CYBER WELFARE

Protect your Digital Privacy

What to do if your account is sending messages you did not write: the steps in order

A friend texts you: “Sorry, what was that link you sent me this morning?” You did not send any link. A little later a colleague asks about a similar message, and then your cousin gets in touch to ask whether you really need to borrow money.

When one of your accounts sends messages without your consent, it usually means that someone else has managed to get into it, or has linked a device of their own to your messaging app. It is not your fault and it is not a disaster: it is a situation that can be put right, as long as you move calmly and in the right order.

This post organises the response into four moments: prevent it from happening, detect the signs, respond by closing the door, and recover to a stable situation. It is the practical, hands-on side of the recommendation on checking messages sent in your name: here you will find what to do once the messages have already gone out.

Before you start: why the order matters

The first instinct is to write to everyone straight away, or to delete the messages that were sent. Both reactions are understandable, but it pays to close the door first. If whoever got in is still connected, they can keep writing while you warn your contacts, and read their replies.

The sequence worth following is this one:

  1. sign out of sessions and remove linked devices;
  2. change the password;
  3. turn on multi-factor authentication and the verification PIN;
  4. check forwarding rules and connected apps;
  5. warn your contacts with a clear message;
  6. report what happened to the platform;
  7. check your phone;
  8. keep the evidence.

If you have ten minutes, spend them on the first three steps: they are the ones that take away someone else’s ability to keep writing in your place.

A quick check first. On social networks, your contacts sometimes receive messages from a profile with your photo and your name, but a different username. In that case it is not your account doing the writing: it is a copy created by someone else. It should be reported, but steps 1–4 matter less. How to tell the two situations apart is explained in the post on the signs of messages you did not send.

1. Prevention: reducing the risk before it happens

Use a different password for every account

What to do. If your email password is the same one you used on a site that was breached years ago, anyone who finds it can try it everywhere. A unique password limits the damage to a single service: the reasoning is set out in the recommendation on a unique password for every account.

Never share verification codes

What to do. A verification code is the short number a service sends you by text message or notification to confirm that it really is you. It should never be given to anyone, not even to a contact who says they received it “by mistake”. This is one of the most common ways a messaging account is taken over: the mechanism is described in the post on messaging account takeover.

Be wary of links that ask you to sign in

What to do. If a message invites you to “verify your account” through a link, go to the service through its own app or its official address instead. It is the basic rule against phishing, messages designed to steal your login details. To train your eye, there is the resource on how to recognise phishing.

2. Detection: noticing early

Listen to whoever warns you

What to do. When a contact asks you about a message you do not remember, do not brush it off as a misunderstanding. Ask for a screenshot, the time it arrived and the channel it came through. It is often the first sign, and it tends to arrive before any notification.

Keep login alerts switched on

What to do. Many services can tell you when someone signs in from a new device. Turning them on is the subject of the recommendation on account login alerts; here it is enough to remember to read them rather than archive them unopened.

Glance at your sent messages now and then

What to do. Every few weeks, open your sent email folder and scroll through your recent chats. Look for messages you do not remember writing, especially if they went out at night or to many people at once. The other signs that someone else has access are gathered in the post on how to tell if your account was hacked.

3. Response: closing the door

This is where the order matters most. If the account involved is your email, start there: from that inbox almost every other account can be reset.

Sign out of sessions and remove linked devices

What to do. A session is a login that has been left open in a browser or an app; a linked device is a computer or tablet paired with your messaging app, which receives and sends messages as if it were your phone. Open the section called “linked devices”, “active sessions” or “where you are signed in” and close everything you do not recognise. Where it exists, use “sign out of all devices”.

On messaging apps this is often the decisive step: where to find the option and how to read the list is explained in the post on linked devices on messaging apps. For good habits around signing out, there is also the resource on how to log out of your accounts.

Change the password

What to do. Straight afterwards, set a new password that is long and unique, and not derived from the old one. Many services close other sessions when the password changes; if yours does not, repeat the sign-out. Do it from a device you trust.

If you can no longer get in. Use only the official recovery procedure, reached through the service’s own app or website. Be wary of anyone who contacts you offering to “recover your account” for a fee: that is a scam in its own right.

Turn on multi-factor authentication and the verification PIN

What to do. Multi-factor authentication (MFA) asks, on top of your password, for a second proof: a code from a dedicated app, a notification to approve, or a physical security key. On messaging apps tied to your phone number, the equivalent is the verification PIN (sometimes called “two-step verification”): a code you choose yourself, requested whenever someone tries to register your number on another phone.

Why it matters. For someone who has stolen your password or a text-message code, that alone is no longer enough to get back in. The reasons are explored in the recommendation on protecting accounts with a second factor.

Do not forget. Save your recovery codes, the backup codes that let you back in if you lose your phone, somewhere you can reach even without the phone, and choose a PIN that is not your date of birth.

Check forwarding rules and connected apps

What to check in your email. A forwarding rule is an instruction that automatically sends a copy of your messages to another address; a filter can move certain emails straight to the bin. Someone who gets into an inbox uses them to keep reading your mail even after the password has changed, or to hide your contacts’ replies. Look at automatic forwarding, filters, automatic replies, your signature and your recovery details (secondary email address and phone number).

