Hackers Sell Scraped Data of 500 Million LinkedIn Users Online
A massive dataset containing information from over 500 million LinkedIn users is currently being sold on a hacker forum. LinkedIn clarifies that this is not a traditional breach, but rather an aggregation of publicly scraped data from multiple sources.
Data from over 500 million LinkedIn users is currently being sold on an underground hacker forum, marking the second major data exposure incident revealed this week. The massive dataset contains publicly viewable information such as user IDs, full names, email addresses, phone numbers, and professional titles. Security researchers at CyberNews discover this aggregated data and verify its connection to LinkedIn accounts.
LinkedIn denies that hackers penetrate its internal databases, explaining instead that bad actors scrape this information from the platform's public-facing service. The company states that the data actually comes from an aggregation of multiple websites and companies, rather than a direct security breach of LinkedIn's systems. Despite this technicality, LinkedIn emphasizes that scraping member data violates its terms of service.
Although the leaked dataset does not include highly sensitive details like Social Security numbers or credit card information, it still poses significant risks to affected users. Hackers easily use the exposed email addresses and phone numbers to launch highly convincing phishing attacks against unsuspecting victims. Impacted individuals can check if their information is compromised by visiting data breach tracking services like Have I Been Pwned.