NordVPN says it found more than 263 million browser cookies tied to South African users sitting in infostealer datasets, ranking the country 30th globally. The worry is session hijacking, where someone reuses an active login cookie to enter an account without ever needing the password, which also sidesteps multifactor authentication.
The FBI has issued warnings about the same technique. Netflix, YouTube, Reddit, Twitch and Bing came up frequently among detected exposures. Globally, the count was 52.4 billion cookies over a single year.
Interesting insights on stolen browser cookies
NordVPN's own material carries caveats the headline drops. The company states the figures are cumulative cookie records rather than unique users, devices or attacks, and that the study does not measure how many people were actually compromised.
Advertising and tracking cookies made up the largest share of the haul, while authentication cookies, the genuinely dangerous ones, are far less common. In an earlier NordVPN dataset, cookies tagged auth numbered 272.9 million and login 61.2 million, against 18 billion tagged simply as ID.
Only a small percentage remained live: Redline accounted for roughly 42 billion cookies with 6.2% still valid, and Vidar 10.5 billion at 7.2%. The data ran from 9 June 2025 to 8 June 2026, drawn from dark web forums and Telegram marketplaces, and included 607 million passwords and 1.09 million payment cards alongside the cookies.
What others are saying about stolen browser cookies
MyBroadband reports the finding that should worry people most: 96% of the analysed logs came from devices already running active security software. NordVPN recommends signing out of affected accounts to force new sessions, which invalidates any cookie already taken. TechNewsWorld notes cookie records turned up 4.6 times more often than passwords, payment cards and files combined.
The number is inflated, and the fix is still free
Two things hold at once here. The 263 million figure is doing heavy lifting: it counts records rather than people, most of those records are advertising junk, and the majority had already expired.
NordVPN sells security products and is under no obligation to lead with that. But the mechanism is real, and the defence costs nothing. Signing out of a session rather than just closing the tab kills any cookie already lifted. Clearing browser data periodically does the same. Checking recent device login history in your account settings catches what slipped through.
For anyone running a business, the number to sit with is that 96%: endpoint protection is not a substitute for session hygiene, and if staff sign into company tools in a browser on a machine that also collects dubious downloads, your controls are decorative.
Short session timeouts and forced re-authentication belong in policy, not in a reminder email.
You might also like our roundup of SA startup news, our case for small business reform in South Africa, and what separates successful startups in SA.
Get more SA tech and business news and subscribe to The Open Letter.


