PanicStation.org
us Technology & digital loss

What to do if…
an unknown third-party app, access token, API key, or connection appears on your account

Produced and maintained by PanicStation.org Published: Last reviewed: Editorial policy USA guide

Short answer

Open the service directly on a device you trust, record the details shown for the unfamiliar item, then revoke or disable it through the service’s official security settings. For a work, school, shared, or production account, alert the administrator or responsible security contact immediately.

Do not do these things

  • Do not follow links in an unexpected email, text, or security alert to reach the account.
  • Do not paste an API key, access token, or other secret into a search engine, chat, email, or ordinary support ticket.
  • Do not reconnect or use the unfamiliar item to test it.
  • Do not delete security alerts, audit records, or other useful details before recording them.
  • Do not assume that changing the account password will also revoke every app connection, token, or API key.
  • Do not start changing every unrelated credential before containing the unfamiliar access, unless the provider or your security team directs you to do so.
  • Do not ignore the item merely because you can still sign in normally.

What to do now

  1. On a device you trust, type the service’s address yourself or use its official app. Open the area for security, authorized apps, connected services, integrations, sessions, developer settings, or API credentials.

  2. Record any details shown, such as the item’s name, developer or owner, permissions, creation time, last-used time, and resources it can reach. Take a screenshot if appropriate, but do not copy the complete token or API key into ordinary notes.

  3. Check whether you or another trusted account owner recently added the item. For a work, school, shared, or production account, contact the administrator or responsible team through a known channel and ask whether it belongs to an approved system.

  4. If the item remains unrecognized, use the provider’s revoke, remove, disable, suspend, or disconnect control. Be aware that removing a legitimate connection may interrupt an app or automated process, so involve the responsible administrator promptly when the account supports important systems.

  5. If the item is an API key or access token, revoke or disable that credential. Create a replacement only for a known system that genuinely needs one, restrict it to the minimum available permissions, and place the replacement in the system’s approved secret-storage location rather than sending it in a message.

  6. Secure the main account. Change its password to a unique password, sign out other sessions where that option is available, verify the recovery email address and phone number, and enable multifactor authentication if it is available and not already active.

  7. Review recent sign-ins, security events, authorized apps, tokens, API activity, app passwords, account-recovery changes, email forwarding rules, and payment changes that the service shows. Remove or report anything else you do not recognize.

  8. If you cannot revoke the item, it reappears, or you see continuing unauthorized activity, use the provider’s official account-recovery or support route. If personal information has been used for identity theft, use IdentityTheft.gov. If money or a payment account is affected, contact the bank, card issuer, or payment provider through its official contact route.

What can wait

You do not need to identify who created the item, complete a full investigation, close the account, reinstall every device, or rotate credentials unrelated to the affected access right now. First contain the unfamiliar access, secure the main account, and preserve the basic details.

Important reassurance

An unfamiliar entry does not by itself prove that all of your account data was stolen. Legitimate integrations can appear under unexpected technical or developer names, but treating the item as untrusted until it is verified can help limit further access.

Scope note

This guide covers immediate containment and account-security steps only. Investigation, system recovery, notification decisions, or changes to a business environment may require help from the service provider, an account administrator, or a qualified cybersecurity professional.

Important note

This is general information, not cybersecurity, legal, financial, or other professional advice. Available controls and the effects of revoking a connection vary by provider, account type, and organization.

Additional Resources

About this guide

This guide was produced and is maintained by PanicStation.org using its published editorial process. Official and specialist sources are checked where relevant, and AI-assisted tools may be used for drafting, organisation, and consistency checks. The site operator remains responsible for publication, revision, and removal decisions.

Support us