LinkedIn Scraped and Faked Data (2023) Data Breach (2023): What Was Exposed & What To Do
SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.
The LinkedIn Scraped and Faked Data (2023) Data Breach (2023) (reported November 4, 2023) exposed Email addresses, Genders, Geographic locations and Job titles belonging to roughly 19.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In November 2023, roughly 19.8 million people learned that records tied to their LinkedIn presence had appeared in a public dump. The material mixed real profile details scraped from the platform with email addresses that had been built from people’s names rather than taken from LinkedIn itself. For anyone whose professional identity lives on the site, the practical stakes are straightforward: names, job titles, skills, locations and contact patterns can be reused for targeted phishing, impersonation or further scraping.
Public reporting dated 4 November 2023 confirmed the scale and the mixed nature of the data. Exact technical methods and any internal LinkedIn findings remain limited in the open record, so the clearest picture comes from what was actually posted and later examined.
Inside the incident
On or around 4 November 2023 a post appeared on a popular hacking forum claiming that millions of LinkedIn records had been scraped and leaked. Subsequent review showed the set contained approximately 19.8 million records. Investigators determined that the dump combined two kinds of information: legitimate data obtained by scraping publicly visible LinkedIn profiles, and email addresses that had been constructed from the names of the people involved rather than extracted from LinkedIn systems.
No evidence in the public summary indicates that LinkedIn’s internal databases were breached. The incident is therefore characterised as large-scale scraping plus fabrication of email addresses, not as a compromise of LinkedIn’s authentication or storage infrastructure. Timing beyond the November 2023 reporting date, the precise scraping technique, and any attribution to a named group are undisclosed.
How a breach like this happens
Incidents of this type typically begin with automated collection of information that users or platforms make visible. Scrapers request profile pages at high volume, parse the returned HTML or API responses, and store names, headlines, locations, skills and other fields. Because many professional networks display these details to logged-in users or even to the public, the barrier to collection can be low once rate limits or anti-bot controls are bypassed or ignored.
Separately, attackers or data brokers often generate email addresses by combining first and last names with common domain patterns. When these constructed addresses are later merged with scraped profile data, the resulting file looks more complete and more useful for spam or social-engineering campaigns. The finished package is then offered or posted on forums. No specific threat group is named in connection with the 2023 LinkedIn matter, and none should be assumed.
LinkedIn and its sector
LinkedIn is a professional networking platform used by individuals and organisations to publish career histories, skills, job titles and contact preferences. In the broader sector of social and professional networks, such services hold large volumes of identity and employment data that users deliberately make visible in order to be found by recruiters, colleagues and clients. That visibility is the product’s core value; it is also what makes bulk scraping feasible.
A large exposure of profile-derived records matters because the same information that helps legitimate networking can be repurposed to craft convincing phishing messages, to map organisational structures, or to enrich other stolen data sets. Even when the platform’s own servers are not compromised, the aggregation of public and semi-public fields at scale creates a ready-made targeting list.
The information in question
The records associated with this incident are reported to have included the following categories:
- Email addresses (many of them constructed from names rather than taken from LinkedIn)
- Genders
- Geographic locations
- Job titles
- Names
- Professional skills
- Social media profiles
These fields match what is commonly visible on professional networking profiles. Because part of the email data was fabricated, not every address in the set necessarily belongs to the named individual or was ever stored by LinkedIn. The exact proportion of real versus constructed emails and the full raw contents of every record remain unconfirmed beyond the categories listed above.
The real-world impact
For affected individuals the main risks are secondary misuse rather than direct account takeover of LinkedIn. A name, job title, location and plausible email address are sufficient raw material for spear-phishing, fake job offers, or credential-stuffing attempts against other services where the same person re-uses passwords. Recruiters and colleagues may also receive impersonation messages that appear to come from a known contact.
For LinkedIn the episode underscores the persistent tension between open professional visibility and bulk data collection. Even without a confirmed intrusion into company systems, the circulation of 19.8 million enriched records can erode user trust and invite regulatory or contractual scrutiny over how public profile data is protected from industrial-scale scraping. No financial loss figures or formal regulatory findings are included in the available facts.
Were you affected?
If you maintained a LinkedIn profile before November 2023, treat the possibility of inclusion as real. Practical first steps include enabling multi-factor authentication on LinkedIn and on any email accounts that share your name, reviewing recent login activity, and treating unsolicited messages that reference your job title or skills with extra caution. Consider placing fraud alerts with credit bureaus if you see signs of identity misuse. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. Public detail on this specific incident does not extend to an official notification list, so personal verification remains the most direct way to assess exposure.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Aman Data Breach (2026)7-Eleven Data Breach (2026)Association Nationale des Premiers Secours Data Breach (2026)DemandScience by Pure Incubation Data Breach (2024)Latest breaches
Read GalaxyWarden’s full analysis of the LinkedIn Scraped and Faked Data (2023) Data Breach (2023) →
Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.