Detecting Unwanted Social Sign‑In Links Created With Your Email

“Sign in with Google,” “Continue with Apple,” “Log in with Facebook,” and similar buttons are convenient—and risky when someone else links them to your email. If a fraudster connects a social sign-in to an account in your name, they might bypass your password entirely and access services you use. This guide explains how these links work, how to detect ones you didn’t create, and the steps to remove them and secure your identity.

Why unwanted social sign-ins are a real risk

Social sign-ins rely on a technology called OAuth. Instead of creating a new password for each site, you authorize a trusted provider (like Google or Apple) to prove your identity to the site. It’s secure when you control both sides: your social account and the site you’re signing into. Problems start when:

  • A site account using your email exists, and someone links their social profile to it.
  • Your email was typo-squatted (e.g., missing a dot) and linked to a social login that can still be confused for yours by support teams.
  • A breached or forwarded email lets an attacker complete a confirmation step you never see.
  • You reuse passwords and an attacker adds a new, easier login path (social sign-in) to keep access even if you change the password later.

Because some services don’t notify you when a new login method is added, these links can persist unnoticed until there’s account misuse, purchases, or data exposure.

Quick signs your email may be linked to an unwanted social sign-in

  • Login surprises: A site suddenly lets you in with a social button you never set up.
  • Password confusion: You click “Forgot password,” but the site tells you to use Google/Apple/Facebook instead.
  • Odd emails: “You signed in with [Provider]” or “New login method added” emails you don’t recognize, including in Spam/Junk folders.
  • Security alerts: Your provider (Google, Apple, Microsoft, Facebook) shows recent authorizations to apps or sites you don’t use.
  • Billing or activity drift: New orders, changed settings, or unfamiliar devices showing up in account history.

How to audit your social accounts for unwanted app links

Start with the providers most commonly used for one-click sign-in. You’re checking which third-party sites and apps have access, when access was granted, and what data is shared.

Google

  1. Go to your Google Account security settings and open “Third-party apps with account access” or “Security & Privacy > Third-party access.”
  2. Review each app/site. Click into any you don’t recognize to see the access scope (basic profile, email, calendar, contacts, etc.).
  3. Remove access for anything you don’t use or don’t recognize. Note the app/site name so you can also check that account directly.
  4. Check “Recent security events” and “Devices” for unknown sign-ins or new app authorizations.

Apple (Sign in with Apple)

  1. On an iPhone/iPad: Settings > [your name] > Password & Security > Apps Using Your Apple ID.
  2. On the web (Apple ID account): Review “Sign in with Apple” and “Security” sections for connected apps.
  3. Remove any unfamiliar app/site. If you used Apple’s private relay email (Hide My Email), note the relay address so you can identify related messages.

Facebook

  1. Open Facebook Settings > Apps and Websites.
  2. Filter Active apps. Review permissions and the date added.
  3. Remove anything you don’t recognize. Consider turning off “Login with Facebook” for apps you no longer use.

Microsoft

  1. Visit your Microsoft account’s Privacy/Security dashboard and open “Apps and services you’ve given access.”
  2. Revoke access to unknown or unused apps.
  3. Check “Recent activity” for unfamiliar sign-ins or grant events.

Tip: After revoking access, change your password and enable two‑factor authentication (2FA) on the relevant provider to prevent reauthorization if your account was compromised.

How to check individual sites for linked social logins

Even if your provider shows no unfamiliar apps, a site may still be set up to accept a social login with your email. Audit high-value accounts first: shopping, travel, file storage, financial, communication, and subscription services.

  1. Open the site’s login page and click “Need help?” “Account settings,” or “Security.”
  2. Look for “Connected accounts,” “Linked logins,” “Social sign-in,” or “External authentication.”
  3. If you find a provider linked that you didn’t set up, remove or unlink it immediately.
  4. Change the site’s password and enable 2FA (preferably app-based codes or hardware keys).
  5. Check the account’s activity log, devices, and sessions. Sign out of all sessions if available.

What to do if you suspect someone added a social login to your account

  1. Secure your email first.
    • Change your email password to a strong, unique one.
    • Turn on 2FA for your email (authenticator app or hardware key). Email is often the recovery path—locking it down blocks attackers.
  2. Lock down the social provider used.
    • Change the provider account password and enable 2FA.
    • Revoke unknown devices and sessions. Remove unfamiliar recovery methods (backup emails/phones).
  3. Unlink the connection at the target site.
    • In account settings, remove the social login and set a new password.
    • If you’ve lost access, contact the site’s support and state: “An unauthorized social login was linked to my email. Please remove all external authentication methods and force a password reset.”
  4. Sweep for reuse.
    • Update passwords for any other sites where you used the same or similar password.
    • Use a password manager to create unique passwords going forward.
  5. Monitor for fallout.
    • Watch for password reset emails you didn’t request.
    • Review financial accounts and subscriptions tied to the compromised account.

