DIGITAL LIFE

Brazil ranks second in stolen cookies by cybercriminals, study finds
Brazil holds second place in the global ranking of stolen cookies, according to new research by cybersecurity firm NordVPN. Globally, the study identified over 52.4 billion stolen cookies—sourced from historical infostealer data and the NordStellar platform—across 250 countries and territories over a one-year period (June 9, 2025, to June 8, 2026). Brazil accounted for 2.83 billion of these.
India leads the list with 4.68 billion. The United States ranks third with 2.43 billion. Rounding out the top five are Indonesia (2.10 billion) and the Philippines (1.93 billion). When adjusted for population size, Uruguay, Peru, and Chile showed the highest concentrations of stolen cookies per capita.
According to the study, browser cookies have become the primary currency for cybercriminals, appearing 4.6 times more frequently than all other types of stolen data combined—including passwords, files, and payment card details.
The data further reveals that the most frequently stolen records were not linked to banking access but to popular platforms used on a daily basis. Google topped the dataset with 11.78 million stolen records, followed by Facebook (8.10 million) and Microsoft (7.85 million). Services such as Twitch, Netflix, YouTube, Reddit, and Bing also frequently appeared among the detected exposures.
Cookies are small data files that websites store in a user's browser to recognize them and retain information across different visits. They help maintain login sessions, language preferences, shopping cart items, and browsing settings, and can also support analytics and advertising tools. NordVPN explains that, while these files do not necessarily store the password itself, some contain identifiers that prove an authenticated session. If a criminal steals an active session cookie, they can take over the account without re-entering credentials. This attack, known as session hijacking, remains possible until the user terminates or invalidates the access.
“We have observed a fundamental shift in how hackers operate. It is no longer just about discovering a password. Now, they seek to steal the digital key that is already turned in the lock,” said Marijus Briedis, the company’s Chief Technology Officer.
Since more than 96% of the analyzed infection records originated from devices with active security software, the study highlights the need for users to combine traditional protections with rapid responses.
Briedis recommended ending sessions, clearing browser caches, and using session monitoring tools to invalidate stolen digital keys before criminals can exploit them.
“Cookie theft demonstrates that cybersecurity is not just about prevention. It also depends on how quickly you react when something goes wrong. If someone steals a session cookie, logging out of the affected accounts and renewing the session can significantly limit the damage,” the executive added.
Infostealers are harvesting cookies on a massive scale...Research by NordVPN shows that browser cookies have become a primary target for infostealer malware. Over the course of a year—from June 9, 2025, to June 8, 2026—researchers identified 52,389,324,619 stolen cookies within infostealer datasets.
Among the types of stolen data included in this dataset, cookies appeared most frequently in terms of raw numbers. The same dataset includes 6.75 billion login autofill entries, 2.17 billion files, 1.55 billion credential records, and 607.9 million passwords, as well as 341.4 million unique victim email addresses and 1.09 million payment card records. In total, infostealers collected 4.6 times more cookie records than all other listed data types combined.
This scale illustrates why browser cookies have become valuable targets. Some cookies help websites remember your preferences or keep you logged into your account, while others are used for advertising, tracking, or analytics. When infostealers harvest cookies from an infected device, they can reveal your online activities, helping criminals build a profile of your interests. Alternatively, in the case of session cookies, they enable criminals to hijack active login sessions.
People typically contract infostealer malware through unsafe downloads, fake software updates, malicious ads, phishing links, cracked apps, game cheats, or infected email attachments. The services mentioned in this research (such as Netflix, YouTube, Twitch, or Google) are not sources of malware themselves; rather, they are examples of platforms where accounts can be compromised after browser data is stolen from an infected device.
Tracking and advertising cookies account for the largest share of cookies stolen in this study. While these cookies may not grant cybercriminals direct access, they can still reveal information about your online behavior, interests, and browsing patterns.
Tracking can also involve various types of cookies you might not recognize:
Third-party cookies. These are placed by sites or services other than the specific site you are visiting and are used for advertising, retargeting, and cross-site tracking.
Supercookies. These are highly persistent tracking files that can store identifiers outside the browser's standard cookie storage, making them harder to delete than standard browser cookies.
Zombie cookies. These tracking cookies can recreate themselves even after being deleted by the user, making them highly intrusive regarding user privacy.
That said, these findings show that stolen cookies do not need to unlock an account to be valuable. At this scale, even cookies used for advertising, analytics, and tracking can reveal to cybercriminals which sites the victim visits, what their interests are, and how they navigate the web.
mundophone



/i.s3.glbimg.com/v1/AUTH_e536e40f1baf4c1a8bf1ed12d20577fd/internal_photos/bs/2026/a/K/m5XMYkQUabsTBALPlRkA/pzzb9096.jpeg)
