LinkedIn is once again at the forefront of the battle against illegal data scraping, this time filing a lawsuit against ProAPIs Inc. and its founder, Rehmat Alam . The platform accuses the company of violating its terms of service through the widespread fake accounts creation of .

According to the lawsuit filed in California court, ProAPIs allegedly used over a million fake profiles to perform automated scraping of public user information, in flagrant violation of LinkedIn's Terms of Service (ToS)
A network of bots behind the data collection
The case concerns the automated extraction of profile data — names, jobs, companies, skills and other public data — which was then exploited commercially. This phenomenon is not new, but the scope of ProAPIs' activity makes it unprecedented.
The company, according to LinkedIn, provided access to the iScraper API, a tool advertised as a “real-time LinkedIn data retriever.” The service sold access to high request speeds — up to 150 requests per second — for as much as $15,000 per month.
See also: Huawei – Data Breach: Hacker says he is selling source code
This feature, LinkedIn notes, indicates data collection industrial-scale, which violates not only the platform's terms but also legal privacy principles.
From "leaks" to scraping: The distinction that matters
LinkedIn has been the subject of several data leaks in recent years, but most of them were not security breaches in the traditional sense — they scraping, the extraction of publicly available data by bots or scripts.
LinkedIn, which is owned by Microsoft and now has over 1 billion members, highlights the difference: “None of our infrastructure was breached — the information was collected without authorization, which remains illegal and harmful to our members.”

Strengthening measures against fake profiles
The company has stepped up its defenses against so-called scrapers. In 2022, LinkedIn introduced three new mechanisms for detecting and blocking fake accounts, combining machine learning, behavioral analysis , and connection pattern detection.
According to Sarah Wight, the company's Vice President of Legal Affairs, ProAPIs created "millions of fake accounts in waves" in order to continue collecting data even after previous ones were blocked.
See also: Data breach at Doctors Imaging Group
"We continue to invest in technologies and teams that stop unauthorized data collection," said , adding that LinkedIn will not hesitate to take legal action when its members' personal data is threatened.
LinkedIn is scaling up its legal strategy
The new lawsuit is not an isolated incident. In recent years, LinkedIn has taken legal action against dozens of scrapers, including ProxyCurl, which it forced to cease operations after a multi-year legal battle.
In the current case, the platform requests:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Permanent injunction prohibiting ProAPIs and its partners from collecting data from LinkedIn.
- Delete all data that has already been collected.
- Payment of compensation and legal fees.
Additionally, Rehmat Alam is accused of using invalid credit cards to sign up for LinkedIn Premium accounts without paying, which may also result in criminal consequences.
ProAPIs' response and the silence that reinforces the questions
ProAPIs has not yet officially responded to requests for comment. The service's status page shows that the iScraper API is still up and running, despite some minor outages over the past 24 hours.
See also: Abuse of PsExec to Execute Malicious Code
Cybersecurity market analysts estimate that ProAPIs is likely trying to move its activity outside the US in order to avoid legal pressure — a phenomenon often observed with scraping companies.
Scraping: Between legality and ethics
Collecting public data online remains a gray area in the legal landscape. US law allows scraping public websites in some cases, as long as technical barriers are not circumvented. However, creating fake accounts and using bots to mass extract data are considered violations of terms of service and can lead to civil or criminal prosecution.
Microsoft itself has emphasized that such practices "threaten the integrity of the platform and user trust."

The future of data protection on LinkedIn
The ProAPIs case comes at a time when artificial intelligence is increasing the demand for large datasets of profiles, biographies, and professional relationships — a “digital gold” that many are attempting to collect uncontrollably.
The LinkedIn battle shows that platforms are no longer content with passive defense. They are moving forward with aggressive legal moves, seeking to draw clear boundaries between research access and data exploitation.
See also: Hackers exploit AWS X-Ray service
As a company spokesperson stated, “Trust is the foundation of LinkedIn — and we will not allow it to be eroded by bots or businesses that consider our members’ personal data a commodity.”
A court case with implications beyond LinkedIn
The outcome of this case could be a foregone conclusion for how social media platforms protect their data in the future. If LinkedIn wins, it will strengthen the position of companies that treat scraping as a violation of intellectual property rights , not a simple access technique.
In a world where information is the new currency, the LinkedIn–ProAPIs case is not just about the legal side — it’s about who controls the data and who benefits from it.
Source: www.bleepingcomputer.com
