Report: hackers scraped data of 500M LinkedIn users and posted it for sale online; LinkedIn confirms the dataset includes publicly viewable info from its site
- Personal data from 500 million LinkedIn users has been scraped and is reportedly for sale on a hacking forum.
InsiderKatie Canales
Context & Ripple Effects
LinkedIn had previously been tied to a sale of email-and-password records from its 2012 breach, making the distinction in this case consequential: the company says the newly marketed material consists of information visible on member profiles rather than stolen credentials.
The incident also fits a recurring market for aggregated LinkedIn records. Later coverage of a purported 700M-user dataset showed how sellers can combine LinkedIn-derived material with information from other sources, complicating both attribution and user protection.
First-order effects
Forum buyers gain a ready-made collection of LinkedIn profile information, reducing the effort required to gather data that was individually publicly viewable.
LinkedIn must explain the boundary between a compromise of its systems and large-scale collection of public profiles while responding to affected members' privacy concerns.
Second-order effects
The earlier credential-record sale and this profile-data offering create two different exposure narratives for LinkedIn users, raising the value of clear disclosure about what data was obtained and from where.
Repeated listings make aggregated public-profile data a sellable product rather than merely a byproduct of web access, increasing pressure on LinkedIn to deter bulk collection at the account level.
Third-order effects
If the pattern persists, professional networks will increasingly treat public-profile access as a data-rights and anti-automation problem, not solely a conventional breach-response problem; LinkedIn's later allegations over fake accounts used for scraping illustrate that shift.
The durable fault line is whether data being publicly viewable permits industrial-scale extraction and resale, a boundary that will shape platform controls and enforcement.
The trend: Professional platforms are moving toward tighter control of bulk access as publicly visible member data becomes a commercial scraping target.
Connecting digital dots across the web “Members trust LinkedIn with their data.” We “have determined that it is actually an aggregation of data from a number of websites and companies.” https://news.linkedin.com/... https://twitter.com/...
After the discovery of the data leak that affected 533 million Facebook users, privacy protection company @surfshark has examined 2,837,793,637 data points and prepared an in-depth analysis to illustrate the scope of the breach. Have a read. It's BAD https://surfshark.com/... htt…
Based on the samples, they appear to contain a variety of from LinkedIn profiles, including: LinkedIn IDs Full names Email addresses Phone numbers Genders Links to LinkedIn profiles Links to other social media profiles Professional titles https://cybernews.com/...
We see reports that the data was ‘scraped’ https://www.techrepublic.com/ ... or ‘leaked’ https://www.theverge.com/... We should perhaps find better ways to describe poor design & unlawful processing data
Facebook's negligence at its best. I reported this issue to them in 2017. They didn't ‘find’ it in 2019 - that's only when they decided to do something about it, after 2 years. https://medium.com/... https://twitter.com/... https://twitter.com/...
Data scraped from 500 million LinkedIn users found for sale online IDs, names, email addresses and more personal details are part of the massive database of stolen data, which could be used to launch additional attacks on LinkedIn and its users. https://www.techrepublic.com/ ... …
Did LinkedIn already react and say something like “Scraping data using features meant to help people violates our terms”? 😜 Among the leaked data of 500M users: name, email, phone number, gender and work-related data. https://cybernews.com/... #infosec
@RaibleChris @Techmeme @lilyhnewman You might regret this tweet in a few days when that “500 million LinkedIn profiles” dataset is confirmed Especially since LinkedIn has the shadiest and misleading PR dept I met in my reporter life and they'll add words to the English dictionary…
Oh great, another one. 500m records with names, email addresses and phone numbers. It's unclear whether it's about “up-to-date LinkedIn profiles, or if the data has been taken or aggregated from a previous breach suffered by LinkedIn or other companies”: https://www.techrepublic.…
There's rather a lot of leaked data floating around at the moment: “Scraped data of 500 million LinkedIn users being sold online, 2 million records leaked as proof” https://cybernews.com/...