Preventing unwanted social sign-ins going forward

  • Use unique passwords everywhere. Reuse is the main way attackers get in and then add new login methods.
  • Enable 2FA on your email, social providers, and high-value sites. App-based 2FA or hardware keys are stronger than SMS.
  • Limit social sign-in to a small number of low-risk sites, or avoid it entirely for financial, storage, and communications accounts.
  • Turn on login alerts. Many providers and sites can notify you about new devices, new sign-in methods, or first-time logins.
  • Review connected apps quarterly across Google, Apple, Facebook, and Microsoft.
  • Use email aliases wisely. For Apple, Hide My Email keeps your real address private; for Gmail, plus-addressing (name+site@gmail.com) helps track where a login originated.
  • Stop auto-forwarding of sensitive mailboxes. Forwarding can let attackers complete confirmations unseen.
  • Keep your recovery info tight. Remove old phone numbers and backup emails you no longer control.

How attackers add these links—and the clues they leave

Understanding common methods helps you spot issues faster:

  • Credential stuffing: An attacker signs into your account using reused credentials, then links their social login to create a backdoor. Clue: An unexpected “new login method added” email or a log entry in the account’s security history.
  • Email manipulation: If your email forwards to another inbox, attackers can confirm new links. Clue: Confirmation emails marked as read or filtered into obscure folders.
  • Support abuse: An attacker convinces support to link a social login for “account recovery.” Clue: Support messages you didn’t start, or profile details changed without your action.
  • Typos/variants: A look-alike email (like missing a dot in Gmail) gets associated to your identity at a site. Clue: You receive receipts or account summaries for services you never used.

How to document and escalate when needed

If money, health, or identity data is involved, collect evidence before changes disappear.

  • Take screenshots of linked logins, app access pages, device lists, and recent activity.
  • Save copies of emails showing new login methods or sign-ins.
  • Note dates, times, IP locations, and device names shown in security logs.
  • Contact the site’s security or support with clear language: “Unauthorized external authentication was added to my account on [date]. Please remove third-party sign-ins, invalidate sessions, and confirm by email.”
  • If financial accounts are affected, notify your bank/card issuer and set up transaction alerts.

When monitoring your financial identity helps

If an attacker can access services with your email—shopping, subscriptions, or travel—they may test stolen cards, open new lines of credit, or change billing. Continuous monitoring and fast alerts can reduce the damage window. Consider using a reputable service that brings together credit monitoring, identity alerts, and recovery support to help you spot unwanted activity early. For a practical option, see our overview of SmartCredit for privacy, credit monitoring, and identity protection.

Monthly checklist to catch unwanted links early

  • Google: Review Third‑party access, Recent security events, Devices.
  • Apple: Check Apps Using Your Apple ID and Hide My Email entries.
  • Facebook: Audit Active Apps and Websites.
  • Microsoft: Review Apps & Services and Recent activity.
  • Email: Search your inbox and spam for “new sign-in,” “new app,” “connected,” “authorized,” or “OAuth.”
  • Top sites: Open Security/Privacy pages, confirm only your intended login methods are present, and verify 2FA.

Frequently asked questions

Can someone link their Google to my account without my password?

They usually need some access—either your account on that site, your email, or a support loophole. But because some sites allow linking after a simple confirmation, an exposed or forwarded email can be enough. That’s why locking down email and using 2FA is critical.

If I remove a social login from my provider, does it break site access immediately?

Revoking access at the provider stops future sign-ins, but an existing session on the site may remain active. Sign out of all sessions at the site and change the site password to fully cut access.

Is social sign-in safe?

Yes, when used thoughtfully: secure the provider with strong 2FA and limit where you use it. The risk increases if your provider account or email is weak, or if you rely on social sign-in for high-value accounts.

What data do these sign-ins share?

Often your name and email; sometimes profile photo or contacts. Review scopes during authorization and revoke apps that request more than you’re comfortable sharing.

What if I can’t unlink the social login?

Contact the site’s support, reference account ownership proofs (billing info, ID verification if appropriate), and request removal of external authentication plus a forced password reset. Keep records of your request and follow up.

Conclusion

Unwanted social sign-ins let attackers slip past passwords—sometimes without obvious alerts. By regularly auditing connected apps in Google, Apple, Facebook, and Microsoft, checking each site’s linked logins, and tightening your passwords and 2FA, you can spot and remove rogue connections before they lead to financial loss or data exposure. Act quickly if you see signs of trouble: secure your email and provider accounts, unlink the access, and monitor for follow-on activity. A few monthly checks go a long way toward keeping your accounts—and identity—under your control.

Good to Know

Many sites don’t email you when a new social login link is added to your account. Regularly reviewing your connected apps and recent sign-ins in Google, Apple, Facebook, and Microsoft is one of the fastest ways to catch unwanted links early.