The Leaked Cookies API returns browser cookies stolen from employee devices by infostealer malware, matched to your domain and enriched with device and source context. A leaked session cookie lets an attacker skip the login page entirely - even with a strong password and MFA.
Infostealer malware copies the browser profile of an infected machine - saved logins and every cookie in it. When those logs are traded or leaked, Webz.io collects them, extracts the cookies, and matches them to the domains you monitor.
Each record is one cookie: its name, value, the host it belongs to, the browser it was taken from, when it expires, and the machine it came from.
Every record is enriched at collection time:
AUTH, SESSION, REFRESH, UNCLASSIFIED), browser, and expiration time.domain you want to check - see Quickstart.next URL to page through the rest - see Pagination.The first time you query a domain, Webz.io starts monitoring it. Until the initial scan finishes, responses carry "domainStatus": "pending" and may be empty or partial. Once it reads "active", the initial scan is complete - new records keep arriving as they are discovered, so query again over time.
A leaked session or auth cookie is a live credential. Treat every active record as an open session to revoke.