Map Every App Linked to a Breached Login: Exports, Connected Accounts, and Silent Sessions

When a login is exposed in a breach, the danger extends far beyond that single password. Modern accounts connect to dozens of apps, devices, and background services through tokens that can stay active even after you change your password. This guide shows you how to map every app linked to the breached login, export and review your data, and shut down hidden sessions so attackers lose their foothold.

Why mapping connected apps matters after a breach

Attackers rarely stop at one account. They try your exposed email and password set across other services, scrape your files and messages, and use token-based connections to hop into additional apps without re-entering a password. If you only reset the password, you might still have:

  • OAuth authorizations that let third-party apps access your account data with long-lived tokens.
  • Connected accounts (sign in with Google, Apple, Microsoft, Facebook, X, GitHub, etc.) that bypass normal passwords.
  • Persistent device sessions on phones, browsers, consoles, and smart TVs that stay signed in until revoked.
  • API keys and app passwords made for legacy mail clients, calendar sync, or scripts that ignore new passwords.
  • Forwarding rules and webhooks quietly exfiltrating your emails, files, or messages.

Immediate safety checklist (do this first)

Before you start mapping, stop active misuse and lock down the breached account:

  1. Turn on strongest available MFA (preferably passkeys or an authenticator app; avoid SMS if possible).
  2. Change the password to a unique, long passphrase you have never used elsewhere.
  3. Invalidate all sessions using the account’s “Sign out of all devices” or “Log out everywhere” feature.
  4. Review recent activity for logins, device adds, forwarding rules, password resets, and security emails.
  5. Check recovery channels: confirm the recovery email and phone belong to you and remove unknown devices.

The three-part map: exports, connected accounts, and silent sessions

Your goal is to produce a complete picture of what’s linked to the breached login. Work through all three layers.

1) Export your data to see the full footprint

Data exports reveal connected apps, devices, and configuration that the web interface may hide. Look for “Download your data,” “Export,” or “Takeout.”

  • Email services: Export mailbox metadata, filters, forwarding, IMAP/POP and app passwords, OAuth tokens.
  • Cloud storage: Export sharing links, external collaborators, third-party app integrations, and webhooks.
  • Social networks: Export sessions, login history, linked apps, authorized advertisers, connected identities.
  • Productivity suites: Export audit logs, drive shares, calendar delegates, add-ins, and integration logs.

After downloading, scan the archive for:

  • Authorized apps and tokens (CSV, JSON, or HTML lists).
  • Active device lists and sign-in timelines.
  • Rules and automations such as email forwarding, filters, webhooks, or scripts.
  • Shared links (especially “anyone with the link” access).

2) Enumerate connected accounts and app permissions

Visit your account’s security or privacy dashboard to locate and remove third-party access. Common locations:

  • Google: Security > Third-party access, Your devices, App passwords, Less secure access (if present), Account activity.
  • Apple ID: Sign-In & Security > Sign in with Apple, Two-Factor Authentication, Devices, App-specific passwords.
  • Microsoft: Privacy/Security dashboards > Apps & Services, Devices, App passwords (Outlook/Exchange), Recent activity.
  • Facebook/Meta: Settings > Security and login > Where you’re logged in, Apps and websites, Business integrations.
  • Twitter/X, GitHub, Dropbox, Box, Slack: Look for “Connected apps,” “Authorized OAuth apps,” “Sessions,” and “Devices.”

For each connected app or service, document:

  • App name and publisher
  • Scopes/permissions (read contacts, send email, manage files, post on your behalf)
  • Token activity (last used date/time)
  • Linked identities (Sign in with Google/Apple/Microsoft/Facebook, etc.)

Revoke any app you don’t recognize, no longer use, or that has broad access such as “read, compose, send, and permanently delete” for email or “read and write to all files” in cloud storage.

3) Close silent sessions and backdoors

Silent sessions are access paths that remain active even after you change your password. Target these specifically:

  • App passwords (per-app credentials for email/calendar/legacy devices).
  • Remembered browsers and devices with “Don’t ask for codes on this device.”
  • Long-lived OAuth tokens issued to third-party apps and extensions.
  • IMAP/POP and SMTP connections for email accounts.
  • Forwarding rules and auto-bcc that copy email to attackers.
  • Sync links and shared folders in cloud storage with public or external access.
  • API keys and webhooks in developer or automation settings.

Revoke or rotate each of these. If rotation is not available, delete and recreate only what you still need.

Detailed walkthroughs for popular ecosystems

Use the steps below as a pattern. Interfaces change, but the principles are the same: enumerate, export, revoke, rotate, and resecure.

Google account

  1. Export: Use Google Takeout to include Security logs, Drive permissions, Contacts, Calendar, and OAuth app lists.
  2. Revoke access: Security > Third-party access > Remove unknown or high-permission apps.
  3. End sessions: Security > Your devices > Sign out of all unfamiliar devices; review “Recent security events.”
  4. App passwords: Security > 2-Step Verification > App passwords > Delete all; recreate only what you need.
  5. Gmail rules: Settings > See all settings > Filters and Forwarding > Remove unknown filters and forwarding addresses.
  6. Drive sharing: Audit “Shared with me” and “Shared by me”; remove public links and external collaborators you don’t trust.
  7. Re-secure recovery: Confirm recovery email, phone, and backup codes; regenerate if needed.

