More than 231 million stolen browser cookies linked to Australia have been uncovered in a major cybersecurity study, highlighting how hackers are increasingly bypassing passwords to hijack active online sessions.

Research from NordVPN identified 52.4 billion stolen cookies in historical infostealer data collected over a 12-month period, with Australia ranking 34th globally for the number of exposed records.

Cookie records appeared 4.6 times more often than passwords, files and payment card details combined in the analysed data.

Browser cookies allow websites to remember that a user has already logged in. If stolen, attackers can potentially reuse the cookie to impersonate the account holder and bypass login screens, including password and some authentication checks.

“We are seeing a fundamental shift in how hackers operate,” NordVPN chief technology officer Marijus Briedis said.

“It is no longer just about cracking a password. It’s about stealing the digital key that is already turned in the lock.”

Google was the most frequently identified platform in the dataset, with 11.78 million stolen records, followed by Facebook with 8.1 million and Microsoft with 7.85 million.

Entertainment and social platforms including Twitch, Netflix, YouTube, Reddit, Instagram, Discord and Roblox also appeared among exposed records, indicating cybercriminals are targeting more than banking and payment accounts.

India recorded the highest volume of stolen cookies at 4.68 billion, followed by Brazil with 2.83 billion, the US with 2.43 billion, Indonesia with 2.1 billion and the Philippines with 1.93 billion.

NordVPN said more than 96% of the analysed infection logs came from devices with active security software, suggesting conventional antivirus protection may not prevent every instance of session theft.

Users who suspect an account has been compromised are advised to log out of all active sessions, clear browser cookies and caches, change their password and review connected devices.

The research examined data available through NordVPN’s NordStellar platform between June 9, 2025, and June 8, 2026.

The figures represent cumulative cookie records rather than unique users, devices or accounts.