Politics

263 million South African browser cookies stolen by cybercriminals

South Africans are being warned about a growing cyber threat that could allow criminals to access online accounts without even knowing the victim’s…

263 million South African browser cookies stolen by cybercriminals — article image

The Full Story

South Africans are being warned about a growing cyber threat that could allow criminals to access online accounts without even knowing the victim’s password.

More than 263 million browser cookies linked to South Africa have been found in infostealer datasets circulating online, according to research by cybersecurity company NordVPN.

South Africa ranked 30th globally for the number of stolen browser cookies identified in the research.

Browser cookies are small pieces of data stored on devices that allow websites to remember users, including keeping them logged in or saving shopping carts.

Cybercriminals are increasingly targeting so-called “remember-me” cookies, which can contain information linked to an authenticated session. If criminals obtain a valid session cookie, they may be able to access an account as the legitimate user, potentially bypassing password and other authentication measures.

How the ‘browser cookie’ scam works

The attack, known as session hijacking, typically starts when criminals trick users into downloading infostealer malware through phishing links, suspicious websites or social engineering.

The malware can search a device for valuable information, including browser cookies, which can then be used to hijack online sessions.

The FBI has warned that stolen cookies can allow criminals to access accounts such as Netflix, YouTube and Reddit, as well as potentially more sensitive services such as email.

More than 52 billion browser cookies stolen globally

NordVPN found more than 52 billion cookies in infostealer datasets worldwide.

The most frequently stolen records were not primarily banking-related. Google accounted for approximately 11.78 million stolen records, followed by Facebook with 8.10 million and Microsoft with 7.85 million.

Entertainment and social platforms were also heavily affected, with Twitch, Netflix, YouTube, Reddit and Bing among the frequently detected services.

By country, India recorded the most stolen cookies at 4.68 billion, followed by Brazil at 2.83 billion, the US at 2.43 billion, Indonesia at 2.1 billion and the Philippines at 1.93 billion.

South Africa’s 263 million cookies placed it 30th globally.

One particularly concerning finding was that 96% of the analysed logs came from devices that already had active security software installed.

NordVPN Chief Technology Officer Marijus Briedis said criminals are increasingly looking beyond passwords.

“It is no longer just about cracking a password. It’s about stealing the digital key that is already turned in the lock,” he said.

The FBI recommends avoiding suspicious links and regularly checking recent device login activity through the security settings of online accounts.

Users should also be cautious about downloading files or software from unfamiliar websites.

NordVPN recommends regularly clearing browser cookies, while Briedis said that if a session cookie is suspected of being stolen, logging out of affected accounts and refreshing…

Sources