In a recent study conducted by NordVPN’s investigative team, the alarming scale of cookie breaches was revealed, showcasing a staggering total of over 52.4 billion cookie records stolen globally between June 2025 and June 2026. This constitutes an eye-opening rate of approximately 1,600 records compromised per second, marking a significant shift from traditional focus areas in cybercrime, which have primarily centered around passwords alone.
Out of the total numbers, Japan faced its share of the cyber threat with approximately 189 million cookie records stolen, placing the country at 43rd in the world for such breaches. Notably, the number of stolen cookies vastly outpaces other forms of stolen data, with cookies being four times higher than the total of sensitive information, such as passwords, authentication credentials, and card payment details, which collectively amounted to around 11.4 billion records. This stark reality indicates a growing trend among cybercriminals not only to breach passwords but also to access authenticated sessions.
Cookies play a crucial role in user authentication on various platforms, helping maintain user login states and associate preferences with viewing experiences on websites. Although not all cookies grant access to accounts, compromised authentication cookies can enable attackers to impersonate users without needing their passwords or passing through multi-factor authentication barriers.
NordVPN’s internal data further emphasizes concerning trends, revealing that a staggering 96.3% of devices infected with information theft malware had security solutions such as Windows Defender installed. This statistic reinforces the idea that relying solely on security software may not prevent cyber infections; a multi-layered security approach is recommended.
Globally, the malware responsible for stealing cookies was discovered across more than 250 countries and regions, cementing it as a worldwide concern. Countries like India, Brazil, and Indonesia reported the highest instances of cookie record theft, leading in overall numbers. Besides Japan’s 189 million records, the statistics indicate that cookie theft has become a pervasive issue transcending geographical boundaries.
When examining the breach records by domain, prominent service providers such as Google and YouTube emerged significantly. Approximately 540 million cookie records from Google and around 320 million from YouTube were identified, further illustrating the volume of data compromised through familiar, everyday services. The top 100 domains accounted for nearly 51.2% of the total number, indicating that one in five records remained active and potentially vulnerable at the time of analysis.
Traditionally, advice surrounding account safety has revolved around creating strong passwords and enabling two-factor authentication. However, the dynamics shift drastically if an attacker gets access to valid authentication cookies, as they can capitalize on the authenticated user’s session without any further user interaction. This type of cyber attack is termed ‘session hijacking,’ which underlines the critical need for users to engage in active monitoring of their account access.
To safeguard against such threats, users are urged to adopt several proactive measures:
1. Log out from unused services to minimize exposure risks.
2. Change passwords and log out from all devices immediately if any suspicious activity is detected.
3. Keep your browser, operating systems, and extensions updated to defend against malware.
4. Avoid clicking on suspicious links and engaging with unofficial downloads or apps.
5. Utilize data breach detection tools to monitor sensitive information and threats from malicious websites.
The NordVPN research underscores a significant wake-up call for individuals and organizations alike to review their cybersecurity measures diligently. In other words, cybercriminals are now targeting more than just passwords; they can exploit vulnerabilities found in seemingly innocuous data like cookies. Strategies to combat these threats should be advanced and multi-faceted, ensuring both higher awareness and better protection against the evolving threats of cybercrime.
In a statement, NordVPN’s CTO, Mariusz Bledowski emphasized, ‘Cybercriminals are now targeting more than just passwords. Cookies that retain session authentication may serve as digital keys for unauthorized access. When cookie breaches are suspected, it’s vital to change your password and log out from all devices to invalidate existing sessions.’
Keeping track of numerous measures can be overwhelming, but in our current digital landscape, it’s essential that users remain vigilant with their online practices.