CYBER WELFARE

Protect your Digital Privacy

The risks of your account being used for spam: what happens when someone else is writing

You usually find out from someone else’s message: “You’ve just sent me a strange link — was that you?” It’s tempting to see it as a nuisance and little more. But the risks of your account being used for spam go well beyond the annoyance. Spam means unsolicited messages sent in bulk to lots of people; when they come from your account, they carry your name and the trust other people place in you.

So the useful question isn’t “how many messages went out?” but: if someone can write in your name, what else can they do?

This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they show that the damage is never of just one kind.

It expands on the recommendation on checking messages sent in your name.

Three questions to measure an impact

For any account you use to communicate — email, social media, messaging apps — the right questions are these:

  1. What could someone who got in here read? — this is the confidentiality question.
  2. What could they write or post in my name, and to whom? — this is the integrity question.
  3. What would I lose if the account were blocked or taken from me? — this is the availability question.

Whoever is sending spam from your account has already answered the second question. The point is that, to do so, they also gained access to everything the first and third questions cover. The message your contacts see is the visible part of an access that usually goes much deeper.

1. Confidentiality: conversations stay between you and the people you chose

Confidentiality is the guarantee that information can be read only by those who are authorised to read it. A communication account holds a great deal of it, and not all of it is yours: every conversation has at least one other person on the other side.

A practical example

Someone manages to link a device of their own to your messaging app — for instance through the desktop version, or a link you were tricked into approving. A linked device is a second screen that sees the same chats as your phone, in real time. From that moment on it can read new conversations and, often, some of the older ones too.

What the incident looks like

Before sending a single message, whoever gets in looks around. They read your chats to work out who you talk to most, in what tone and about what. They copy your address book: names, numbers, addresses, sometimes even the notes you’ve attached to each contact. In group chats they find the details of people they’ve never met. Photos, documents and shared locations are part of the same archive. The copied address book stays with whoever took it, even after you’ve regained control of the account.

What to watch for

  • devices or sessions you don’t recognise in the account’s list of connections;
  • messages marked as read that you never opened;
  • notifications of a new sign-in or a newly linked device;
  • contacts receiving requests that include details only your conversations could have revealed.

What to do

Check the list of linked devices and active sessions regularly, and disconnect anything you don’t recognise. A session is the “already signed in” state a device keeps until it is closed. The post on linked devices on messaging apps explains where to look and how to judge what you find.

2. Integrity: only you write the messages sent in your name

Integrity is the guarantee that data isn’t altered by anyone without the right to do so. In a communication account, the most valuable piece of data is your identity: the fact that a message signed by you really is yours.

A practical example

The same message goes out from your profile to dozens of contacts: “Look, you’re in this video too”, followed by a link. The people who receive it have no reason to doubt it, because the sender is you. That link may lead to a page imitating a well-known service to ask for a password, or to a file that installs malware — a malicious program that works on a device without its owner knowing.

What the incident looks like

Whoever has read your chats knows who to write to and how to make it sound natural: a greeting with the right nickname, a reference to something recent, an urgent request for help. Alongside private messages, public posts, comments and group invitations may appear. In some cases the messages are deleted straight after sending, so you don’t see them in your history. Every contact who clicks can, in turn, become the starting point of a new wave. The post on contacts scammed in your name describes what actually happens to the people who receive those messages.

What to watch for

  • contacts asking you about messages you don’t remember writing;
  • posts, comments or stories on your profile that you didn’t publish;
  • a changed profile name, photo or description;
  • replies to conversations you never started.

What to do

When a contact tells you about a strange message, take it seriously even if you can’t see anything in your history. Look at your sent messages and your profile’s recent activity, then let the people involved know through a different channel from the compromised one. The signs of messages you did not send help you tell a real problem from a simple misunderstanding.

3. Availability: your account stays yours and usable

Availability is the guarantee of being able to use your data and your services when you need them. For an account being used for spam, the locked door can come from two directions: from whoever has taken it, and from the platform trying to stop it.

A practical example

One morning your messaging app asks you to verify your number again, or the social network tells you your profile has been restricted for “suspicious activity”. In the first case, someone has registered your account on another device; in the second, the platform’s automated systems have spotted an unusual volume of messages and blocked the account to protect other users.

What the incident looks like

A platform block is a protective measure, but it has a cost: while it lasts you can’t write to anyone, and lifting it means proving the account is yours. If in the meantime whoever got in has changed the recovery number or email address, the process becomes more complicated. Then there’s your history: years of chats, photos and documents can be lost if the account is reset without a backup — a safety copy — or if whoever had control deleted them. Finally, for an email address, bulk sending can land it among suspicious senders: your genuine messages may end up in recipients’ spam folders.

What to watch for

  • requests to verify your number or identity again that you didn’t start;
  • notices that your account is restricted, suspended or under review;
  • being suddenly signed out of the app on a device you used normally;
  • contacts no longer receiving your emails, or finding them in their spam folder.

