LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › LinkedIn Scraped and Faked Data (2023) Data Breach (2023)

HIGH severityConfirmedHow we verify

LinkedIn Scraped and Faked Data (2023) Data Breach (2023): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·November 4, 2023

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

LinkedIn Scraped and Faked Data (2023) Data Breach (2023)

Reported November 4, 2023. Approximately 19.8M people affected.

HIGH
Severity
19.8M
People affected
7
Data types exposed
November 4, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The LinkedIn Scraped and Faked Data (2023) Data Breach (2023) (reported November 4, 2023) exposed Email addresses, Genders, Geographic locations and Job titles belonging to roughly 19.8M people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the LinkedIn Scraped and Faked Data (2023) Data Breach (2023) breach?
19.8M accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In November 2023, roughly 19.8 million people learned that records tied to their LinkedIn presence had appeared in a public dump. The material mixed real profile details scraped from the platform with email addresses that had been built from people’s names rather than taken from LinkedIn itself. For anyone whose professional identity lives on the site, the practical stakes are straightforward: names, job titles, skills, locations and contact patterns can be reused for targeted phishing, impersonation or further scraping.

Public reporting dated 4 November 2023 confirmed the scale and the mixed nature of the data. Exact technical methods and any internal LinkedIn findings remain limited in the open record, so the clearest picture comes from what was actually posted and later examined.

Inside the incident

On or around 4 November 2023 a post appeared on a popular hacking forum claiming that millions of LinkedIn records had been scraped and leaked. Subsequent review showed the set contained approximately 19.8 million records. Investigators determined that the dump combined two kinds of information: legitimate data obtained by scraping publicly visible LinkedIn profiles, and email addresses that had been constructed from the names of the people involved rather than extracted from LinkedIn systems.

No evidence in the public summary indicates that LinkedIn’s internal databases were breached. The incident is therefore characterised as large-scale scraping plus fabrication of email addresses, not as a compromise of LinkedIn’s authentication or storage infrastructure. Timing beyond the November 2023 reporting date, the precise scraping technique, and any attribution to a named group are undisclosed.

How a breach like this happens

Incidents of this type typically begin with automated collection of information that users or platforms make visible. Scrapers request profile pages at high volume, parse the returned HTML or API responses, and store names, headlines, locations, skills and other fields. Because many professional networks display these details to logged-in users or even to the public, the barrier to collection can be low once rate limits or anti-bot controls are bypassed or ignored.

Separately, attackers or data brokers often generate email addresses by combining first and last names with common domain patterns. When these constructed addresses are later merged with scraped profile data, the resulting file looks more complete and more useful for spam or social-engineering campaigns. The finished package is then offered or posted on forums. No specific threat group is named in connection with the 2023 LinkedIn matter, and none should be assumed.

LinkedIn and its sector

LinkedIn is a professional networking platform used by individuals and organisations to publish career histories, skills, job titles and contact preferences. In the broader sector of social and professional networks, such services hold large volumes of identity and employment data that users deliberately make visible in order to be found by recruiters, colleagues and clients. That visibility is the product’s core value; it is also what makes bulk scraping feasible.

A large exposure of profile-derived records matters because the same information that helps legitimate networking can be repurposed to craft convincing phishing messages, to map organisational structures, or to enrich other stolen data sets. Even when the platform’s own servers are not compromised, the aggregation of public and semi-public fields at scale creates a ready-made targeting list.

The information in question

The records associated with this incident are reported to have included the following categories:

These fields match what is commonly visible on professional networking profiles. Because part of the email data was fabricated, not every address in the set necessarily belongs to the named individual or was ever stored by LinkedIn. The exact proportion of real versus constructed emails and the full raw contents of every record remain unconfirmed beyond the categories listed above.

The real-world impact

For affected individuals the main risks are secondary misuse rather than direct account takeover of LinkedIn. A name, job title, location and plausible email address are sufficient raw material for spear-phishing, fake job offers, or credential-stuffing attempts against other services where the same person re-uses passwords. Recruiters and colleagues may also receive impersonation messages that appear to come from a known contact.

For LinkedIn the episode underscores the persistent tension between open professional visibility and bulk data collection. Even without a confirmed intrusion into company systems, the circulation of 19.8 million enriched records can erode user trust and invite regulatory or contractual scrutiny over how public profile data is protected from industrial-scale scraping. No financial loss figures or formal regulatory findings are included in the available facts.

Were you affected?

If you maintained a LinkedIn profile before November 2023, treat the possibility of inclusion as real. Practical first steps include enabling multi-factor authentication on LinkedIn and on any email accounts that share your name, reviewing recent login activity, and treating unsolicited messages that reference your job title or skills with extra caution. Consider placing fraud alerts with credit bureaus if you see signs of identity misuse. You can also run a free exposure scan of your email address to check whether it has appeared in known breach data sets. Public detail on this specific incident does not extend to an official notification list, so personal verification remains the most direct way to assess exposure.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyLinkedIn security record
65/100
DoxxScan™ · Moderate doxx risk
D 54Poor record

2 reported incidents on record.

See LinkedIn’s full breach history →
RelatedMore incidents at LinkedIn

More recent breaches

Aman Data Breach (2026)April 20, 20267-Eleven Data Breach (2026)April 8, 2026Association Nationale des Premiers Secours Data Breach (2026)January 30, 2026DemandScience by Pure Incubation Data Breach (2024)February 28, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the LinkedIn Scraped and Faked Data (2023) Data Breach (2023) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram