Skip to content

Music news, business and culture.

South African Police Service, Netflix, YouTube

South African Netflix and YouTube Accounts Hijacked via Cookie Theft

South Africa’s police service has issued a ten-step guide after cybercriminals used stolen browser cookies to hijack active Netflix, YouTube and email sessions.

South Africa is seeing a rise in cybercrime in which attackers steal browser cookies to hijack active sessions on platforms including Netflix, YouTube, Reddit and personal email accounts, without obtaining passwords.

Browser cookies are small data files stored on phones, tablets and computers that remember site preferences and keep users logged in. They also allow items to remain in a digital shopping cart after a browser is closed.

The Federal Bureau of Investigation (FBI) has identified “remember-me cookies” as a key target. These cookies let a user stay logged in without re-entering credentials. When attackers extract a cookie containing recent login data, they can carry out session hijacking, cloning the user’s digital identity and taking over an already logged-in session. This bypasses both passwords and two-factor authentication.

NordVPN, an international cybersecurity firm, has documented the practice in South Africa.

Stolen cookies have become a primary currency in the cybercriminal underground. Attackers usually harvest them by infecting a device with infostealer malware, often through social engineering such as suspicious websites or phishing links that download the malware in the background.

The South African Police Service (SAPS) has issued a warning and a ten-step guide for users in South Africa.

SAPS ten-step prevention guide

  • Implement strict password hygiene. Create strong, unique passwords for every account. Passwords should be at least 10 characters long and include uppercase letters, lowercase letters, numbers and special characters. Avoid writing them down and change them regularly.
  • Activate your firewall. Keep the device’s built-in firewall active. Firewalls monitor network traffic and block unauthorized connections to malicious or unknown websites.
  • Use antivirus and anti-malware software. Install reputable security software to prevent viruses from taking root. Update these programs regularly so they recognize the latest threat signatures.
  • Block spyware intrusions. Install and maintain dedicated anti-spyware software to counter infostealers that target browser cookies.
  • Lock down social media privacy. Limit the personal information shared online. Set profiles on platforms such as Facebook, X (formerly Twitter), YouTube and others to private, and routinely audit security settings.
  • Secure mobile devices. Smartphones and tablets are also vulnerable to hijacking. Download applications only from official sources such as the Apple App Store or Google Play Store.
  • Enable automatic operating system (OS) and app updates. Cybercriminals often exploit known vulnerabilities in outdated software. Enable automatic updates for operating systems including Windows, macOS, Linux, iOS and Android, and for all installed applications.
  • Encrypt and back up sensitive data. Protect critical files such as financial records, tax returns and personal identification with data encryption. Maintain regular backups on a separate offline hard drive or secure cloud location.
  • Fortify your home Wi-Fi network. Default router settings leave home networks susceptible to intrusion. Review network configurations, change default administrator passwords, and ensure Wi-Fi is protected with strong encryption such as Wi-Fi Protected Access 3 (WPA3).
  • Exercise caution on public Wi-Fi. Public hotspots are insecure and are common sites for packet sniffing and cookie theft. Avoid financial transactions, corporate network access, or logging into sensitive accounts while connected to public Wi-Fi.

Head writer at Afrobeats Wire, covering Afrobeats news, business and culture.

More like this