Cookie theft: From stolen credit card details to extortion

Issue 4 2021 News & Events

New research by NordLocker demonstrates that the cookies your browser stores when you visit various websites can get easily snatched by computer viruses. According to the latest discovery, over 2 billion cookies from popular online services like AliExpress, Amazon, Facebook, Dropbox and YouTube were stolen from unaware users’ machines by custom Trojan malware.

“Cookies give you a tailored online experience with more relevant content. For example, online shopping cookies let the website keep track of all the items you place in your cart while you continue to browse,” explains Oliver Noble, a cybersecurity expert at NordLocker. “However, cookies can also help cybercriminals construct a detailed picture of you, including your location, interests and habits. If hackers hijack your cookies, they might impersonate you and even get into your online accounts.”

How can cybercriminals use your cookies?

Cookies, small text files containing data about your interaction with a website, often get hacked when a user logs in to their online accounts over unprotected public Wi-Fi networks or unintentionally downloads malware onto their device. Different cookies store different data, which, when leaked, can cause different problems to a victim.

“Luckily, hackers won’t be able to empty your bank account with the cookies stolen from your online banking session due to strong security measures. However, bad actors can learn important details about the bank you use and timestamps of your transactions. This data can be used in phishing scams, when hackers contact unaware users pretending to be the bank’s representatives to trick their victims into giving away their personally identifiable information,” Noble explains.

Stolen cookies can be used in extortion scams, too. For example, NordLocker’s research found that malware stole millions of YouTube, Netflix and Pornhub cookies. “In video streaming services, cookies provide you with an enjoyable experience as they remember what videos you’ve already watched and which ones you might be interested in watching next. However, they also reveal your location, timestamps, site preferences and your search history – all of which could provide grounds for extortion if a hacker decided to share information with your employer that you’ve been watching inappropriate content during work hours,” warns Noble.

Cybercriminals pretending to be you on social media and sending spam to your contacts is unpleasant, but what is more worrying is when they get into your online accounts where you store your personal information, such as home address and credit card details. To avoid falling victim to cookie theft or session hijacking, you need to follow some cyber hygiene steps.

How to avoid risks associated with website cookies?

* Don’t accept cookies. If you don't want cookies to hold information about you, decline them. Some websites won’t let you access their content, but, for the most part, you'll still be able to access the majority of the Internet without accepting cookies.

* Delete your cookies and block any future ones in your browser’s settings if you don’t like the idea of being tracked and traced.

* Only accept cookies on sites you trust to be safe and secure. A little padlock symbol and the URL starting with “https://” (“s” stands for “secure) means that the connection between the website server and your web browser is encrypted.

* Don’t store your valuable information in your online shopping accounts. Better spend another minute or two typing your credit card details and home address every time you shop online than risk getting this information compromised in cookie theft.

* Refrain from unsecure websites and unprotected public Wi-Fi networks. Use the latter for Internet browsing only, but, if you must log in to your personal accounts, protect your connection with a VPN (virtual private network).




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

SMARTpod talks about HomeSec Expo 2026
SMART Security Solutions Technews Publishing News & Events Residential Estate (Industry) Videos
SMARTpod, the podcast from SMART Security Solutions, finds out more about the upcoming HomeSec Expo happening at Gallagher Estate on 4 & 5 March 2026.

Read more...
“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
Coordinated efforts lead to successful crime response
News & Events Surveillance Integrated Solutions
A synchronised operation involving Vumacam’s control room operators, the Johannesburg Metropolitan Police Department (JMPD), and 24/7 Drone Force, resulted in the successful identification and apprehension of a suspect linked to a reported theft case.

Read more...
2025 Global OSPAs winners
News & Events
Bringing together the very best of the global security industry, the second Global Outstanding Security Performance Awards (OSPAs) was streamed live to a worldwide audience on 05 February 2026.

Read more...
New commercial and technical appointments at Veeam
News & Events Infrastructure
Veeam Software has announced two senior appointments in its South African business as it continues to invest in local market growth and partner and customer engagement.

Read more...
Exhibitions across the security spectrum
News & Events Perimeter Security, Alarms & Intruder Detection Smart Home Automation
HomeSec Expo has become the security industry’s premier trade event. Visitors will experience a live showcase of how different aspects of the security spectrum come together under one roof.

Read more...
A clear vision for a safer, smarter future
News & Events Perimeter Security, Alarms & Intruder Detection Smart Home Automation
With its authoritative lineup of sponsors and exhibitors, HomeSec Expo 2026 embodies an authoritative, yet pragmatic vision, for the security industry. It is a vision that recognises both the urgency of current threats and the excitement of technological innovation.

Read more...
Navigating a modern, layered security landscape
News & Events Perimeter Security, Alarms & Intruder Detection Smart Home Automation
The convergence of perimeter control and access automation is driving demand for solutions that work together. This is the focus of HomeSec Expo 2026, which takes place on 4th and 5th March 2026 at the Gallagher Convention Centre in Johannesburg.

Read more...
Phishing and social engineering are the most significant risks
News & Events Information Security
ESET Research found that phishing accounted for 45,7% of all detected cyberthreats in South Africa, with higher-quality deepfakes, signs of AI-generated phishing websites, and short-lived advertising campaigns designed to evade detection.

Read more...
Cyber remains top business risk, but AI fastest riser at #2
News & Events Security Services & Risk Management
The Allianz Risk Barometer 2026 ranks cybersecurity, especially ransomware attacks, as the #1 risk, while AI is the biggest riser and jumps from #10 to #2, highlighting the emerging risks for companies in almost all industry sectors.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.