Case study
E-commerce brand account hijacked, email and 2FA changed by attacker
The situation
The owner of a home goods shop clicked a convincing “copyright violation” email and entered credentials on a fake page. Within an hour the attacker changed the email, phone and two-factor settings, then began posting crypto scams to 60K followers, damaging the brand by the day.
What the client had tried
The official hacked-account flow, twice, but the selfie verification kept failing because the account had been registered as a business without a face attached. Password resets went to the attacker’s email. The owner was preparing to give up the account and start over.
What we did
- Stopped the restart plan first: a new account would have abandoned 60K followers to an active scammer using the brand’s name.
- Switched the case to the ownership-evidence track suited to business accounts: original email access, purchase receipts for ads, domain ownership matching the account’s linked website and a device that had previously been logged in.
- Managed the verification sequence so each proof landed in the right step, and reported the scam posts through the proper channel in parallel.
Outcome and timeline
Access returned on day six. We then walked the owner through evicting the attacker completely: closing their sessions, removing their recovery email and rebuilding two-factor on hardware the attacker never touched. The scam posts were removed the same day.
Identifying details in this case study have been changed or removed to protect the client. The case type, sequence of events and timeline are real.