CYBER WELFARE

Protect your Digital Privacy

Signs of suspicious connected apps: how to spot them and what to do

Every time you choose “Sign in with” your social media profile, a small link is created between that profile and an outside service. It is almost always harmless. But some of these links stay active for years, with broader permissions than they need, and every now and then one of them starts behaving strangely.

This post brings together the signs of suspicious connected apps: the traces that show an app or service authorised to use your social profile is doing something you would not expect, or that someone else is using that link. For each sign you will find what it means, where you can see it and what to do when you come across it. In technical circles they are called indicators of compromise, or IOCs (Indicators of Compromise).

It is the diagnostic deep dive on the recommendation about limiting social login.

What indicators of compromise mean for connected apps

An indicator of compromise is an observable trace suggesting that something did not go the way it should have.

When it comes to connected apps, there are three terms worth knowing:

  • social login: the option to sign in to a website or app using a social network profile, instead of creating a new password;
  • connected app: any outside service you have given permission, even just once, to use your profile;
  • access token: a kind of digital pass that the social network hands to the app, which lets the app stay authorised without ever knowing your password.

A sign is not proof. It is an invitation to check: it may have a harmless explanation — a service you authorised and then forgot about — or it may mean that an app is misusing its permissions, or that your profile is within someone else’s reach.

The value of these signs lies in timing: noticing one early means you can close a link before it is used to post, write or collect data in your name.

Why they matter more when you sign in with social media

If every service has its own credentials, a problem with one app stays with that app.

With social login, though, your social profile becomes the gateway to many services at once. A sign on a connected app has to be read in two directions: it may concern that app, which perhaps has excessive permissions or has been compromised; or it may mean that the social profile itself is in someone else’s hands, and with it every service it opens.

There is a second reason too: the link is silent by nature. Once you have given consent, the app never asks you anything again. It can read your profile, friends or email address until the permission is revoked. Uninstalling the app from your phone is not enough: the authorisation lives on the social network’s servers, not on your device.

Technical indicators

These are the ones the social network records and makes available in the security and privacy sections of your profile, usually under a heading such as “Apps and websites”, “Connected apps” or “Signed in with your account”.

IndicatorWhat it meansWhy it mattersWhere you see itWhat to do
Connected apps you do not rememberA service you do not recognise appears in the listIt may be consent given without thinking, or an authorisation obtained through deception“Apps and websites” or “Connected apps” section of your profileIf you do not know what it is for, revoke access; if you need it, it will ask again
Broader permissions than necessaryThe app can post, or read messages or contacts, as well as your profileA broad permission is harmless while the app is honest, but becomes a problem if the app is compromisedPermission details for each appRevoke the app or, where the social network allows it, reduce its permissions to the essentials
Recent use of an app you abandonedAn app you have not opened for months shows as recently activeSomeone, or the app itself, is still using the link“Last used” or “Recently active” date, where availableRevoke access and check what was posted or shared during that period
Sign-in notifications from third-party servicesThe social network tells you your profile was used to sign in to a serviceIf it was not you, someone is using your profile as a keySecurity emails or notifications from the social networkIf you do not recognise the sign-in, change your social media password, turn on MFA and revoke the service
Requests for new permissions you never startedAn app that is already connected asks to expand what it can doIt may be a legitimate update, or an attempt to gain more accessConsent windows that pop up out of nowhereDecline, then check from the social network’s settings whether you really need the app
Names that imitate well-known services, or an anonymous developerThe app copies a familiar service or does not say who runs itThis is a common feature of apps built to harvest dataThe connected app’s information pageRevoke access; when in doubt, an app with no clear owner is not worth keeping
Warnings from the social network about an appThe platform reports that a connected app was removed or broke its rulesThe platform may notice before you doSecurity centre, in-app notifications, official emailsSign in from the official website or app, not from the links in the message, and check what it had been authorised to do

MFA, which appears in several rows, stands for multi-factor authentication: a second check, such as a code on your phone, on top of the password. How to set it up is explained in the post on protecting accounts with a second factor.

Signs you can observe yourself

These do not require you to open any settings page: you notice them simply by using your profile, your email and your phone as you normally would.

SignWhat it meansWhy it mattersHow you noticeWhat to do
Posts, stories or comments published in your nameAn app with permission to post, or someone with access to your profile, is writing on your behalfIt exposes your contacts to scams and damages your credibilityYou see them on your timeline, or someone points them outDelete the content, revoke apps that can post, change your password
Messages to your contacts that you did not writeYour profile was used to communicate with other peopleIt is the fastest way to spread harmful links by exploiting trustFriends or colleagues ask you about a messageWarn your contacts through another channel, check your sessions and connected apps
Unexpected welcome emailsA service thanks you for signing up “with your social profile”Someone may have used your profile to open an account, or you gave consent without realisingA sign-up confirmation you do not remember lands in your inboxDo not click the links in the message; check in the social network’s settings whether the service is connected
“Continue as…” windows after a simple clickA quiz, a game or an offer asks you to authorise your profileThis is the moment the link is created, and people often approve without readingWhile browsing, after opening a shared linkClose the window unless you were deliberately choosing to sign up to that service
New follows, likes or group membershipsYour profile is taking actions you did not takeIt points to an app with broad permissions, or unauthorised accessNotifications, or the list of pages and groups you followUndo the actions, revoke suspicious apps, check recent sign-ins
Game or app invitations sent from youYour contacts receive requests in your nameSome apps spread exactly this way, using your friends listSomeone asks why you invited themRevoke the app responsible and let the people who received the invitation know
An account that already existsYou try to sign up to a service and find you already have, through your social profileYour profile may have been used to open accounts without your knowledgeA message saying “this profile is already linked to an account”Sign in, check the account details, then decide whether to close or disconnect it

A concrete example

Sarah receives an email: “Welcome! Thanks for signing up with your social profile.” The service is a prize survey website she has never heard of. She assumes it is an advert and deletes it.

