You usually find out from someone else’s message: “You’ve just sent me a strange link — was that you?” It’s tempting to see it as a nuisance and little more. But the risks of your account being used for spam go well beyond the annoyance. Spam means unsolicited messages sent in bulk to lots of people; when they come from your account, they carry your name and the trust other people place in you.
So the useful question isn’t “how many messages went out?” but: if someone can write in your name, what else can they do?
This post answers it by looking at the three aspects by which the security of any information is measured: that it stays private, that it stays correct, and that it stays available. They are the practical translation of three technical words — confidentiality, integrity, availability — and they show that the damage is never of just one kind.
It expands on the recommendation on checking messages sent in your name.
Three questions to measure an impact
For any account you use to communicate — email, social media, messaging apps — the right questions are these:
- What could someone who got in here read? — this is the confidentiality question.
- What could they write or post in my name, and to whom? — this is the integrity question.
- What would I lose if the account were blocked or taken from me? — this is the availability question.
Whoever is sending spam from your account has already answered the second question. The point is that, to do so, they also gained access to everything the first and third questions cover. The message your contacts see is the visible part of an access that usually goes much deeper.
1. Confidentiality: conversations stay between you and the people you chose
Confidentiality is the guarantee that information can be read only by those who are authorised to read it. A communication account holds a great deal of it, and not all of it is yours: every conversation has at least one other person on the other side.
A practical example
Someone manages to link a device of their own to your messaging app — for instance through the desktop version, or a link you were tricked into approving. A linked device is a second screen that sees the same chats as your phone, in real time. From that moment on it can read new conversations and, often, some of the older ones too.
What the incident looks like
Before sending a single message, whoever gets in looks around. They read your chats to work out who you talk to most, in what tone and about what. They copy your address book: names, numbers, addresses, sometimes even the notes you’ve attached to each contact. In group chats they find the details of people they’ve never met. Photos, documents and shared locations are part of the same archive. The copied address book stays with whoever took it, even after you’ve regained control of the account.
What to watch for
- devices or sessions you don’t recognise in the account’s list of connections;
- messages marked as read that you never opened;
- notifications of a new sign-in or a newly linked device;
- contacts receiving requests that include details only your conversations could have revealed.
What to do
Check the list of linked devices and active sessions regularly, and disconnect anything you don’t recognise. A session is the “already signed in” state a device keeps until it is closed. The post on linked devices on messaging apps explains where to look and how to judge what you find.
2. Integrity: only you write the messages sent in your name
Integrity is the guarantee that data isn’t altered by anyone without the right to do so. In a communication account, the most valuable piece of data is your identity: the fact that a message signed by you really is yours.
A practical example
The same message goes out from your profile to dozens of contacts: “Look, you’re in this video too”, followed by a link. The people who receive it have no reason to doubt it, because the sender is you. That link may lead to a page imitating a well-known service to ask for a password, or to a file that installs malware — a malicious program that works on a device without its owner knowing.
What the incident looks like
Whoever has read your chats knows who to write to and how to make it sound natural: a greeting with the right nickname, a reference to something recent, an urgent request for help. Alongside private messages, public posts, comments and group invitations may appear. In some cases the messages are deleted straight after sending, so you don’t see them in your history. Every contact who clicks can, in turn, become the starting point of a new wave. The post on contacts scammed in your name describes what actually happens to the people who receive those messages.
What to watch for
- contacts asking you about messages you don’t remember writing;
- posts, comments or stories on your profile that you didn’t publish;
- a changed profile name, photo or description;
- replies to conversations you never started.
What to do
When a contact tells you about a strange message, take it seriously even if you can’t see anything in your history. Look at your sent messages and your profile’s recent activity, then let the people involved know through a different channel from the compromised one. The signs of messages you did not send help you tell a real problem from a simple misunderstanding.
3. Availability: your account stays yours and usable
Availability is the guarantee of being able to use your data and your services when you need them. For an account being used for spam, the locked door can come from two directions: from whoever has taken it, and from the platform trying to stop it.
A practical example
One morning your messaging app asks you to verify your number again, or the social network tells you your profile has been restricted for “suspicious activity”. In the first case, someone has registered your account on another device; in the second, the platform’s automated systems have spotted an unusual volume of messages and blocked the account to protect other users.
What the incident looks like
A platform block is a protective measure, but it has a cost: while it lasts you can’t write to anyone, and lifting it means proving the account is yours. If in the meantime whoever got in has changed the recovery number or email address, the process becomes more complicated. Then there’s your history: years of chats, photos and documents can be lost if the account is reset without a backup — a safety copy — or if whoever had control deleted them. Finally, for an email address, bulk sending can land it among suspicious senders: your genuine messages may end up in recipients’ spam folders.
What to watch for
- requests to verify your number or identity again that you didn’t start;
- notices that your account is restricted, suspended or under review;
- being suddenly signed out of the app on a device you used normally;
- contacts no longer receiving your emails, or finding them in their spam folder.
