Case study · Cybersecurity incident response

Stolen in a session, not in a password

Information-stealing malware on one administrator’s Mac copied a live Facebook session. The attacker replayed it, spent inside the business’s own advertising account, and never needed the password or an MFA code. IP Care established the root cause, rebuilt the endpoint and returned the business to safe operation.

Book a security review
Client
UAE SMEName withheld at the client’s request
Exposure
Business social and advertising accounts
Services delivered
Digital forensics & incident response, endpoint rebuild, identity hardening
Engagement
Ten weeks, exposure to closure
5 stages

Attack path reconstructed, from delivery to persistence

6

Unauthorised integrations identified and removed

0

Threats detected on the full post-rebuild endpoint scan

4 days

From forensic review to a validated, hardened endpoint

The situation

A business that runs on its Meta presence

The client is a UAE SME that wins a large share of its new business through Facebook and Instagram, managed from a single administrator’s MacBook and supported by an external marketing agency. That one device held the live sessions for the company’s Meta Business portfolio, its Microsoft 365 account and its commercial systems.

The client noticed advertising activity it had not authorised. Within days Meta restricted the advertising account entirely — in the middle of a launch campaign. IP Care was engaged to establish what had happened, contain it, and return the business to a state it could trust.

The challenge

Four problems at once

  • Unauthorised spend. A fraudulent campaign ran inside the client’s own advertising account, with the daily spend limit raised by several hundred times in a single change.
  • An account behaving as its owner. Profile data was changed by automated tooling running through fabricated or replayed device profiles — with no failed logins to trace.
  • Broad third-party access. Six integrations appeared and were removed inside a single day, while legitimate agency and CRM connections held far more permission than they needed.
  • Commercial disruption. With the advertising account locked, lead generation stopped during the campaign the business had built its quarter around.

Incident at a glance

Ten weeks from exposure to controlled rebuild

  1. Day 0
    Facebook session cookie created in Chrome on the Mac
    Later copied and reused by the attacker.
  2. Weeks 1–4
    Information-stealing malware active on the Mac
    Credentials and browser sessions exposed.
  3. Day 26
    Session replay and logins from attacker infrastructure
    Unrecognised access and automated profile changes.
  4. Day 33
    Endpoint AV removes a crypto-miner and its Launch Agent
    Persistence gone, but the stolen session data stayed exposed.
  5. Day 39
    Fraudulent campaign created and the daily spend limit raised sharply
    Unauthorised spend begins inside the client’s own account.
  6. Day 58
    Meta locks the account
    Access blocked while identity recovery proceeds.
  7. Days 61–64
    Forensic review followed by a controlled Mac rebuild
    Endpoint remediated and security controls validated.

Our approach

Evidence first, then rebuild

Rebuilding a compromised machine destroys the evidence that explains it, so IP Care sequenced the work to deliver both — the account of what happened, and a device the client could use again.

  1. 1

    Preserve and investigate

    Targeted forensic triage, persistence scans and malware-sample recovery on the Mac, with a full review of Meta login records, portfolio roles, payment activity and integrations — corroborated against threat intelligence.

  2. 2

    Contain the exposure

    Use of the affected Mac was restricted, key account passwords were reset with MFA enabled, active sessions and trusted devices were reviewed, and excessive third-party access was escalated for removal.

  3. 3

    Rebuild under control

    The Mac was erased and configured as a new device. No system backup, browser profile, cookies or extensions were restored; only known business documents were carried across, scanned before restoration.

  4. 4

    Harden and validate

    Full OS patching, automatic updates, FileVault, firewall, disabled sharing and remote access, one managed endpoint-protection product, and a clean full-scan result recorded before any account was reconnected.

  5. 5

    Reconnect, monitor, close

    Accounts were reconnected in a controlled order behind written release approval, followed by daily checks for seven days, second-daily checks to day 14, and a documented closure package of residual risks and responsibilities.

What we found

The password was never the weak point

Reconstructed from the recovered malware sample, endpoint persistence artefacts and the platform’s own login records, the attack runs in five stages. Only the first depends on the user making a mistake.

Five-stage attack path and why existing controls did not stop it
StageWhat occurredWhy controls did not stop it
1 · DeliveryA ClickFix-style lure led to a command running on the MacThe first click could not be recovered
2 · InfectionInfostealer malware ran at login via a Launch AgentEndpoint protection was not active
3 · TheftBrowser cookies, credentials and the live session were copiedA live session is an authenticated user
4 · ReplayThe session was loaded on attacker infrastructureNo password or MFA code is requested
5 · PersistencePassword resets did not terminate all sessionsThe open session survived the resets

Root cause

Authenticated-session theft from the endpoint, compounded by delayed endpoint protection, incomplete session revocation and broad third-party permissions. Strong passwords and MFA were in place; neither is enough on its own once a live session token leaves the device. This is now a standard route into business advertising accounts: no failed login appears, no code is requested, and the first visible symptom is money already spent.

The result

A device the client can trust again

Delivered

  • A complete, evidenced account of the attack — delivered before anything was erased.
  • The unauthorised spend quantified and packaged for the platform dispute.
  • A rebuilt Mac with managed endpoint protection, encryption, firewall and automatic updates.
  • Sessions revoked, MFA strengthened and recovery methods verified across Apple, Microsoft 365 and Meta.
  • A self-service method of procedure the client can follow again without specialist help.

What changed going forward

  • Every password reset is now paired with a full session revocation.
  • Phishing-resistant MFA and passkeys where the platform supports them.
  • One managed endpoint-protection product, always on and centrally visible.
  • Least privilege for agencies and integrations, reviewed quarterly.
  • Business-critical accounts accessed only from trusted, fully updated devices.

What we told the client honestly

Reinstatement of the advertising account sits with the platform, not with us, and we said so from the start. The technical engagement could be closed on evidence: the endpoint erased, rebuilt and validated; identities reviewed and reset; unauthorised access removed where technically possible; and residual risks written down and accepted. “Clean” is a defined position, not a guarantee — and the client knew exactly which part of the problem remained outside anyone’s control.

Common questions

Session theft, answered

How can an attacker get in without the password or an MFA code?

Once you sign in, the browser stores a session token that proves you already authenticated. Information-stealing malware copies that token along with saved credentials. Replayed on another machine, it presents as an already-authenticated user, so the platform has no reason to ask for a password or a code.

Does changing the password fix it?

Not on its own. A reset that does not terminate existing sessions leaves the stolen one alive — and if the malware is still on the device, it simply captures the replacement session. Resets must be paired with a full session revocation and carried out from a clean device.

Can fraudulent advertising spend be recovered?

That decision belongs to the platform. What an investigation can do is quantify the spend, evidence the unauthorised access behind it and package both for the dispute and appeal. IP Care is explicit about this distinction before the work starts.

Seeing activity you did not authorise?

Forensic investigation, endpoint recovery and identity hardening — delivered by IP Care Technologies in Abu Dhabi since 2003, with 15+ years of cybersecurity practice behind it.

Talk to our team

Client name withheld at the client’s request. Details are drawn from the engagement’s closeout report; figures that could identify the client or the live platform dispute have been omitted.

Call UsChat with us on WhatsAppSession Hijacking Incident Response Case Study | IP Care UAE