Online information thieves are stealing browser cookies on a massive scale, exposing users to risks ranging from identity theft to account hijacking, according to a report released Monday by a VPN service provider.
From June 2025 through June 2026, NordVPN researchers analyzed more than 52.4 billion browser cookies found in infostealer logs offered for sale on dark web forums and Telegram marketplaces.
Although a small percentage of the stolen cookies remained active, live authentication cookies can give attackers immediate access to online accounts.
"This scale shows why browser cookies have become such a valuable target," Domantas Lapinskas wrote in a NordVPN blog.
He noted that advertising and tracking cookies accounted for the largest share of the stolen cookies in the study, although experts say authentication cookies — while far less common — pose the greatest security risk.













