Just days after Facebook's massive data leak, a similar incident has occurred, this time at LinkedIn. A file containing data allegedly stolen from the profiles of 500 million LinkedIn users has been put up for sale on a popular hacking forum. The hacker who managed to extract it from the Microsoft-owned social network has already published two million user records as proof that the data is real.
Read also: Facebook leak search: See if your account was leaked here!

The leaked files contain information about the users whose data was allegedly stolen – including full names, email addresses, phone numbers, workplace information and more.
The two million user records that have been posted as proof that this is real data can be viewed on the forum for $2. The 500 million accounts are being offered for a four-figure sum, payable in Bitcoin. At this time, it is unclear whether the malicious actor is selling updated LinkedIn profiles or whether the data was obtained/gathered from a previous breach suffered by LinkedIn or other companies.

See also: LinkedIn: Half of users do not update their profile
LinkedIn has not yet commented on the matter.
What was leaked?
According to Security Affairs, the leaked data includes the following:
- IDs
- Full names
- Email addresses
- Phone numbers
- Sex
- Links with LinkedIn profiles
- Links to other social media profiles
- Job titles and other job-related data
Suggestion: Brazil: First in phishing attacks. Which countries follow?

What is the impact of the leak?
Data from the leaked files can be used by threat actors against LinkedIn users for various malicious activities, such as the following:
- Carrying out targeted phishing attacks.
- Spamming to 500 million emails and phone numbers.
- Brute-forcing of passwords for LinkedIn profiles and email addresses.
The leaked files appear to contain only LinkedIn profile information – no particularly sensitive data like credit card details or legal documents have been identified in the sample posted by the hacker. This means that even an email address could be enough for a cybercriminal to cause significant damage.

Additionally, malicious actors can combine the information contained in the leaked files with other data breaches to create detailed profiles of their potential victims. With this information in their hands, they can carry out much more convincing phishing and social engineering attacks, or even commit identity theft against the people whose information has been exposed on the hacking forum.
If you suspect that your LinkedIn profile data has been stolen by malicious actors, it is recommended that you do the following::
- Be especially vigilant for any suspicious messages on LinkedIn and connection requests from strangers.
- Change the passwords for your LinkedIn and email accounts.
- Consider using a password manager to create strong passwords and store them securely.
- Enable two-factor authentication (2FA) on all your online accounts.
