마이크로칩 8월
This page was machine-translated and may differ from the original. View original

NordVPN: "52.4 Billion Browser Cookies Stolen Over One Year…Session Hijacking Surging"

Google 우선 소스Published2026.08.11 09:04


 
South Korea Also Suffers Over 300 Million Stolen Cookies·Ranks 29th Globally, 96% Incidents Occur on Devices with Security Software
 
As browser cookie theft through infosstealer malware infections is surging globally, the 'Session Hijacking' technique that allows account takeover without passwords is being widely utilized in attacks on major online platforms.
 
NordVPN announced on the 11th that based on analysis of infosstealer data collected over the past year, more than 52.4 billion browser cookies have been stolen worldwide.

Among these, session hijacking methods that reuse active session cookies to bypass the login process itself are being exploited to compromise accounts on major platforms such as YouTube and Netflix.

 
By platform, Google had the most stolen records at 11.78 million, followed by Facebook at 8.1 million and Microsoft at 7.85 million.


Platforms used frequently in daily life rather than financial services have become concentrated targets.


NordVPN's session alert data also confirmed that streaming and social accounts such as Netflix, Twitch, YouTube, Roblox, Instagram, and Discord are the primary targets of attackers.

 
By country, India suffered the greatest damage with 468 million cookies, followed by Brazil at 283 million, the United States at 243 million, Indonesia at 210 million, and the Philippines at 193 million.


South Korea had 300,761,511 cookies stolen, recording 29th place globally, and analysis shows that approximately 5.83 cookies per capita were compromised.

 
Notably, over 96% of infection logs analyzed were found to originate from devices with security software running normally, pointing out that existing preventive measures alone have limitations.


NordVPN recommended immediately logging out from suspicious sessions, deleting browser cache, and utilizing session monitoring tools to minimize damage.


Marius Briedis, Chief Technology Officer (CTO) of NordVPN, stated: "Hackers' attack methods have shifted from stealing passwords to intercepting already-authenticated session cookies. If cookie theft is detected, logging out from the affected account and refreshing the session will invalidate the stolen cookies and significantly reduce damage."

To request a correction, reply or follow-up report on this article, see how to file a request. Previously published statements are collected in corrections & replies.
명세환 기자
명세환 Reporter