Cookies: Research reveals 52.4B stolen cookies in one year

Cookies are meant to make browsing easier, but NordVPN research shows how valuable they have become to infostealers. Over one observed year, researchers identified more than 52.4 billion stolen cookies, exposing risks that range from tracking and profiling to session hijacking. NordVPN’s hijacked session alert helps you react if your session cookies appear in known stolen-cookie datasets.

August 3, 2026

11 min read

Browser cookies

Infostealers are collecting cookies at a massive scale

NordVPN research shows that browser cookies have become one of the main targets for infostealer malware. Over an observed one-year period, from June 9, 2025, to June 8, 2026, researchers identified 52,389,324,619 stolen cookies in historical infostealer data.

Among the stolen data types included in the dataset, cookies appeared most often by raw record count. The same dataset included 6.75 billion autofill entries, 2.17 billion files, 1.55 billion credential records, 607.9 million passwords, 341.4 million unique victim emails, and 1.09 million payment cards. In total, infostealers collected more than 4.6 times more cookie records than all other listed stolen data types combined.


Infographic: One year of infections

This scale shows why browser cookies have become such a valuable target. Some cookies help websites remember your preferences or keep you logged in, while others are used for advertising, tracking, or analytics. When infostealers collect cookies from an infected device, they may reveal what you do online, help criminals build a profile of your interests, or in the case of session cookies, help attackers try to take over an active login session.

People usually pick up infostealer malware from unsafe downloads, fake software updates, malicious ads, phishing links, cracked apps, game cheats, or infected email attachments. Services mentioned in this research, such as Netflix, YouTube, Twitch, or Google, are not malware sources. They are examples of accounts that may be exposed after an infected device has its browser data collected.

Advertising and tracking cookies were stolen the most

Advertising and tracking cookies made up the largest share of stolen cookies in the research. These cookies may not give attackers direct access to an account, but they can still reveal information about your online behavior, interests, and browsing patterns.

Tracking can also involve several types of cookies you may not recognize:

  • Third-party cookies. These are placed by websites or services other than the site you’re visiting and are often used for advertising, retargeting, and cross-site tracking.
  • Super cookies. These are more persistent tracking files that can store identifiers outside normal browser cookie storage, making them harder to remove than standard browser cookies.
  • Zombie cookies. These are tracking cookies that can recreate themselves after a user deletes them, making them especially privacy-invasive.

That said, this finding shows that stolen cookies do not need to unlock an account to be valuable. At this scale, even cookies used for advertising, analytics, and tracking can show cybercriminals what sites someone visits, what they may be interested in, and how they move around the web.

Three infostealer families drove most of the theft

Most stolen-cookie records were tied to a small number of infostealer families. Three infostealer malware families — Lumma-C2, RedLine, and Vidar — accounted for almost four in five stolen cookies identified in the research.

Lumma-C2 made up the largest share, accounting for 34.5% of stolen cookies, followed by RedLine at 27.2% and Vidar at 18.1%. Together, they accounted for 79.8% of the stolen cookies.


Infographic: Infostealer families

This concentration matters because a few widely used infostealers can expose large amounts of browser data from infected devices. These tools are designed to collect data from infected devices, including browser-stored cookies, saved credentials, autofill entries, files, and other information that can be useful to cybercriminals.

Law enforcement takedowns have disrupted some major infostealer operations, but they have not eliminated the broader threat. When one malware family is weakened, others can keep collecting browser data. That means cookie theft is not tied to one group or campaign — new or still-active infostealers can keep targeting browser data even after one operation is disrupted.

Why stolen cookies are a security risk

Internet cookies are not dangerous by default. Websites use cookies on the internet to keep pages working, remember user preferences, and recognize them after they log in. The risk starts when cookies are stolen from a browser, and attackers try to reuse them to make a website think they are still the logged-in user.

Session cookies are the most sensitive because they help websites recognize that a user has already logged in. If attackers steal an active session cookie, they may try to impersonate the user and access the account without entering the password. This type of attack is known as session hijacking.

Other stolen cookies may not unlock an account directly, but they can still help attackers learn more about someone and make scams more convincing. When cookies sit alongside stolen credentials, autofill entries, files, or device details from the same infostealer log, attackers can get a clearer picture of the person behind the device and use that context to personalize scams.

That is why the scale of cookie theft matters. A stolen password is an obvious security risk, but stolen cookies can also show which services people use, how they browse, and whether an attacker may be able to take over an active session.

Cookie theft is not limited to one region or platform — if a device gets infected, the cookies stored in its browser can be exposed. NordVPN researchers found stolen cookies across more than 250 countries and territories, showing how widely infostealer malware can spread once it reaches infected devices.

By total stolen-cookie volume, India led the dataset with 4.68 billion stolen cookies, followed by Brazil with 2.83 billion, the United States with 2.43 billion, Indonesia with 2.10 billion, and the Philippines with 1.93 billion. Vietnam, Türkiye, Pakistan, Mexico, France, Egypt, Thailand, Colombia, Argentina, and Peru also appeared among the highest-volume countries.


Infographic: Where the cookies were stolen

The ranking looks different when stolen-cookie volume is compared with population size. Uruguay had the highest count relative to population, with around 29 stolen cookies per person, followed by Peru with around 23 and Chile with around 22.

This does not mean that every person in those countries was affected. A single infected device can expose many cookies, so the figure shows the scale of stolen-cookie volume compared with the population, not the number of individual victims.

