Data on 700M LinkedIn users for sale on a forum, with info like names, addresses, inferred salary; LinkedIn says it seems some of the data is from other sources
Madeleine Hodson / PrivacySharks :
Context & Ripple Effects
The listing follows an earlier sale offer involving scraped LinkedIn profile data, which LinkedIn said consisted of publicly viewable information. The new dataset is more consequential because it is presented with attributes such as addresses and inferred salary, while LinkedIn says at least some material appears to have been assembled from outside sources.
The distinction between a platform scrape and a compiled dossier matters: public professional-profile data can be combined with third-party information into a more actionable commercial or fraud-targeting dataset without all of it originating at LinkedIn.
First-order effects
- LinkedIn must respond to a sale offer tied to 700M of its users while clarifying which fields originated on its service and which came from other sources.
- Affected members face a broader exposure than a single-profile scrape when profile identifiers are offered alongside addresses and inferred compensation data.
Second-order effects
- Data brokers and scrapers gain an incentive to enrich publicly visible professional data with external records, making source-by-source attribution harder for platforms and users.
- LinkedIn's trust burden shifts from protecting account credentials, as in the earlier 2012 credential dataset sale, to limiting the reuse and enrichment of information visible across the web.
Third-order effects
- The episode points to a widening public-data permission boundary: information that is individually visible can become materially more sensitive when compiled, scored, and sold at population scale.
- If profile-data sales continue to rely on mixed sources, platform enforcement will increasingly turn on provenance and downstream use rather than a simple question of whether a field was public.
The trend: Professional-network data is becoming a feedstock for enriched identity datasets, sharpening the divide between public visibility and permission to aggregate and resell.