the highest concentrations of compromised data per person.
Target Platforms and Global Trends
The research indicated that everyday entertainment and social media platforms are the primary targets for these attacks. Google topped the list with 11.78 million stolen records, followed by Facebook with 8.10 million and Microsoft with 7.85 million. Other affected platforms included Instagram, Discord, Netflix, and Roblox.
Additionally, data from hijacked session alerts showed frequent exposures on Twitch, YouTube, Reddit, and Bing. This suggests that accounts used for daily browsing and leisure are highly valued by attackers, rather than just financial or banking logins.
Session Hijacking and Security Software Limits
A notable finding from the study is that nearly 96% of the analyzed infections occurred on devices running active security software. This indicates that traditional antivirus programs may not fully prevent session hijacking, which relies on reusing active digital keys rather than executing malicious files.
“We are seeing a fundamental shift in how hackers operate. It is no longer just about cracking a password. It’s about stealing the digital key that is already turned in the lock,”
Marijus Briedis, Chief Technology Officer at NordVPN
Recommended Mitigation Steps
To mitigate the risks associated with session hijacking, users are advised to adopt active defense measures. These include regularly logging out of active sessions, clearing browser caches, and utilizing specialized session-monitoring apps to invalidate compromised keys.
“Cookie theft is a reminder that cybersecurity is not just about prevention. It is also about how quickly you act when something goes wrong. If a session cookie is stolen, logging out of affected accounts and refreshing that session can significantly limit the damage,”
Marijus Briedis, Chief Technology Officer at NordVPN
The study utilized data from the NordStellar platform, reflecting cumulative cookie-record counts rather than unique users or devices. The findings emphasize the necessity of rapid response in modern digital security frameworks.





