About

Social Media Recovery,
done properly

AwareXone helps people and brands recover hacked, disabled, and locked accounts through legitimate channels, and hardens the human layer attackers still target. Limited cases. Honest review. Not cheap by design.

fig. 01The attack surface that answers
01The gap

Walk into most organisations and you will find real money spent on detection, identity and response, alongside a security awareness module people click through once a year. Then read the incident reports. Almost every one starts the same way: somebody was convinced. On social platforms the same pattern shows up as takeovers, disables, and lockouts that self-serve support cannot finish.

02What changed

That gap was survivable for a long time, because convincing people at scale was expensive and attackers had to choose their targets. That constraint is gone. A model now writes a flawless, personalised pretext, clones a voice from a webinar, and joins a video call wearing a face your finance team trusts. The same generation of attacker also drains accounts, changes recovery contacts, and leaves owners outside their own digital identity.

03Where we sit

AwareXone exists for that shift. Our flagship work is Social Media Recovery from Malaysia: hacked, disabled, and locked accounts through legitimate platform channels, with a limited caseload and honest case review for clients nationwide and worldwide. We also run authorised social-engineering programmes and publish open-source security tools. Outcomes stay best-effort. Platforms decide. We are not a cheap “guaranteed recovery” shop.

04Why part of it is free

The people and organisations targeted hardest are often the ones least able to pay anybody, so we fund an open-source program alongside the service work: tools, playbooks, and research, released without a catch. Paid recovery stays limited on purpose. Doing it properly does not scale like a mass-market restore promise.

What we believe

Four positions everything else follows from

01

People are not the weakest link

They are the most targeted one, which is a different claim. Systems fail silently; people notice things and report them. Treat staff as sensors to be equipped rather than liabilities to be trained at, and the numbers move.

02

Blame destroys security

The moment somebody fears the consequence of admitting a mistake, your detection time collapses. Every part of our reporting is designed so that owning up is the easiest available option.

03

Evidence beats assertion

We would rather show working ownership evidence and a realistic path than invent a guarantee. If a case looks hopeless or improper, we say so before anyone pays.

04

Defence should not be a luxury

The groups least able to absorb a loss are targeted the hardest. Reserving engineering time for free tooling is not marketing for us, it is a condition of the work being worth doing.

What we are not

The short list

  • We do not promise “guaranteed recovery” or invent success rates.
  • We do not collect passwords, OTP codes, or session cookies on this site.
  • We do not resell products or take vendor commission.
  • We do not sell a platform subscription and call it a program.
  • We do not send a junior to deliver what a partner sold.
  • We do not name individuals who fail a simulation.
  • We do not manufacture severity to justify an invoice.
  • We do not test anything without written authorisation.
How we operate

The practical details

Primary marketMalaysiaKuala Lumpur, Cyberjaya, Selangor, nationwide. Remote case review worldwide
Who we helpIndividuals to enterprisesCreators, founders, brands, and teams. No headcount minimum for recovery
CaseloadLimited by designWe take fewer cases so each one gets an accountable human process
Who leads thisFounder-ledMd Shariar Shanaz Shuvon · ethical hacker and researcher. Speaking credentials

Tell us what happened

Start with a private case review. We reply within five hours and say honestly whether a legitimate path looks realistic. No passwords. No outcome guarantees we cannot keep.