DigitalMANIPULATIVE
Friend Spam
What it is
Asking for access to a person's contacts or social accounts under a benign pretext — “see which friends are already here” — and then messaging those contacts in the person's name, often repeatedly, without their knowledge.
How it works
Real-world examples
- •Perkins v. LinkedIn: LinkedIn's “Add Connections” flow harvested users' e-mail contacts and sent invitations plus two reminder e-mails in the user's name; the company settled the class action for $13 million in 2015 and changed the flow.
- •Path, a social app, uploaded users' entire iPhone address books without consent in 2012 and settled FTC charges in 2013, paying an $800,000 penalty that also covered children's data.
- •Facebook confirmed in 2019 that it had, since 2016, uploaded the e-mail contacts of about 1.5 million new users without their consent during an e-mail “verification” step.
- •Mobile games and shopping apps that gate a reward or a discount behind “invite 5 friends”, turning the user into a distribution channel and the friends into targets of messages they did not ask for.
Ethical guidelines
- ●Say exactly what will happen with contacts before asking for them, in the permission prompt itself: who will be messaged, how many times, in whose name.
- ●Never send anything in a user's name that the user has not composed or explicitly approved, and never send reminders to non-users.
- ●Contacts of a user are personal data of third parties who gave nothing; collect the minimum, keep it briefly, and honor deletion.
- ●A reward for invitations is a payment for endorsements; treat it as one and do not let it turn a user's friendships into a quota.
How to defend against it
- ►Deny contact access at sign-up by default; a service that needs your address book to function will say so, and one that only “helps you find friends” can wait.
- ►If you did grant it, revoke it in the phone settings, then check the platform's “sent invitations” or “imported contacts” page and delete what it stored.
- ►Tell friends who receive an invitation in your name that you did not send it, so they do not act on your apparent endorsement; the correction is the only thing that stops the loop.
- ►When you receive one, treat it as a message from the company, not from the friend: verify with the friend before joining, and mark it as spam.
- ►Report unlawful contact harvesting to your data-protection authority (EU/UK) or the FTC (US); LinkedIn and Path show that these complaints succeed.
From the Defense Playbook
Every playbook entry states how strong its evidence is and when not to use it. Browse the full playbook.
References
- Brignull, H. (2023). Deceptive Patterns: Exposing the Tricks Tech Companies Use to Control You. Testimonium LtdThe definition of friend spam in the dark-patterns taxonomy and the LinkedIn case.
- United States District Court for the Northern District of California (2015). Perkins v. LinkedIn Corporation, Case No. 13-cv-04303 — class action settlement. N.D. Cal., settlement announced October 2015The $13 million settlement over the Add Connections feature and its reminder e-mails sent in users' names.
- Federal Trade Commission (2013). United States v. Path, Inc. — consent decree and civil penalty. FTC press release, February 2013The $800,000 settlement over Path's collection of users' address books without consent.
Last reviewed
Suggest a correctionRelated Articles
Dark Patterns in UX: How Apps Manipulate Your Behavior
Subscription traps, misleading interfaces, and engineered addiction. Understanding the persuasion techniques built into the apps you use every day.
7 min read
OSINT for Beginners: Open Source Intelligence Explained
Open Source Intelligence (OSINT) uses publicly available data to gather actionable insights. Here is a beginner-friendly guide to what OSINT is and how it is used.
10 min read