What to do
Keep a recovery channel up to date and separate from the one you use every day, turn on chat backup if the service offers it, and store your recovery codes somewhere you can reach even without your phone. If your account is blocked, follow only the platform’s official procedures, reached from the app or its official address — never from a link received in a message.
| Aspect | What someone who gets in can do | Why it matters |
|---|---|---|
| Confidentiality | Reads conversations, copies your address book, gathers photos and documents | It affects your contacts too, and a copied address book can’t be taken back |
| Integrity | Writes and posts in your name, exploits your contacts’ trust, covers their tracks | Puts believable requests into circulation and damages relationships |
| Availability | Locks you out of the account or gets it blocked by the platform | Cuts off personal and work communication, sometimes with your history lost |
One scenario that brings them together
One Friday evening a message arrives on your phone that seems to come from your messaging app’s support team: “To confirm your account, enter the code you’ve just received.” A code really has just arrived, so you enter it.
In the minutes that follow, whoever obtained the code registers your account on another phone. They read your chats and download your address book (confidentiality). They write to around thirty contacts, starting with the ones you talk to most, asking for a small urgent loan or for the same verification code, in your tone and with your nicknames (integrity). By Saturday morning your phone can no longer get in and, after a series of reports, the platform temporarily restricts the number (availability).
Three different impacts, a single cause: a verification code handed to someone who should never have had it. It’s the pattern that the post on messaging account takeover describes in detail, from the attacker’s side.
The impacts that show up later
Not every effect appears right away, which is why “I got my account back” doesn’t really close the matter.
- The address book keeps circulating. Copied contacts can be used weeks later for messages that no longer come from your account, but mention your name to seem believable.
- Access that stays open. A linked device or an active session can keep working even after a password change, unless it is explicitly closed.
- Trust wears thin slowly. Some contacts stop opening your links; others write to you more warily. It’s a real cost, even if it never shows up in a notification.
- Other people’s devices infected. Someone who opened an attachment or link that came “from you” may only discover later that there’s a problem on their own phone or computer.
This isn’t a reason to live on high alert. It’s the reason protection has to be preventive: a unique password, a second verification factor and a regular check of linked devices reduce all four of these effects, including the ones you’ll never see.
Not all accounts weigh the same
The impact depends on what an account holds, how many people it reaches and how much those people trust whoever is writing.
| Type of account | Main impact | Why |
|---|---|---|
| Personal messaging app | Confidentiality and integrity | Holds intimate conversations and reaches the people closest to you, who trust you most |
| Main email | All three, with a multiplier effect | It’s also the recovery key for your other accounts |
| Social media | Integrity | Messages and posts reach many people, well beyond your close circle |
| Work accounts | All three, with effects on others | Involves clients, colleagues and suppliers, and the organisation’s reputation |
| Profile on buy-and-sell platforms | Integrity | Messages in your name can include believable payment requests |
| Forgotten accounts you signed in to with social login | Low on their own, high if linked | Whoever controls your main profile can reach them without you noticing |
The last row deserves attention: an account being used for spam isn’t always the one you keep the closest eye on. The post on limiting social login explains why every extra connection widens the perimeter.
Why even a single message matters
Messages sent from a compromised account work because they exploit trust, not because they are sophisticated.
| Message sent in your name | Why it works |
|---|---|
| “Is that you in this video?” with a link | Curiosity and a touch of worry, from the most believable sender there is |
| “A code came to you by mistake — can you pass it on?” | It looks like a trivial favour, but the code is used to take over the recipient’s account |
| “My phone’s broken, can you make an urgent transfer?” | It combines urgency and affection: there seems to be no time to check |
| An attachment presented as an invoice, photo or document | It comes from someone familiar, so it gets opened without a second thought |
A single message opened can turn a contact into the next account used for spam. For the people receiving them, the guides on attachments from unknown senders and on spotting the signs of malware on your phone are useful.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Awareness | Recognising that a message sent in your name is the visible sign of a wider access |
| Skills | Being able to read the confidentiality, integrity and availability of a communication account as three concrete questions |
| Secure Behaviour | Regularly checking linked devices, active sessions and recovery channels, and taking contacts’ reports seriously |
Reference level: FL2 — Beginner. This is the level at which you move from “someone sent spam from my account” to “I understand what they could see, do and take away from me.” To find out where to start, you can take the digital resilience self-assessment.
Summary
- Confidentiality is about what gets read: conversations, address book, photos and documents — your contacts’ too.
- Integrity is about what gets written in your name: messages, posts, requests that exploit the trust of people who know you.
- Availability is about what you can no longer use: an account taken over or blocked by the platform, history lost.
Behind every unwanted message — which touches integrity — the other two impacts are almost always there as well. The signs your account was hacked are gathered in a dedicated post; to know straight away when someone gets in, it’s worth turning on account login alerts and protecting your accounts with a second factor.
One thing to do today. Open your main messaging app and the social network you use most, and check two things in each: the list of linked devices and the active sessions. Disconnect anything you don’t recognise. It takes about five minutes, and it covers all three impacts at once.
Related content
- Checking messages sent in your name — the recommendation this expands on
- Contacts scammed in your name — the concrete effects on the people who receive the messages, and on your relationships
- Signs of messages you did not send — how to notice that one of these impacts is already under way
- What to do if your account is sending messages — what to do, in order of priority
Related resources
Short pieces from the Resources section, for anyone who wants to focus on a single aspect:
- The Final Step: How to Log Out of Your Accounts
- How to Recognise Phishing When It Is Built to Be Convincing
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



