In 2021, data from 700 million LinkedIn users—93% of its user base—was scraped and sold, including email addresses, phone numbers, and geolocation. While LinkedIn argued no system breach occurred, the data aggregated from public profiles enabled targeted phishing for 95% of entries with full names and workplaces. This affected 25% more users than the 2021 Facebook leak of 533 million, and the scraped dataset was far richer for social engineering than the MOVEit breach’s purely exfiltrated files, which lacked direct contact details. The incident cost LinkedIn an estimated $1.2 million in remediation and legal fees.

Comments on "LinkedIn (2021)"
Create a free account or sign in to join the discussion.
Sign in to join the conversation