CYBER WELFARE

Protect your Digital Privacy

Checking messages sent in your name: what to do when a contact warns you

One afternoon a message arrives from a friend: “Sorry, did you send me that link? It looked a bit odd.” Or a colleague asks why you wrote to them at three in the morning asking for an urgent favour. You did not write anything, and the first reaction is almost always the same: it must be a mistake, it must be spam, it will pass.

Sometimes that is exactly what it is. Other times the message really did leave your account, sent by someone who found a way in. And the person who receives it trusts it, because it carries your name, your photo, the way you usually say hello. Messages sent behind your back are almost always meant to spread infected links, harvest passwords or ask for money, exploiting the trust people place in you.

This recommendation — R29 of the Cyber Welfare Framework — helps you with checking messages sent in your name and responding calmly and in order when something does not add up. You do not need to be an expert and there is no need to panic: what you need is to take the warning seriously, look in the right places and follow a few steps in the right sequence.

What this recommendation says

Recommendation R29 states that every report of a message you did not write should be taken seriously and checked, by looking at what has left your accounts and at who has access to those accounts.

In practice it asks for three things:

  • listen to your contacts: they are often the first, and sometimes the only ones, to notice that something is wrong;
  • check from the inside: look at your sent messages, your active sessions and your linked devices, rather than simply hoping it is a false alarm;
  • close off and warn: if you find traces of access that is not yours, secure the account and let anyone who may have been reached know.

Two terms come up often. A session is a login that stays open on a device, so you do not have to enter your password every time you use it. Linked devices are computers, tablets or browsers that a messaging app has given access to your conversations, usually by scanning a QR code.

What it is not. It is not the general list of signs that an account has been hacked: that is the subject of the guide on how to tell if your account was hacked. R29 starts from one specific clue, the messages, and one specific source, the people who receive them. Nor is it an invitation to be suspicious of every strange email: not every message that appears to come from you actually left your account.

Where it applies. To every channel you use to talk to other people: personal and work email, social media profiles, messaging apps on your phone and computer, and text messages.

Why it matters

An account that can send messages is valuable to whoever controls it for one simple reason: trust. A message from a stranger is treated with suspicion; the same message from a friend, a relative or a colleague gets opened without a second thought.

That is why messages sent in your name tend to have one of these aims:

  • spreading malware — malware is software written to act against the interests of the person using the device; a link or attachment “to have a look at” is the quickest way to get it installed;
  • phishing — luring people to fake pages that imitate real services in order to steal passwords and codes;
  • asking for money or favours — top-ups, urgent bank transfers, verification codes “sent by mistake”;
  • widening the theft — every contact who falls for it becomes, in turn, a new starting point.

The more time passes, the further the damage spreads. And there is your reputation, too: someone who receives a request for money from your number may feel hurt, even once they realise it was not you. Reacting early and clearly is the best way to protect that relationship as well.

Benefit of checkingWhy it counts
Breaks the chainEvery hour saved reduces the contacts reached and those who might fall for it
Protects the people who know youFamily, friends and colleagues are the first targets of messages in your name
Reveals hidden accessSessions and linked devices show who else is using the account
Protects your reputationA clear, timely warning avoids misunderstandings and mistrust
Gives you back controlYou know what happened, what you have closed and what is left to check

A concrete example

Helen gets a phone call from her sister: “I got an email from you saying ‘have a look at these photos from lunch’, but the link goes to a page asking for my password. Was that you?” Helen has not sent any email.

Her first instinct is to say it must be spam. Instead, she opens her email on the computer and checks the sent folder. She finds dozens of emails sent the night before, all identical, addressed to almost everyone in her contacts.

At that point she goes into the account’s security settings and looks at the list of recent logins: alongside her phone and her computer, there is a session open on a device she does not recognise, in a city she has never been to. Helen signs out of every session, changes her password to a new one she has never used anywhere else, and turns on multi-factor authentication.

Then she checks her forwarding rules — the instructions her mailbox follows automatically on incoming messages. She finds one she did not create, sending a copy of all her incoming mail to an unknown address. She deletes it.

Finally she sends a short message to every contact who was reached: her email was used by someone else, the link should not be opened, and anyone who has already opened it would do well to change the password for the service they were asked about. Two people reply to thank her: their finger was already on the link.

Without her sister’s phone call, that forwarding rule could have stayed active for months.

When to apply it

The recommendation always applies, but some moments make it particularly useful.

  • When a contact tells you about a strange message. This is the main case: even if it seems impossible, it is worth checking.
  • When you get replies to messages you do not remember writing. Someone answers “sure, I’ll send you the code right away” or “I can’t do the transfer right now”.
  • When you receive verification codes you did not ask for. It may be a sign that someone is trying to register your number or your account on another device.
  • After using a shared or public computer. If you forgot to sign out, the session may still be open. Why that matters so much is explained in the Resource on how to log out of your accounts.
  • After clicking a suspicious link or entering your password on a doubtful page. Even if nothing seemed to happen at the time.
  • Periodically, as a habit. Every now and then, even without any warning signs, a look at sessions and linked devices takes only a few minutes.

How to apply it

When a warning arrives, the order of the steps matters more than speed.

