Every time you choose “Sign in with” your social media profile, a small link is created between that profile and an outside service. It is almost always harmless. But some of these links stay active for years, with broader permissions than they need, and every now and then one of them starts behaving strangely.
This post brings together the signs of suspicious connected apps: the traces that show an app or service authorised to use your social profile is doing something you would not expect, or that someone else is using that link. For each sign you will find what it means, where you can see it and what to do when you come across it. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise).
It is the diagnostic deep dive on the recommendation about limiting social login.
What indicators of compromise mean for connected apps
An indicator of compromise is an observable trace suggesting that something did not go the way it should have.
When it comes to connected apps, there are three terms worth knowing:
- social login: the option to sign in to a website or app using a social network profile, instead of creating a new password;
- connected app: any outside service you have given permission, even just once, to use your profile;
- access token: a kind of digital pass that the social network hands to the app, which lets the app stay authorised without ever knowing your password.
A sign is not proof. It is an invitation to check: it may have a harmless explanation — a service you authorised and then forgot about — or it may mean that an app is misusing its permissions, or that your profile is within someone else’s reach.
The value of these signs lies in timing: noticing one early means you can close a link before it is used to post, write or collect data in your name.
If every service has its own credentials, a problem with one app stays with that app.
With social login, though, your social profile becomes the gateway to many services at once. A sign on a connected app has to be read in two directions: it may concern that app, which perhaps has excessive permissions or has been compromised; or it may mean that the social profile itself is in someone else’s hands, and with it every service it opens.
There is a second reason too: the link is silent by nature. Once you have given consent, the app never asks you anything again. It can read your profile, friends or email address until the permission is revoked. Uninstalling the app from your phone is not enough: the authorisation lives on the social network’s servers, not on your device.
Technical indicators
These are the ones the social network records and makes available in the security and privacy sections of your profile, usually under a heading such as “Apps and websites”, “Connected apps” or “Signed in with your account”.
| Indicator | What it means | Why it matters | Where you see it | What to do |
|---|---|---|---|---|
| Connected apps you do not remember | A service you do not recognise appears in the list | It may be consent given without thinking, or an authorisation obtained through deception | “Apps and websites” or “Connected apps” section of your profile | If you do not know what it is for, revoke access; if you need it, it will ask again |
| Broader permissions than necessary | The app can post, or read messages or contacts, as well as your profile | A broad permission is harmless while the app is honest, but becomes a problem if the app is compromised | Permission details for each app | Revoke the app or, where the social network allows it, reduce its permissions to the essentials |
| Recent use of an app you abandoned | An app you have not opened for months shows as recently active | Someone, or the app itself, is still using the link | “Last used” or “Recently active” date, where available | Revoke access and check what was posted or shared during that period |
| Sign-in notifications from third-party services | The social network tells you your profile was used to sign in to a service | If it was not you, someone is using your profile as a key | Security emails or notifications from the social network | If you do not recognise the sign-in, change your social media password, turn on MFA and revoke the service |
| Requests for new permissions you never started | An app that is already connected asks to expand what it can do | It may be a legitimate update, or an attempt to gain more access | Consent windows that pop up out of nowhere | Decline, then check from the social network’s settings whether you really need the app |
| Names that imitate well-known services, or an anonymous developer | The app copies a familiar service or does not say who runs it | This is a common feature of apps built to harvest data | The connected app’s information page | Revoke access; when in doubt, an app with no clear owner is not worth keeping |
| Warnings from the social network about an app | The platform reports that a connected app was removed or broke its rules | The platform may notice before you do | Security centre, in-app notifications, official emails | Sign in from the official website or app, not from the links in the message, and check what it had been authorised to do |
MFA, which appears in several rows, stands for multi-factor authentication: a second check, such as a code on your phone, on top of the password. How to set it up is explained in the post on protecting accounts with a second factor.
Signs you can observe yourself
These do not require you to open any settings page: you notice them simply by using your profile, your email and your phone as you normally would.
| Sign | What it means | Why it matters | How you notice | What to do |
|---|---|---|---|---|
| Posts, stories or comments published in your name | An app with permission to post, or someone with access to your profile, is writing on your behalf | It exposes your contacts to scams and damages your credibility | You see them on your timeline, or someone points them out | Delete the content, revoke apps that can post, change your password |
| Messages to your contacts that you did not write | Your profile was used to communicate with other people | It is the fastest way to spread harmful links by exploiting trust | Friends or colleagues ask you about a message | Warn your contacts through another channel, check your sessions and connected apps |
| Unexpected welcome emails | A service thanks you for signing up “with your social profile” | Someone may have used your profile to open an account, or you gave consent without realising | A sign-up confirmation you do not remember lands in your inbox | Do not click the links in the message; check in the social network’s settings whether the service is connected |
| “Continue as…” windows after a simple click | A quiz, a game or an offer asks you to authorise your profile | This is the moment the link is created, and people often approve without reading | While browsing, after opening a shared link | Close the window unless you were deliberately choosing to sign up to that service |
| New follows, likes or group memberships | Your profile is taking actions you did not take | It points to an app with broad permissions, or unauthorised access | Notifications, or the list of pages and groups you follow | Undo the actions, revoke suspicious apps, check recent sign-ins |
| Game or app invitations sent from you | Your contacts receive requests in your name | Some apps spread exactly this way, using your friends list | Someone asks why you invited them | Revoke the app responsible and let the people who received the invitation know |
| An account that already exists | You try to sign up to a service and find you already have, through your social profile | Your profile may have been used to open accounts without your knowledge | A message saying “this profile is already linked to an account” | Sign in, check the account details, then decide whether to close or disconnect it |
A concrete example
Sarah receives an email: “Welcome! Thanks for signing up with your social profile.” The service is a prize survey website she has never heard of. She assumes it is an advert and deletes it.
