Publié le 24 août 2026 · 4 min read
For this week’s Top Story, we’re figuring out what scammers are doing with your cookies.
Hackers are less interested in your passwords, banking information and computer files these days. Now they’re hungry for your cookies. Turns out, there’s more to chew on there than what’s in your private Insta account.
Cookies are the digital breadcrumbs you leave behind whenever you’re online. They’re the reason Amazon remembers your favourite brand of soap, how Netflix predicts your taste in rom-coms and how your bank knows what kind of device and browser you usually log in from and in what city.
And, you know that creepy feeling you get when you see an ad for something your friend just mentioned? It might be because your phone heard it too, and also that their credit card purchase history was shared with Facebook which knows you follow each other on instagram and are on the same wifi network (among a myriad of other reasons that rely on cookie data).
Scammers have developed a growing appetite for cookies. According to a recent study conducted by NordVPN, hackers stole 52.4 billion cookies in the last year, 410 million from Canadians alone. If you always accept internet cookies, know that those digital breadcrumbs were stolen at 4.6 times the rate of passwords, files and payment records combined.
Why are criminals stealing cookies? How can you keep your info safe? Keep reading—and bring snacks.
Is it safe to enable cookies?
Cookies can improve your browsing experience, for the above reasons. But more valuable to hackers than the “preference” cookies that remember what you like, however, are what’s known as “session cookies,” which keep you logged into online services until you log out or close your browser window. If a hacker successfully hijacks one of these sessions, they don’t need your keys (your login info), because the front door is already open (potentially revealing your account info, including credit card info, home address and more). Session hacking can even circumvent traditional cybersecurity measures like password managers and multi-factor authentication.
“We found out that cookie data is actually on a massive rise in terms of exposure, and understandably so,” says Gerald Kasulis, the vice president of global affairs for NordVPN. “Everyone is focusing on passwords nowadays, and a regular user doesn’t realize the importance of cookie sessions in our browsers, which actually are a lot more powerful than a breached password if a hacker gets access.”
Why hackers want your cookies—it goes beyond data
Rather than going after financial data, hackers are instead targeting the platforms most Canadians use every day, with Google’s suite of products topping the list of stolen data sources, followed by Facebook and Microsoft.
“Your Google login or Facebook login might not necessarily be really lucrative to a hacker, but then they could create a lot more sophisticated attacks and try to get into your systems by pretending to be you,” Kasulis explains. “Those three platforms are going to be the most lucrative in terms of how much personal information there is about you.”
With that information hackers can impersonate you to target friends, family, even your employer, or dig through your data in search of something they can use to blackmail you, like an intimate photo, medical information or sensitive corporate data.
“Many financial institutions have invested in fraud detection technology. That includes the ability to detect that you’re logging in from an unusual browser, that you’re logging in from an unusual location, that this is a new device, and all these signals can trigger the bank to stop a transaction,” says David Shipley, the CEO and co-founder of Fredericton-based Beauceron Security. “When a criminal gathers cookies—and the most valuable of these are the session cookies—they understand how to look like you.”
Shipley likens stealing cookie sessions to getting your hand stamped at a bar. To someone trying to sneak in, that stamp often has more value than a fake ID.
Keeping your cookies safe
Protecting yourself from cybercrime starts with many of the usual best practices, like not repeating passwords, using a password manager, turning on multi-factor authentication, and keeping all devices, apps and browsers current (do those updates). And never ever giving someone your pin or any verification codes.
When it comes to securing your cookies specifically, Kasulis suggests deleting your browser history on a weekly basis, closing tabs you aren’t actively using, and signing out of accounts—like email, social media and even streaming apps—whenever they’re not in use.
“If you go into your browser settings, go into settings and go into cookies and data, you’ll be able to see how much data has been collected since your last browser history deletion,” he says. “If you’re not in the habit of deleting that data, you’ll probably be scared and surprised how much data has been collected.”
Read more from this issue of The Get:

Jared Lindzon
As a Toronto-based freelance journalist and author, Jared Lindzon writes for publications like The Toronto Star, The Globe & Mail, Fast Company, TIME Magazine, and others. His first book, Do More in Four: Why It’s Time for a Shorter Workweek, was published by Harvard Business Review Press in 2026.
The Get is owned by Neo Financial Technologies Inc. and the content it produces is for informational purposes only. Any views and opinions expressed are those of the individual authors or The Get editorial team and do not necessarily reflect the official policy or position of Neo Financial Technologies Inc. or any of its partners or affiliates.
Nothing in this newsletter is intended to constitute professional financial, legal, or tax advice, and should not be the sole source for making any financial decisions. Past performance is not a guarantee of future results. Neo Financial Technologies Inc. does not endorse any third-party views referenced in this content. Always do your due diligence before deciding what to do with your money.
© 2026 Neo Financial Technologies Inc. All rights reserved.





