With more than a billion professional users, LinkedIn, which is owned by Microsoft, has access to a vast array of personal information, including data that could reveal religious and political positions. What's not clear is how LinkedIn uses all that data.

A small European company, which sells a browser extension to leverage different aspects of LinkedIn data, is running a campaign, which it calls BrowserGate , accusing LinkedIn of “illegally searching your computer” and “conducting one of the largest corporate espionage operations in modern history.”
“Every time any of LinkedIn’s one billion users visits linkedin.com, hidden code searches their computer for installed software, collects the results, and transmits them to LinkedIn’s servers and third-party companies, including an American-Israeli cybersecurity firm,” the company claimed. “The user is never asked. They are never informed. LinkedIn’s privacy policy doesn’t mention it,” the website BrowserGate reported.
See also: Learn all about Microsoft's Agent Governance Toolkit
“Because LinkedIn knows each user's real name, employer, and job title, it doesn't look for anonymous visitors. It looks for identified people at identified companies.“.
What is LinkedIn's response to the accusations?
LinkedIn denies some of these accusations and refuses to respond to others. “This [accusation] is a house of cards based entirely on fabrication,” said a statement from LinkedIn emailed to CSOonline.
“We disclose that we scan for browser extensions in our privacy policy in order to detect abuse and provide defense for site stability“.
When asked whether it uses this data exclusively for these purposes, LinkedIn did not respond.
Possible misuse
The central figure behind the accusations calls himself Steven Morrell (not his real name, according to CsoOnline).
The company he represents also goes by different names, including Teamfluence and Fairlinked. Morrell said LinkedIn collects data that includes sensitive details, including information that he argued could be used to determine religious and political leanings. Collecting such data, Morrell said, could violate European privacy rules.
However, it's worth noting that Morrell isn't saying that LinkedIn actually uses the data to determine these preferences, but that it could. The same could be said for almost all major companies.
See also: Meta: Former engineer under investigation for stealing 30,000 photos of Facebook users

Additionally, he and LinkedIn are also embroiled in a legal dispute in Germany , in which Morrell said LinkedIn violated EU rules and banned him from the service without reason .
LinkedIn countered that Morrell and the other plaintiffs had violated its terms of service with their plugins. Last month, a judge in Munich ruled in LinkedIn’s favor, rejecting a request for a preliminary injunction.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Tips for CIOs
Cybersecurity consultant Brian Levine, executive director of FormerGov, said enterprise CIOs should use these categories, even if they prove untrue, to help adjust their data strategy and privacy policies for 2026.
“Assuming that the BrowserGate allegations are true, LinkedIn users should consider reducing the amount of identifiable, traceable, or sensitive data browser , and organizations should treat LinkedIn as a potentially hostile environment until the facts are verified,” Levine said. “Even if BrowserGate is exaggerated, browser fingerprinting is a real, widespread practice on the internet. Treat LinkedIn like any other third-party data collector. LinkedIn has historically been considered safe, but that assumption may need to be reexamined.”
See also: Contagious Interview – North Korea: 1,700 malicious npm, PyPI, Go, Rust packages

Levine said IT managers should “assume that LinkedIn can map their” and that, if the claims are accurate, LinkedIn could infer “what SaaS tools employees are using, what competitors they rely on, what tools job search staff are using, and what political/religious leanings are present in the workforce.”
He added that IT should consider blocking LinkedIn on sensitive networks or requiring it to be accessed only via VDI, as well as implementing browser isolation techniques.
Some companies may even want to use a separate isolated browser exclusively for LinkedIn, or, as he said, “use an isolated browser session, such as Browserling or other cloud-isolated browsers.”