  1. Take the report seriously. Ask the person who warned you which channel the message came through, at what time, and if possible for a screenshot. Do not open the link to “see what is there”.
  2. Check your sent messages. In your email, the sent folder; on social media and in messaging apps, your recent conversations. Bear in mind that whoever is using the account secretly sometimes deletes what they sent: an empty folder is not enough to rule out a problem.
  3. Look at sessions and linked devices. Almost every service shows active logins and authorised devices in its security settings. If you find something you do not recognise, disconnect it. Signing out of every session except the one you are using is a sensible choice.
  4. Change the password. A new, long password, used only for that account. If it was the same as on other services, change it there too.
  5. Turn on multi-factor authentication. MFA (Multi-Factor Authentication) asks for a second check on top of the password, such as a code or a confirmation on your phone. It is the most effective way of protecting accounts with a second factor even when the password is no longer secret. In messaging apps, look for the two-step verification PIN.
  6. Check forwarding rules and connected apps. In your email, make sure there are no rules that forward or delete messages automatically. On social media, check which apps are authorised to act on your behalf: the guide to signs of suspicious connected apps helps you recognise them.
  7. Warn your contacts. A short, clear message, ideally through another channel as well: what happened, not to open links or attachments received from you in recent hours, not to send codes or money, and to call you if in doubt.
  8. Turn on alerts for the future. Account login alerts tell you when someone signs in from a new device, so next time you might know before your contacts do.

If the messages went out by text or through the messaging app and the account looks in order, the problem may lie in the phone itself: in that case it is worth spotting the signs of malware on your phone calmly, one sign at a time.

Common mistakes to avoid

  • Assuming it must be spam. Dismissing the warning without looking is the most common mistake, and the most costly one.
  • Confusing a forged sender with a hacked account. With email, it is possible to make your address appear as the sender without getting into your account: this is called spoofing. On social media, someone can create a clone profile with your photo. In these cases your password is not the problem, but your contacts should still be warned and the fake profile reported to the platform.
  • Changing the password and stopping there. If a session stays open or a device stays linked, whoever got in can keep reading and writing even without the new password.
  • Forgetting forwarding rules. They are silent: everything seems back to normal, while a copy of your mail keeps going out.
  • Warning your contacts with a vague message. “I’ve had a problem” is not enough. You need to say what not to open and what not to do.
  • Replying from the compromised channel before securing it. Whoever controls the account can read the reply, delete it or answer in your place.
  • Feeling embarrassed and saying nothing. This can happen to anyone. Silence only helps the person using your name.

How this connects to the Cyber Welfare Framework

R29 takes security beyond a single device: it is about the way your accounts touch the lives of the people who know you.

PillarHow this contributes
SkillsKnowing how to find the sent folder, active sessions, linked devices and forwarding rules in your own accounts
AwarenessUnderstanding that a hacked account hits your contacts’ trust first, and that not every forged sender means a hacked account
Secure BehaviourResponding to every report with an orderly check and a clear warning, instead of ignoring it

Digital maturity levels.

  • FL1 — Basic. When a contact reports a strange message, you assume it is spam and do not check. It is an understandable reaction, not a fault.
  • FL2 — Beginner. You take the warning seriously, check your sent messages, change your password and warn your contacts.
  • FL3 — Autonomous. You know how to check sessions, linked devices, forwarding rules and authorised apps, and you have MFA turned on for the accounts you use to communicate.
  • FL4 — Skilled. You check logins and devices regularly even without warning signs, and you have turned on new-login alerts.
  • FL5 — Expert-Guide. You help family, friends or colleagues understand what happened and secure their accounts when they receive or send suspicious messages.

R29 is a typical step at FL2, and it paves the way towards the independence of FL3.

How to check you are applying it properly

Three questions, to be answered honestly.

  1. If a friend told me tomorrow that they had received a strange link from me, would I know where to look to find out whether it came from my account?
  2. Do I know how many devices are linked right now to my messaging app and my email?
  3. Do I already have in mind, at least roughly, the message I would send to warn my contacts?

Quick checklist

  • ☐ I know where to find the sent folder and the recent conversations for each account
  • ☐ I have checked the active sessions on my email and social media in recent months
  • ☐ There are no linked devices I do not recognise on my messaging app
  • ☐ There are no forwarding rules in my mailbox that I did not create
  • ☐ MFA is turned on for the accounts I use to communicate with others
  • ☐ I have turned on new-login alerts wherever the service offers them

If a box stays empty, you already have your next step. If you would like a more structured measure of where you stand, you can take the digital resilience self-assessment.

In short

When a contact tells you they have received a strange message from you, that warning is valuable information: it may be the first sign that someone is using your account to exploit the trust of the people who know you.

The response is not complicated, but it needs to follow an order: check your sent messages, close sessions and devices you do not recognise, change the password, turn on MFA, check forwarding rules and connected apps, and warn your contacts in plain words.

No check makes an account invulnerable. But knowing where to look turns a moment of confusion into a series of concrete steps, and lets you remain the only voice that speaks in your name.

Something to think about. If someone wrote to your contacts today pretending to be you, how long would it take you to notice?

Explore this recommendation

This recommendation is the pivot of a content unit. Each post looks at a different aspect.

Related resources

Short reads from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.