What to do

Keep a recovery channel up to date and separate from the one you use every day, turn on chat backup if the service offers it, and store your recovery codes somewhere you can reach even without your phone. If your account is blocked, follow only the platform’s official procedures, reached from the app or its official address — never from a link received in a message.

AspectWhat someone who gets in can doWhy it matters
ConfidentialityReads conversations, copies your address book, gathers photos and documentsIt affects your contacts too, and a copied address book can’t be taken back
IntegrityWrites and posts in your name, exploits your contacts’ trust, covers their tracksPuts believable requests into circulation and damages relationships
AvailabilityLocks you out of the account or gets it blocked by the platformCuts off personal and work communication, sometimes with your history lost

One scenario that brings them together

One Friday evening a message arrives on your phone that seems to come from your messaging app’s support team: “To confirm your account, enter the code you’ve just received.” A code really has just arrived, so you enter it.

In the minutes that follow, whoever obtained the code registers your account on another phone. They read your chats and download your address book (confidentiality). They write to around thirty contacts, starting with the ones you talk to most, asking for a small urgent loan or for the same verification code, in your tone and with your nicknames (integrity). By Saturday morning your phone can no longer get in and, after a series of reports, the platform temporarily restricts the number (availability).

Three different impacts, a single cause: a verification code handed to someone who should never have had it. It’s the pattern that the post on messaging account takeover describes in detail, from the attacker’s side.

The impacts that show up later

Not every effect appears right away, which is why “I got my account back” doesn’t really close the matter.

  • The address book keeps circulating. Copied contacts can be used weeks later for messages that no longer come from your account, but mention your name to seem believable.
  • Access that stays open. A linked device or an active session can keep working even after a password change, unless it is explicitly closed.
  • Trust wears thin slowly. Some contacts stop opening your links; others write to you more warily. It’s a real cost, even if it never shows up in a notification.
  • Other people’s devices infected. Someone who opened an attachment or link that came “from you” may only discover later that there’s a problem on their own phone or computer.

This isn’t a reason to live on high alert. It’s the reason protection has to be preventive: a unique password, a second verification factor and a regular check of linked devices reduce all four of these effects, including the ones you’ll never see.

Not all accounts weigh the same

The impact depends on what an account holds, how many people it reaches and how much those people trust whoever is writing.

Type of accountMain impactWhy
Personal messaging appConfidentiality and integrityHolds intimate conversations and reaches the people closest to you, who trust you most
Main emailAll three, with a multiplier effectIt’s also the recovery key for your other accounts
Social mediaIntegrityMessages and posts reach many people, well beyond your close circle
Work accountsAll three, with effects on othersInvolves clients, colleagues and suppliers, and the organisation’s reputation
Profile on buy-and-sell platformsIntegrityMessages in your name can include believable payment requests
Forgotten accounts you signed in to with social loginLow on their own, high if linkedWhoever controls your main profile can reach them without you noticing

The last row deserves attention: an account being used for spam isn’t always the one you keep the closest eye on. The post on limiting social login explains why every extra connection widens the perimeter.

Why even a single message matters

Messages sent from a compromised account work because they exploit trust, not because they are sophisticated.

Message sent in your nameWhy it works
“Is that you in this video?” with a linkCuriosity and a touch of worry, from the most believable sender there is
“A code came to you by mistake — can you pass it on?”It looks like a trivial favour, but the code is used to take over the recipient’s account
“My phone’s broken, can you make an urgent transfer?”It combines urgency and affection: there seems to be no time to check
An attachment presented as an invoice, photo or documentIt comes from someone familiar, so it gets opened without a second thought

A single message opened can turn a contact into the next account used for spam. For the people receiving them, the guides on attachments from unknown senders and on spotting the signs of malware on your phone are useful.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessRecognising that a message sent in your name is the visible sign of a wider access
SkillsBeing able to read the confidentiality, integrity and availability of a communication account as three concrete questions
Secure BehaviourRegularly checking linked devices, active sessions and recovery channels, and taking contacts’ reports seriously

Reference level: FL2 — Beginner. This is the level at which you move from “someone sent spam from my account” to “I understand what they could see, do and take away from me.” To find out where to start, you can take the digital resilience self-assessment.

Summary

  • Confidentiality is about what gets read: conversations, address book, photos and documents — your contacts’ too.
  • Integrity is about what gets written in your name: messages, posts, requests that exploit the trust of people who know you.
  • Availability is about what you can no longer use: an account taken over or blocked by the platform, history lost.

Behind every unwanted message — which touches integrity — the other two impacts are almost always there as well. The signs your account was hacked are gathered in a dedicated post; to know straight away when someone gets in, it’s worth turning on account login alerts and protecting your accounts with a second factor.

One thing to do today. Open your main messaging app and the social network you use most, and check two things in each: the list of linked devices and the active sessions. Disconnect anything you don’t recognise. It takes about five minutes, and it covers all three impacts at once.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.