What to do if…
an unknown third-party app, access token, API key, or connection appears on your account
Short answer
Treat the connection as potentially unauthorised. Using a trusted device, record its basic details, revoke or remove its access, secure the account, and use the service’s official controls to rotate, regenerate, revoke, or replace any API key, token, or other secret that may have been exposed.
Do not do these things
- Do not approve a sign-in, verification request, or permission prompt that you did not initiate.
- Do not follow links in unexpected security emails or messages; open the service through its official app or website instead.
- Do not contact the unknown app using details contained in a suspicious message.
- Do not share passwords, recovery codes, API keys, tokens, or verification codes with anyone offering to investigate.
- Do not assume that changing the password will automatically cancel every existing app connection, session, token, or API key.
- Do not erase all records of the connection before noting the name, permissions, creation time, and recent activity where these are visible.
- Do not continue using a possibly exposed API key or token after replacing it.
What to do now
-
Open the account through its official app or by entering the known website address yourself. If you suspect the device you are using is infected or remotely controlled, use another trusted and updated device.
-
Go to the account’s security, privacy, connected apps, integrations, authorised applications, API keys, tokens, or active sessions area. Record the unknown item’s name, permissions, creation date, last-used time, and any linked account or device. Take a screenshot if it is safe to do so.
-
Revoke, disconnect, disable, remove, or delete the unknown app, token, API key, or connection through the account’s own settings. End other unfamiliar sessions and remove devices you do not recognise.
-
If an API key, access token, client secret, webhook secret, recovery code, or similar credential may have been exposed, use the service’s official controls to rotate, regenerate, revoke, or replace it as appropriate. Revoke or disable the old value where the service supports that, and update any legitimate application that relies on the credential without sending or displaying the new value unnecessarily.
-
Change the account password to a strong, unique password that you do not use elsewhere. If the same or a similar password is used on other accounts, change those too, beginning with the email account used for recovery.
-
Turn on two-step verification or a passkey where available. Review registered email addresses, phone numbers, recovery methods, trusted devices, security keys, and application passwords, and remove anything unfamiliar.
-
Check recent activity for actions you did not make. Look for changes to security settings, new administrators, sent messages, purchases, data exports, email forwarding rules, filters, newly created credentials, and altered recovery details.
-
For a work, school, client, or organisation-managed account, contact the responsible IT or security team promptly through a known internal route. Give them the details you recorded and follow their incident process.
-
Contact the account provider through its official support or recovery route if you cannot revoke the access, cannot sign in, or the unknown connection returns. Warn relevant contacts if unauthorised messages may have been sent from your account.
-
If money has been taken or payment details may have been misused, contact your bank or card provider immediately. Cybercrime or fraud can be reported through Report Fraud in England, Wales and Northern Ireland. In Scotland, contact Police Scotland.
What can wait
You do not need to identify who created the connection, understand every technical permission, rebuild every device, or decide whether to close the account before containing the access. Detailed investigation, long-term security changes, and decisions about replacing services can wait until the unknown access has been revoked and the account is stable.
Important reassurance
An unfamiliar connection does not always mean that someone has full control of the account. It may be an old integration, a renamed service, or a forgotten sign-in. Revoking access, replacing exposed credentials, and securing the account can limit further activity.
Scope note
This guide covers immediate containment and account-security steps only. Further investigation, restoration, regulatory reporting, or a wider system response may require the account provider, an organisation’s security team, or a qualified cyber-security professional.
Important note
This is general information, not legal, financial, technical, or professional cyber-security advice. Account controls and credential behaviour vary between services, so use the provider’s official instructions and seek specialist help where sensitive, business-critical, or regulated data may be affected.
Additional Resources
- National Cyber Security Centre — Hacked accounts
- National Cyber Security Centre — Recovering a hacked account
- National Cyber Security Centre — Top tips for staying secure online
- National Cyber Security Centre — Top tips for staying secure online
- Police.uk — Reporting a fraud
- Police Scotland — Hacked accounts
About this guide
This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.