Breach report
Social MediaDetails On 700 Million LinkedIn Users For Sale On Notorious Hacking Forum
A seller on RaidForums offered data on roughly 700 million LinkedIn users in June 2021, combining scraped profile details with emails and phone numbers. LinkedIn insisted it was scraping, not a breach.
Reported by Forbes
Records exposed
700M
About 700 million user records
Scale vs. largest on file
- When
- 2021
- How they got in
- Mass scraping of public profiles combined with data from other sources
- Sector
- Social Media
In late June 2021, a user on the hacking marketplace RaidForums advertised a database said to contain information on about 700 million LinkedIn users, which at the time represented the vast majority of the network's members. To prove the data was real, the seller released a sample of one million records. Researchers who reviewed it found names, email addresses, phone numbers, physical addresses, geolocation data, profile URLs, job titles, employers and even inferred salary ranges.
The listing came just two months after a similar sale involving roughly 500 million LinkedIn profiles, and in the same season as large Facebook and Clubhouse scraping dumps. The seller claimed to have gathered the information by abusing LinkedIn's application programming interface. In the months that followed, the full collection, about 187 gigabytes of archives, spread for free through torrents and private Telegram channels.
LinkedIn rejected the idea that it had been breached. The company said its investigation found no private member data had been taken from its systems and that the dataset appeared to be an aggregation of information scraped from LinkedIn and other websites. It noted that scraping violated its terms of service. That position was complicated by the fact that many records included contact details, particularly email addresses and phone numbers, that are not normally visible on public LinkedIn profiles, suggesting enrichment from outside sources.
The incident fed into a long-running legal fight over scraping. LinkedIn had been battling analytics firm hiQ Labs in US courts over whether collecting public profile data amounted to unauthorized computer access, and an appeals court had sided with hiQ in 2019 before the Supreme Court sent the case back for reconsideration in 2021. European regulators, meanwhile, began examining whether large scrapes should be treated as personal-data breaches under GDPR.
For security teams, the practical consequence was clear even if the legal label was not. A dataset that maps names to employers, job titles and direct contact information is a ready-made targeting list for spear-phishing, business email compromise and fake recruiter scams. The episode showed that professional networks are especially valuable to attackers because they reveal organizational structure, and that employees should expect their public work details to be weaponized in social engineering.