What to check in connected apps. These are the services you have allowed to use your account, often through “Sign in with…”. An authorised app can keep posting or sending even after a password change. Remove anything you do not recognise: the signs of a suspicious app are covered in the post on suspicious connected apps, and the thinking behind this kind of access in the recommendation on limiting social login.

4. Recovery: putting things back in order

Warn your contacts with a clear message

What to do. Now that the door is closed, write to the people involved. If you are not sure who received what, a short message to all your recent contacts is fine. Keep the tone simple and avoid alarming anyone:

“Hi, over the last few hours some messages were sent from my account that I did not write. If you received links, or requests for money or codes, please do not open them or reply. My account is back under my control now. If you have already clicked or paid, let me know and I will tell you what to do.”

Do not forget. Anyone who may already have replied, clicked or paid should be reached through a different channel, for example a phone call. What the people contacted can do is explained in the post on contacts scammed in your name.

Report what happened to the platform

What to do. Almost every service has an option to report a compromised account or spam sent from your profile. Reach it through the official app or website. Reporting helps block the harmful links and leaves a record that will be useful if you need to recover the account later on.

Check your phone

What to do. If messages keep going out even after you have closed the sessions and changed the password, the source may be the phone itself. Malware, a harmful program installed without your knowledge, can send messages from your apps. How to notice it is the subject of the recommendation on spotting the signs of malware on your phone.

Keep the evidence

What to keep. Screenshots of the messages that went out and of those your contacts forwarded to you, with dates and times; the emails from the service confirming logins or changes; the list of people involved. Store them in a folder outside the affected account.

Why it matters. You will need them to report the problem to the platform, to recover the account if it comes to that and, if someone has lost money, to report it to the police or your country’s official cybercrime reporting service. If you have already deleted some of it, that is fine: keep whatever is left.

A plan in three twenty-minute sessions

If this feels like a lot, here is a version in three stages.

Session 1 — Right away (20 minutes)

  1. Close any sessions and linked devices you do not recognise.
  2. Change the password to a new, unique one.
  3. Turn on MFA or the verification PIN and save your recovery codes.

With this single session, nobody else can write in your place any more.

Session 2 — The same day (20 minutes)

  1. Check automatic forwarding, filters, recovery details and connected apps.
  2. Send your contacts the warning message and phone anyone who may have replied.
  3. Report the compromised account to the platform.

Session 3 — Over the following days (20 minutes, repeatable)

  1. Gather screenshots and emails into one folder.
  2. Check sessions and linked devices again after a few days.
  3. If messages are still going out, check your phone.

In three sessions you have closed the door, warned the people who needed warning and left a tidy record behind you.

Common mistakes when putting things right

Even people who react quickly often trip up at the same points.

  • Warning your contacts before closing the door. Whoever is inside reads the replies and can send a new message contradicting yours.
  • Changing the password and forgetting linked devices. A device paired with your messaging app can stay active even with new login details.
  • Deleting every message that went out straight away. It removes the evidence and does not stop anyone who is still connected.
  • Not looking at forwarding rules. Your email keeps going out in copy, even with a new password.
  • Giving a verification code to someone helping you “remotely”. No genuine support service will ask you for it.
  • Keeping quiet out of embarrassment. The sooner your contacts know, the less likely it is that anyone falls for it.

Action checklist

Phase 1 — Close the door

  • ☐ Unknown sessions and linked devices signed out
  • ☐ New, unique password set
  • ☐ MFA or verification PIN switched on, recovery codes saved

Phase 2 — Look for anything still open

  • ☐ Automatic forwarding, filters and automatic replies checked
  • ☐ Recovery email and phone number verified
  • ☐ Connected apps reviewed and revoked if not recognised

Phase 3 — Warn and report

  • ☐ Warning message sent to your contacts
  • ☐ Anyone who replied or paid contacted through another channel
  • ☐ Compromised account reported to the platform

Phase 4 — Consolidate

  • ☐ Phone checked, if messages kept going out
  • ☐ Evidence gathered in a folder outside the account
  • ☐ Reminder set to check sessions and sent messages again in a month

Mini-scenario

One Saturday morning Lucy gets a call from a friend: a message has arrived from her number asking her friend to cover an urgent payment.

Lucy does not write to everyone straight away. She opens her messaging app, goes to linked devices and finds a computer she has never used: she unlinks it. Then she turns on the verification PIN and checks her email, where she finds no unusual rules. Only then does she send her contacts the warning message, call her friend to thank her and report what happened through the app. She keeps the screenshots in a folder.

In half an hour she has closed the door. Had she warned everyone first, whoever was connected would have read the replies and written back “all fine, it was just a joke”.

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
SkillsKnowing how to carry out, in the right order, the steps that take control of an account away from someone using it to write in your name
AwarenessUnderstanding why you close the door before warning your contacts, and why linked devices matter as much as the password
Secure BehaviourResponding with method, warning people without shame and regularly checking sessions and sent messages

Reference level: FL2 — Beginner. This is the level at which you recognise the main risks and follow a clear sequence of steps, without needing any particular technical skills.

Conclusion

An account sending messages in your name is not your fault, and it can almost always be made secure again. What counts is the order: close sessions and linked devices, change the password, add the second check, look at what is still open, and only then warn, report and keep the evidence.

What to do right now. Open the “linked devices” section of your messaging app today and turn on the verification PIN, if you have not done so already. It takes two minutes.

To see where you stand, the digital resilience self-assessment gives you a reference point.

Related content

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.