DigitalMANIPULATIVE

Friend Spam

What it is

Asking for access to a person's contacts or social accounts under a benign pretext — “see which friends are already here” — and then messaging those contacts in the person's name, often repeatedly, without their knowledge.

How it works

Brignull named friend spam in his original taxonomy: the product requests your address book or social permissions to help you find friends, then uses them to send invitations that appear to come from you. Two deceptions are stacked. The first is at the permission step, where the frame is discovery (“who do you know?”) and the consequence — outbound messages under your name — is omitted or buried in a pre-checked box. The second is at the recipient's end: an invitation from a known name carries the trust, reciprocity, and curiosity that a message from a company would not, so open and sign-up rates are far higher, which is exactly why the platform borrows the name. The recipient's address has also been collected without their consent, which in the EU and UK is a data-protection breach in its own right. LinkedIn's “Add Connections” feature, which sent an initial invitation and two reminders to imported contacts, produced a class action settled for $13 million in 2015; Path uploaded users' address books without asking and settled with the FTC in 2013. The mechanism survives in games that unlock rewards for “inviting five friends” and apps that ask for contacts before showing anything at all.

Real-world examples

  • Perkins v. LinkedIn: LinkedIn's “Add Connections” flow harvested users' e-mail contacts and sent invitations plus two reminder e-mails in the user's name; the company settled the class action for $13 million in 2015 and changed the flow.
  • Path, a social app, uploaded users' entire iPhone address books without consent in 2012 and settled FTC charges in 2013, paying an $800,000 penalty that also covered children's data.
  • Facebook confirmed in 2019 that it had, since 2016, uploaded the e-mail contacts of about 1.5 million new users without their consent during an e-mail “verification” step.
  • Mobile games and shopping apps that gate a reward or a discount behind “invite 5 friends”, turning the user into a distribution channel and the friends into targets of messages they did not ask for.

Ethical guidelines

  • Say exactly what will happen with contacts before asking for them, in the permission prompt itself: who will be messaged, how many times, in whose name.
  • Never send anything in a user's name that the user has not composed or explicitly approved, and never send reminders to non-users.
  • Contacts of a user are personal data of third parties who gave nothing; collect the minimum, keep it briefly, and honor deletion.
  • A reward for invitations is a payment for endorsements; treat it as one and do not let it turn a user's friendships into a quota.

How to defend against it

  • Deny contact access at sign-up by default; a service that needs your address book to function will say so, and one that only “helps you find friends” can wait.
  • If you did grant it, revoke it in the phone settings, then check the platform's “sent invitations” or “imported contacts” page and delete what it stored.
  • Tell friends who receive an invitation in your name that you did not send it, so they do not act on your apparent endorsement; the correction is the only thing that stops the loop.
  • When you receive one, treat it as a message from the company, not from the friend: verify with the friend before joining, and mark it as spam.
  • Report unlawful contact harvesting to your data-protection authority (EU/UK) or the FTC (US); LinkedIn and Path show that these complaints succeed.

From the Defense Playbook

Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.

References

  1. Brignull, H. (2023). Deceptive Patterns: Exposing the Tricks Tech Companies Use to Control You. Testimonium Ltd
    The definition of friend spam in the dark-patterns taxonomy and the LinkedIn case.
  2. United States District Court for the Northern District of California (2015). Perkins v. LinkedIn Corporation, Case No. 13-cv-04303 — class action settlement. N.D. Cal., settlement announced October 2015
    The $13 million settlement over the Add Connections feature and its reminder e-mails sent in users' names.
  3. Federal Trade Commission (2013). United States v. Path, Inc. — consent decree and civil penalty. FTC press release, February 2013
    The $800,000 settlement over Path's collection of users' address books without consent.
Last reviewed
Suggest a correction

Detect Friend Spam in any text

Paste any message, email, or article into our free Manipulation Detector to see if Friend Spam or other techniques are being used on you.

Related Articles