A week later, a friend messages her: why did she share an offer for sunglasses at an impossible price? Sarah has not shared anything.
When she opens the list of connected apps, she finds the survey website. Only then does she remember: a few days earlier she had clicked on a quiz sent by a contact, and a window had asked her to “continue as Sarah”. One click, without reading the permissions. Among them was permission to post on her profile.
Sarah revokes access, deletes the post, changes her password and turns on MFA on her social profile. Then she lets her friend know, and the contact the quiz came from.
The first sign was already enough. Treated as spam, the email was ignored; read as an indicator of a connected app, it would have led her to close the link before the post went out.
What to check right away
On the social profile you use to sign in to other services
- the list of connected apps and websites, one by one;
- each app’s permissions, especially the ability to post, read messages and see your contacts;
- recent sign-ins and active sessions;
- the status of multi-factor authentication.
On the email address linked to the profile
- sign-up confirmations and welcome messages you do not remember;
- security notifications from the social network over the past few months;
- the recovery email address and phone number for your social profile.
If you find a suspicious indicator
- Revoke the app’s access from the social network’s settings. Uninstalling it from your phone is not enough: the authorisation stays active until you remove it from your profile settings.
- Change your social media password and turn on multi-factor authentication if it is not already active.
- Check what was done in your name: posts, messages, sign-ups, pages followed. Delete anything you do not recognise.
- Let your contacts know if they may have received messages or invitations, using a channel other than the affected profile.
- Review the important connected services and consider switching them to sign-in with their own credentials.
The full sequence, in the recommended order, is in the post on disconnecting apps from your social account. To understand how a link is created and why an app’s digital pass stays valid, see the explanation of how social login works.
What is not an indicator
Telling the difference helps you avoid two opposite mistakes: getting alarmed over nothing, and getting used to ignoring the real signs.
| Situation | Why it is usually not a sign |
|---|---|
| A connected app with a different name from the one you know | The settings page often shows the name of the company behind the service, not the app’s brand name |
| The social network asks you to reconfirm permissions for an app you use | Many platforms let consent expire after a period of inactivity and ask for it again from time to time |
| A connected service writes to you about updated terms of use | It is a routine communication, not proof that the app is doing anything strange |
| Automatic sharing you set up yourself | A fitness app that posts your routes is doing what you asked it to; if anything, it is a setting worth reviewing |
| Adverts that seem to know your interests | This comes down to how advertising systems work in general, not to a suspicious connected app |
| A fake profile with your photo messaging your friends | It is a real problem, but it concerns a cloned account, not yours: report it to the platform |
The rule of thumb: one isolated sign deserves a check; two signs together deserve action.
How often to check
You do not need a demanding routine. You just need one to exist.
| Frequency | What to check |
|---|---|
| Whenever an unexpected notification or email arrives | Check right away in the social network’s settings whether the service is connected |
| Every 3 months | The list of connected apps and their permissions, on every profile you use for social login |
| Every 6 months | Important services still linked to your social profile: consider giving them their own credentials |
| After trying a new quiz, game or app | Revoke access straight away if you will not use it again |
| After news of a breach at a connected service | Revoke the app involved and change your social media password |
Setting a quarterly reminder works better than any good intention. If you would rather receive alerts than go looking for them, it is also worth turning on account login alerts: they are often the first sign to arrive.
Two important warnings
An indicator is not proof. An app with an unfamiliar name may be a service you use every day, listed under the company’s name. A welcome email may arrive late for a genuine sign-up. Check before you get alarmed — but always check.
No indicators is not a guarantee. An app that only reads your profile or friends list leaves no visible traces: it does not post, does not write, does not notify anyone. That is why protection does not rest on watching for signs, but on prevention: connecting fewer services, granting fewer permissions, reviewing the list regularly. The ways a link can be exploited are described in the post on attacks through connected apps.
How this connects to the Cyber Welfare Framework
| Pillar | What this content contributes |
|---|---|
| Skills | Knowing how to find the connected apps page, read its permissions and revoke access |
| Awareness | Understanding that a sign on a connected app may concern your social profile and every service that relies on it |
| Secure Behaviour | Reviewing connected apps regularly, without waiting for a post you did not write |
Reference level: FL3 — Autonomous. This is the level at which you recognise a sign and act on it without needing outside support.
Conclusion
The signs of suspicious connected apps are not meant to make you wary of every service you use. They are meant for the opposite: knowing where to look, every now and then, so you can close a forgotten link before someone uses it in your place.
What to do right now. Open the settings of the social profile you use most often to sign in to other services and find the connected apps section. Count how many there are and how many you recognise. If there is one you do not remember, revoke it: you have just closed a door you did not need. If everything looks fine, you now know that this check takes five minutes and you can repeat it in a few months. To see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.
Related resources
Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:
- App Permissions: Deciding What Each App Can Reach
- Security and Privacy Settings: The Half Hour Worth Spending
Related content
- Limiting social login — the recommendation this belongs to
- Attacks through connected apps — the threats that generate these signs
- Disconnecting apps from your social account — what to do, in the right order
- How social login works — tokens, permissions and revocation explained simply
- Social login risks — what gets hit when a sign is confirmed
Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.