A week later, a friend messages her: why did she share an offer for sunglasses at an impossible price? Sarah has not shared anything.

When she opens the list of connected apps, she finds the survey website. Only then does she remember: a few days earlier she had clicked on a quiz sent by a contact, and a window had asked her to “continue as Sarah”. One click, without reading the permissions. Among them was permission to post on her profile.

Sarah revokes access, deletes the post, changes her password and turns on MFA on her social profile. Then she lets her friend know, and the contact the quiz came from.

The first sign was already enough. Treated as spam, the email was ignored; read as an indicator of a connected app, it would have led her to close the link before the post went out.

What to check right away

On the social profile you use to sign in to other services

  • the list of connected apps and websites, one by one;
  • each app’s permissions, especially the ability to post, read messages and see your contacts;
  • recent sign-ins and active sessions;
  • the status of multi-factor authentication.

On the email address linked to the profile

  • sign-up confirmations and welcome messages you do not remember;
  • security notifications from the social network over the past few months;
  • the recovery email address and phone number for your social profile.

If you find a suspicious indicator

  1. Revoke the app’s access from the social network’s settings. Uninstalling it from your phone is not enough: the authorisation stays active until you remove it from your profile settings.
  2. Change your social media password and turn on multi-factor authentication if it is not already active.
  3. Check what was done in your name: posts, messages, sign-ups, pages followed. Delete anything you do not recognise.
  4. Let your contacts know if they may have received messages or invitations, using a channel other than the affected profile.
  5. Review the important connected services and consider switching them to sign-in with their own credentials.

The full sequence, in the recommended order, is in the post on disconnecting apps from your social account. To understand how a link is created and why an app’s digital pass stays valid, see the explanation of how social login works.

What is not an indicator

Telling the difference helps you avoid two opposite mistakes: getting alarmed over nothing, and getting used to ignoring the real signs.

SituationWhy it is usually not a sign
A connected app with a different name from the one you knowThe settings page often shows the name of the company behind the service, not the app’s brand name
The social network asks you to reconfirm permissions for an app you useMany platforms let consent expire after a period of inactivity and ask for it again from time to time
A connected service writes to you about updated terms of useIt is a routine communication, not proof that the app is doing anything strange
Automatic sharing you set up yourselfA fitness app that posts your routes is doing what you asked it to; if anything, it is a setting worth reviewing
Adverts that seem to know your interestsThis comes down to how advertising systems work in general, not to a suspicious connected app
A fake profile with your photo messaging your friendsIt is a real problem, but it concerns a cloned account, not yours: report it to the platform

The rule of thumb: one isolated sign deserves a check; two signs together deserve action.

How often to check

You do not need a demanding routine. You just need one to exist.

FrequencyWhat to check
Whenever an unexpected notification or email arrivesCheck right away in the social network’s settings whether the service is connected
Every 3 monthsThe list of connected apps and their permissions, on every profile you use for social login
Every 6 monthsImportant services still linked to your social profile: consider giving them their own credentials
After trying a new quiz, game or appRevoke access straight away if you will not use it again
After news of a breach at a connected serviceRevoke the app involved and change your social media password

Setting a quarterly reminder works better than any good intention. If you would rather receive alerts than go looking for them, it is also worth turning on account login alerts: they are often the first sign to arrive.

Two important warnings

An indicator is not proof. An app with an unfamiliar name may be a service you use every day, listed under the company’s name. A welcome email may arrive late for a genuine sign-up. Check before you get alarmed — but always check.

No indicators is not a guarantee. An app that only reads your profile or friends list leaves no visible traces: it does not post, does not write, does not notify anyone. That is why protection does not rest on watching for signs, but on prevention: connecting fewer services, granting fewer permissions, reviewing the list regularly. The ways a link can be exploited are described in the post on attacks through connected apps.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to find the connected apps page, read its permissions and revoke access
AwarenessUnderstanding that a sign on a connected app may concern your social profile and every service that relies on it
Secure BehaviourReviewing connected apps regularly, without waiting for a post you did not write

Reference level: FL3 — Autonomous. This is the level at which you recognise a sign and act on it without needing outside support.

Conclusion

The signs of suspicious connected apps are not meant to make you wary of every service you use. They are meant for the opposite: knowing where to look, every now and then, so you can close a forgotten link before someone uses it in your place.

What to do right now. Open the settings of the social profile you use most often to sign in to other services and find the connected apps section. Count how many there are and how many you recognise. If there is one you do not remember, revoke it: you have just closed a door you did not need. If everything looks fine, you now know that this check takes five minutes and you can repeat it in a few months. To see where you stand on the other aspects of your digital security, you can take the digital resilience self-assessment.

Related resources

Short deep dives from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.