Case study · Cybersecurity incident response
Stolen in a session, not in a password
Information-stealing malware on one administrator’s Mac copied a live Facebook session. The attacker replayed it, spent inside the business’s own advertising account, and never needed the password or an MFA code. IP Care established the root cause, rebuilt the endpoint and returned the business to safe operation.
Book a security review- Client
- UAE SMEName withheld at the client’s request
- Exposure
- Business social and advertising accounts
- Services delivered
- Digital forensics & incident response, endpoint rebuild, identity hardening
- Engagement
- Ten weeks, exposure to closure
Attack path reconstructed, from delivery to persistence
Unauthorised integrations identified and removed
Threats detected on the full post-rebuild endpoint scan
From forensic review to a validated, hardened endpoint
The situation
A business that runs on its Meta presence
The client is a UAE SME that wins a large share of its new business through Facebook and Instagram, managed from a single administrator’s MacBook and supported by an external marketing agency. That one device held the live sessions for the company’s Meta Business portfolio, its Microsoft 365 account and its commercial systems.
The client noticed advertising activity it had not authorised. Within days Meta restricted the advertising account entirely — in the middle of a launch campaign. IP Care was engaged to establish what had happened, contain it, and return the business to a state it could trust.
The challenge
Four problems at once
- Unauthorised spend. A fraudulent campaign ran inside the client’s own advertising account, with the daily spend limit raised by several hundred times in a single change.
- An account behaving as its owner. Profile data was changed by automated tooling running through fabricated or replayed device profiles — with no failed logins to trace.
- Broad third-party access. Six integrations appeared and were removed inside a single day, while legitimate agency and CRM connections held far more permission than they needed.
- Commercial disruption. With the advertising account locked, lead generation stopped during the campaign the business had built its quarter around.
Incident at a glance
Ten weeks from exposure to controlled rebuild
- Day 0Facebook session cookie created in Chrome on the MacLater copied and reused by the attacker.
- Weeks 1–4Information-stealing malware active on the MacCredentials and browser sessions exposed.
- Day 26Session replay and logins from attacker infrastructureUnrecognised access and automated profile changes.
- Day 33Endpoint AV removes a crypto-miner and its Launch AgentPersistence gone, but the stolen session data stayed exposed.
- Day 39Fraudulent campaign created and the daily spend limit raised sharplyUnauthorised spend begins inside the client’s own account.
- Day 58Meta locks the accountAccess blocked while identity recovery proceeds.
- Days 61–64Forensic review followed by a controlled Mac rebuildEndpoint remediated and security controls validated.
Our approach
Evidence first, then rebuild
Rebuilding a compromised machine destroys the evidence that explains it, so IP Care sequenced the work to deliver both — the account of what happened, and a device the client could use again.
- 1
Preserve and investigate
Targeted forensic triage, persistence scans and malware-sample recovery on the Mac, with a full review of Meta login records, portfolio roles, payment activity and integrations — corroborated against threat intelligence.
- 2
Contain the exposure
Use of the affected Mac was restricted, key account passwords were reset with MFA enabled, active sessions and trusted devices were reviewed, and excessive third-party access was escalated for removal.
- 3
Rebuild under control
The Mac was erased and configured as a new device. No system backup, browser profile, cookies or extensions were restored; only known business documents were carried across, scanned before restoration.
- 4
Harden and validate
Full OS patching, automatic updates, FileVault, firewall, disabled sharing and remote access, one managed endpoint-protection product, and a clean full-scan result recorded before any account was reconnected.
- 5
Reconnect, monitor, close
Accounts were reconnected in a controlled order behind written release approval, followed by daily checks for seven days, second-daily checks to day 14, and a documented closure package of residual risks and responsibilities.
What we found
The password was never the weak point
Reconstructed from the recovered malware sample, endpoint persistence artefacts and the platform’s own login records, the attack runs in five stages. Only the first depends on the user making a mistake.
| Stage | What occurred | Why controls did not stop it |
|---|---|---|
| 1 · Delivery | A ClickFix-style lure led to a command running on the Mac | The first click could not be recovered |
| 2 · Infection | Infostealer malware ran at login via a Launch Agent | Endpoint protection was not active |
| 3 · Theft | Browser cookies, credentials and the live session were copied | A live session is an authenticated user |
| 4 · Replay | The session was loaded on attacker infrastructure | No password or MFA code is requested |
| 5 · Persistence | Password resets did not terminate all sessions | The open session survived the resets |
Root cause
Authenticated-session theft from the endpoint, compounded by delayed endpoint protection, incomplete session revocation and broad third-party permissions. Strong passwords and MFA were in place; neither is enough on its own once a live session token leaves the device. This is now a standard route into business advertising accounts: no failed login appears, no code is requested, and the first visible symptom is money already spent.
The result
A device the client can trust again
Delivered
- A complete, evidenced account of the attack — delivered before anything was erased.
- The unauthorised spend quantified and packaged for the platform dispute.
- A rebuilt Mac with managed endpoint protection, encryption, firewall and automatic updates.
- Sessions revoked, MFA strengthened and recovery methods verified across Apple, Microsoft 365 and Meta.
- A self-service method of procedure the client can follow again without specialist help.
What changed going forward
- Every password reset is now paired with a full session revocation.
- Phishing-resistant MFA and passkeys where the platform supports them.
- One managed endpoint-protection product, always on and centrally visible.
- Least privilege for agencies and integrations, reviewed quarterly.
- Business-critical accounts accessed only from trusted, fully updated devices.
What we told the client honestly
Reinstatement of the advertising account sits with the platform, not with us, and we said so from the start. The technical engagement could be closed on evidence: the endpoint erased, rebuilt and validated; identities reviewed and reset; unauthorised access removed where technically possible; and residual risks written down and accepted. “Clean” is a defined position, not a guarantee — and the client knew exactly which part of the problem remained outside anyone’s control.
Common questions
Session theft, answered
How can an attacker get in without the password or an MFA code?
Once you sign in, the browser stores a session token that proves you already authenticated. Information-stealing malware copies that token along with saved credentials. Replayed on another machine, it presents as an already-authenticated user, so the platform has no reason to ask for a password or a code.
Does changing the password fix it?
Not on its own. A reset that does not terminate existing sessions leaves the stolen one alive — and if the malware is still on the device, it simply captures the replacement session. Resets must be paired with a full session revocation and carried out from a clean device.
Can fraudulent advertising spend be recovered?
That decision belongs to the platform. What an investigation can do is quantify the spend, evidence the unauthorised access behind it and package both for the dispute and appeal. IP Care is explicit about this distinction before the work starts.
Related services
How we can help
Incident Response
Containment, forensics and recovery when something gets through — on retainer or on call.
ExploreEndpoint Protection
Managed EDR/XDR deployed and monitored, so malware never gets the chance to sit idle on a device.
ExploreMicrosoft Entra ID
Identity hardening, conditional access and phishing-resistant MFA across your business accounts.
ExploreManaged IT Services
Proactive monitoring, endpoint management and SLA-backed support, so an exposure like this is caught before it costs anything.
ExploreSeeing activity you did not authorise?
Forensic investigation, endpoint recovery and identity hardening — delivered by IP Care Technologies in Abu Dhabi since 2003, with 15+ years of cybersecurity practice behind it.
Client name withheld at the client’s request. Details are drawn from the engagement’s closeout report; figures that could identify the client or the live platform dispute have been omitted.