Apple ID / iCloud

  1. Export: Request a copy of your data via privacy.apple.com where available.
  2. Devices: Settings > Your Name > Review devices; remove unknown devices and browsers.
  3. Sign in with Apple: Review apps using your Apple ID; stop sharing and hide email if not needed.
  4. App-specific passwords: Delete all; recreate only for trusted mail or calendar clients.
  5. Keychain and Messages: Ensure only your devices have access; remove old or lost devices.

Microsoft account

  1. Export: Check Privacy dashboard for activity logs.
  2. Apps & Services: Remove suspicious authorizations; review “Recent activity.”
  3. Devices: Sign out unknown Windows, Xbox, or Office activations.
  4. Mail (Outlook/Exchange): Disable unknown forwarding rules and inbox rules; remove IMAP/POP access you don’t use.
  5. App passwords: Delete and recreate only as necessary.

Social platforms (Meta, X, LinkedIn, Reddit, GitHub)

  • Authorized apps: Remove browser extensions and third-party tools you don’t recognize.
  • Sessions: Log out everywhere; kill active tokens from all devices.
  • Posting/DM permissions: Revoke any app that can post or read DMs/messages.
  • Developer keys: Regenerate API tokens or personal access tokens if present.

Build your breach map: a simple worksheet

A lightweight worksheet helps you track what you find and prove you closed the gaps. Create columns for:

  • Service (e.g., Google, Dropbox, Outlook)
  • Access type (OAuth app, session, device, app password, API key, forwarding rule, shared link)
  • Scope (read-only, read/write, send-as, full control)
  • Last used
  • Action (revoked, rotated, deleted, kept)
  • Date/initials

Prioritize high-scope items first: send-as email, full file access, messaging read/write, account settings control, and payment scopes.

Kill common backdoors attackers love

Even experienced users miss these. Check them explicitly:

  • Email forwarding: Any rule that forwards or redirects to an unknown address.
  • Catch-all filters: Filters that archive or mark important alerts as read to hide notifications.
  • Calendar sharing: Public calendars exposing travel or meeting links.
  • Cloud storage links: “Anyone with the link” shares containing IDs, invoices, or scans.
  • Security-bypass devices: Trusted devices that skip MFA prompts.
  • Authenticator transfers: Seed exports or device migrations that duplicate your MFA codes.

Rotate what matters: passwords, tokens, and keys

After you revoke access, rotate any credentials that could be reused:

  • Primary password: Use a unique passphrase managed by a password manager.
  • Recovery methods: Reset backup codes; confirm only your phone/email are listed.
  • App passwords/API keys: Regenerate and store securely; delete stale ones.
  • Security questions: Replace with random answers stored in your manager.
  • Payment authorization tokens: Review saved cards and subscriptions; remove those you don’t recognize.

Harden the account so this doesn’t happen again

Once the immediate risk is gone, upgrade default security:

  • Enable passkeys or hardware keys where supported to resist phishing and credential stuffing.
  • Reduce app permissions: Grant the minimum necessary scopes; prefer read-only where possible.
  • Use separate identities for high-risk tools (e.g., a dedicated email for financial accounts).
  • Quarterly access review: Calendar a recurring check of connected apps, sessions, and rules.
  • Browser hygiene: Remove unused extensions; update regularly; isolate logins with profiles/containers.

What to monitor in the days and weeks after

Breaches can lead to identity misuse weeks later. Keep watch for:

  • Unexpected MFA prompts or new device approvals.
  • Password reset emails you did not request.
  • New-app authorization prompts appearing on your phone.
  • Unusual email or DMs sent from your accounts.
  • Financial alerts: new credit inquiries, accounts, or address changes.

If the breach included personal details like SSN or date of birth, consider ongoing monitoring for financial identity misuse. A consolidated privacy and credit monitoring resource can help you track changes, set alerts, and detect new-account fraud. If you need that support, see SmartCredit for privacy, credit monitoring, and identity protection.

Fast-reference: where common settings live

  • Sessions/Devices: Security or Login Activity.
  • Third-party apps/OAuth: Security, Privacy, or Connected Apps.
  • App passwords: 2FA/MFA settings.
  • Email rules/forwarding: Mail settings > Filters/Forwarding.
  • Shared links: Files > Shared or Link settings.
  • API keys/Webhooks: Developer or Integrations.

FAQ

Is changing my password enough after a breach?

No. Many apps, devices, and tokens stay signed in until you explicitly revoke them. You must end sessions and remove connected apps.

Should I delete every connected app?

Remove anything you don’t recognize or no longer use. For apps you need, reauthorize them after you’ve secured the account so they receive fresh, safer tokens.

How do I know if an attacker set up forwarding rules?

Check your email settings for “Forwarding” and “Filters/Rules.” Remove any that you didn’t create and that send or redirect messages externally.

What if a service doesn’t show token last-used times?

Export your data to look for logs, and when in doubt, revoke and recreate access. Prefer services that provide clear audit trails.

What’s the safest MFA?

Passkeys or hardware security keys provide the strongest protection against phishing. Authenticator apps are next best; SMS is better than nothing but more vulnerable.

Conclusion

After a breach, your real risk isn’t just a stolen password—it’s the invisible web of apps, tokens, and sessions that login enables. By exporting your data, listing every connected account, and revoking silent sessions, you cut off the attacker’s easy paths and regain control. Finish by rotating sensitive credentials, tightening MFA, and scheduling regular access reviews. With a clear map and a repeatable process, you transform a chaotic breach response into a precise cleanup that protects your privacy going forward.

Good to Know

After a breach, changing your password is not enough. Many accounts stay signed in through long-lived tokens and device sessions that ignore new passwords until you explicitly revoke them.