started · updated
Session cookie hijacking endangers Google accounts worldwide
Security researchers have identified a surge in session‑cookie hijacking, a technique that lets attackers access online accounts without passwords or two‑factor codes. An analysis by NordVPN’s research platform found nearly 94 billion stolen browser cookies on underground markets, a 74 % increase from the previous year, with about 20 % still active. Google and Microsoft accounts are the most frequently targeted, with cookies from Gmail, YouTube, Outlook and Bing among the most common. The stolen cookies are harvested by malware families such as RedLine, Vidar and LummaC2, which infiltrate computers via pirated software, fake updates or malicious attachments.
A separate warning highlights that Google Chrome’s default “sync everything” setting aggregates passwords, credit‑card data and browsing history in a single Google account, making a compromised login a gateway to all stored information. Security experts advise users to customize Chrome sync, disabling the sync of sensitive categories like passwords and payment methods, and to consider password managers or passkeys for stronger protection.