Together, these findings show that cookie theft is both broad and uneven. The practical risk is simple — if infostealer malware reaches a device, the cookies stored in its browser can be exposed, regardless of where that device is located.

Everyday accounts appeared in stolen records

The research also showed how often infostealer data is tied to everyday online accounts. Among stolen login records, accounts.google.com appeared most often, with 11.78 million records, followed by facebook.com with 8.10 million and login.live.com with 7.85 million.

Other widely used services also appeared in the top 10, including Instagram, Discord, Netflix, Roblox, and mobile Facebook and Instagram domains. The ranking shows that infostealers collect not only data linked to banking, business, or high-value corporate accounts, but also data linked to the services you may use every day.

This matters because personal accounts are often connected to other parts of your digital life. A stolen login can expose messages, saved payment details, recovery options, linked profiles, or reused credentials. When stolen cookies and credential records come from the same infected device, attackers may have more than one way to misuse the account.

The research also found stolen cookies from devices that had security software installed. Among stealer logs that listed installed security software, 96.3% named Windows Defender, while the rest referenced commercial antivirus suites.

This does not mean antivirus tools are useless. It shows that no single layer of protection can stop every infostealer infection. You also need to know when your data may have been exposed and act quickly — by logging out, changing passwords, and scanning your device for malware.

Streaming and entertainment accounts stood out in alert data

NordVPN’s hijacked session alert data gives a limited snapshot of which services may appear when exposed session cookies are detected. In a June 2026 internal analysis of hijacked session alert data, streaming and entertainment services appeared often among affected devices: Twitch was linked to 47 affected devices, Netflix to 42, and YouTube to 29. Bing appeared on 20 affected devices, while Reddit appeared on six affected devices.

This sample does not represent all stolen cookies, all affected accounts, or the broader NordVPN research dataset. This should not be read as a ranking of the most stolen services. Still, the sample shows that session-cookie theft is not only a risk for banking, email, or work accounts.

Entertainment accounts can also be abused, resold, or used as stepping stones for broader account misuse, especially if they contain saved payment details, shared profiles, or reused credentials.

How NordVPN’s hijacked session alert helps you react

NordVPN’s hijacked session alert warns you if your session cookies appear in known stolen-cookie datasets. This helps you react quickly by logging out of the affected account, changing the password, and creating a fresh session cookie.

Internal data suggests that many affected devices stopped triggering alerts after users were warned, though the analysis used alert activity as a proxy rather than directly tracking when a new cookie was created. Across 144 fingerprinted devices, the median was two alerts per device. In that sample, 58 devices raised only one alert, while 49 raised two to five alerts.

The hijacked session alert is part of NordVPN’s next-gen antivirus and focuses on exposed session cookies found in known stolen-cookie datasets. If you receive an alert, you should still scan your device for malware, because an active infostealer could keep collecting new cookies.

Online security starts with a click.

Stay safe with the world’s leading VPN

What to do if your cookies are stolen

If you find out that your cookies were stolen, log out of the affected account on all devices. Logging out can close active sessions and make the stolen session cookie less likely to keep working for attackers.

Next, change your password, enable two-factor authentication, and review recent account activity, connected devices, recovery options, and saved payment methods. If anything looks unfamiliar, remove it and update your security settings.

Finally, clear cookies from your browser, review your settings to enable or disable cookies based on your privacy preferences, and scan your device for malware.

Methodology

NordVPN researchers analyzed historical infostealer cookie data through the NordStellar platform to understand the volume of stolen cookies, the malware families associated with them, their country-level distribution, and cookie usage patterns.

The analyzed period covered approximately one year, from June 9, 2025, to June 8, 2026. All figures from this research are cumulative cookie-record counts from that time window. The headline figure of 52,389,324,619 refers to cookie records, not unique users, devices, or infections.

The research also compared cookie records with other stolen data types included in the broader dataset, including autofill entries, files, credential records, passwords, unique victim emails, and payment cards. Malware family and country shares were calculated from the full one-year cookie total.

Cookie data was gathered from stealer logs, and researchers used metadata that came with those logs. Country-level findings were based on country information included alongside cookies in the same infected-computer logs, not from the cookies themselves. Some cookie records had no country information, so only records with country data were included in per-country counts.

Malware families were assigned based on tags already included in the logs and matched with the cookies in those logs. Cookie categories were grouped by words in the cookie name, such as names containing “session.” Antivirus findings were based on 9,838,326 stealer logs that recorded a security product. Of those, 96.3% listed Windows Defender, while the rest named commercial antivirus suites.

The information in this article also includes a separate June 2026 internal analysis of NordVPN’s hijacked session alert data. That analysis covered 2,057 aggregated alert rows received between May 17 and June 10, 2026, with event timestamps ranging from February 4 to June 10, 2026. The analysis included 144 distinct fingerprinted devices, and rows without a device fingerprint were excluded from per-device analysis.

The analysis could not directly track when a new cookie was created, because the export did not include cookie identifiers or cookie-creation timestamps. Instead, the end of alert activity was used as a proxy for action.

The findings reflect observed infostealer data analyzed through the NordStellar platform and limited internal hijacked session alert insights. They should not be interpreted as a complete count of every cookie stolen globally during that period, the number of unique affected users or devices, or a ranking of all stolen cookies worldwide.

Also available in: English,Svenska,简体中文.

Blog author Domantas Lapinskas

Domantas Lapinskas

Domantas writes about cybersecurity, privacy, and the strange little ways the internet gets people into trouble. He offers clear, practical advice for staying safe online that is easier to remember than another complicated password.