惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Latest news
Latest news
T
Troy Hunt's Blog
V
Vulnerabilities – Threatpost
L
LINUX DO - 热门话题
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
V
V2EX
博客园 - 司徒正美
B
Blog RSS Feed
AWS News Blog
AWS News Blog
MyScale Blog
MyScale Blog
Scott Helme
Scott Helme
Cisco Talos Blog
Cisco Talos Blog
Last Week in AI
Last Week in AI
NISL@THU
NISL@THU
博客园 - Franky
P
Proofpoint News Feed
博客园_首页
C
CERT Recently Published Vulnerability Notes
雷峰网
雷峰网
S
Schneier on Security
P
Proofpoint News Feed
Hugging Face - Blog
Hugging Face - Blog
G
GRAHAM CLULEY
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
WordPress大学
WordPress大学
The Hacker News
The Hacker News
T
Threatpost
阮一峰的网络日志
阮一峰的网络日志
A
Arctic Wolf
Microsoft Azure Blog
Microsoft Azure Blog
T
The Exploit Database - CXSecurity.com
Engineering at Meta
Engineering at Meta
罗磊的独立博客
T
The Blog of Author Tim Ferriss
D
Darknet – Hacking Tools, Hacker News & Cyber Security
I
Intezer
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
K
Kaspersky official blog
SecWiki News
SecWiki News
云风的 BLOG
云风的 BLOG
美团技术团队
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Security Latest
Security Latest
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog
S
Security Affairs

WeLiveSecurity

Supply chain dependencies: Have you checked your blind spot? Recovery scammers hit you when you’re down: Here’s how to avoid a ‘second strike’ As breakout time accelerates, prevention-first cybersecurity takes center stage Digital assets after death: Managing risks to your loved one’s digital estate This month in security with Tony Anscombe – March 2026 edition RSAC 2026 wrap-up – Week in security with Tony Anscombe A cunning predator: How Silver Fox preys on Japanese firms this tax season Virtual machines, virtually everywhere – but not all protected Cloud workload security: Mind the gaps Move fast and save things: A quick guide to recovering a hacked account EDR killers explained: Beyond the drivers Face value: What it takes to fool facial recognition Cyber fallout from the Iran war: What to have on your radar Sednit reloaded: Back in the trenches What cybersecurity actually does for your business How SMBs use threat research and MDR to build a defensive edge Protecting education: How MDR can tip the balance in favor of schools This month in security with Tony Anscombe – February 2026 edition Mobile app permissions (still) matter more than you may think Faking it on the phone: How to tell if a voice call is AI or not PromptSpy ushers in the era of Android threats using GenAI Is Poshmark safe? How to buy and sell without getting scammed Is it OK to let your children post selfies online? Naming and shaming: How ransomware groups tighten the screws on victims Taxing times: Top IRS scams to look out for in 2026 OfferUp scammers are out in force: Here’s what you should know A slippery slope: Beware of Winter Olympics scams and other cyberthreats This month in security with Tony Anscombe – January 2026 edition DynoWiper update: Technical analysis and attribution Love? Actually: Fake dating app used as lure in targeted spyware campaign in Pakistan Drowning in spam or scam emails lately? Here’s why ESET Research: Sandworm behind cyberattack on Poland’s power grid in late 2025 Children and chatbots: What parents should know Common Apple Pay scams, and how to stay safe Old habits die hard: 2025’s most common passwords were as predictable as ever Is it time for internet services to adopt identity verification? Your information is on the dark web. What happens next? Credential stuffing: What it is and how to protect yourself This month in security with Tony Anscombe – December 2025 edition A brush with online fraud: What are brushing scams and how do I stay safe? Revisiting CVE‑2025‑50165: A critical flaw in Windows Imaging Component LongNosedGoblin tries to sniff out governmental affairs in Southeast Asia and Japan ESET Threat Report H2 2025 Black Hat Europe 2025: Was that device designed to be on the internet at all? Black Hat Europe 2025: Reputation is currency – even in the ransomware economy Locks, SOCs and a cat in a box: What Schrödinger can teach us about cybersecurity Seeking symmetry during ATT&CK® season: How to harness today’s diverse analyst and tester landscape to paint a security masterpiece The biggest catch: How whaling attacks target top executives Phishing, privileges and passwords: Why identity is critical to improving cybersecurity posture MuddyWater: Snakes by the riverbank Oversharing is not caring: What’s at stake if your employees post too much online This month in security with Tony Anscombe – November 2025 edition What parents should know to protect their children from doxxing Influencers in the crosshairs: How cybercriminals are targeting content creators MDR is the answer – now, what’s the question? The OSINT playbook: Find your weak spots before attackers do PlushDaemon compromises network devices for adversary-in-the-middle attacks What if your romantic AI chatbot can’t keep a secret? Can password managers get hacked? Here’s what to know Why shadow AI could be your biggest security blind spot In memoriam: David Harley The who, where, and how of APT attacks in Q2 2025–Q3 2025 ESET APT Activity Report Q2 2025–Q3 2025 Sharing is scaring: The WhatsApp screen-sharing scam you didn’t see coming How social engineering really works | Unlocked 403 cybersecurity podcast (S2E6) Ground zero: 5 things to do after discovering a cyberattack This month in security with Tony Anscombe – October 2025 edition Fraud prevention: How to help older family members avoid scams Cybersecurity Awareness Month 2025: When seeing isn't believing Recruitment red flags: Can you spot a spy posing as a job seeker? How MDR can give MSPs the edge in a competitive market Cybersecurity Awareness Month 2025: Cyber risk thrives in the shadows Gotta fly: Lazarus targets the UAV sector SnakeStealer: How it preys on personal data – and how to stay safe Cybersecurity Awareness Month 2025: Building resilience against ransomware Minecraft mods: When ‘hacking’ your game becomes a security risk IT service desks: The security blind spot that may put your business at risk Cybersecurity Awareness Month 2025: Why software patching matters more than ever AI-aided malvertising: How chatbots can help spread scams How Uber seems to know where you are – even with restricted location permissions Cybersecurity Awareness Month 2025: Passwords alone are not enough The case for cybersecurity: Why successful businesses are built on protection Beware of threats lurking in booby-trapped PDF files Manufacturing under fire: Strengthening cyber-defenses amid surging threats New spyware campaigns target privacy-conscious Android users in the UAE Cybersecurity Awareness Month 2025: Knowledge is power This month in security with Tony Anscombe – September 2025 edition Roblox executors: It’s all fun and games until someone gets hacked DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception Watch out for SVG files booby-trapped with malware Gamaredon X Turla collab Small business, big risk: How SMBs can fight back against ransomware HybridPetya: A Petya/NotPetya copycat comes with a twist Introducing HybridPetya: Petya/NotPetya copycat with UEFI Secure Boot bypass Are cybercriminals hacking your systems – or just logging in? Preventing business disruption and building cyber-resilience with MDR Under lock and key: Safeguarding business data with encryption GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes This month in security with Tony Anscombe – August 2025 edition Don’t let “back to school” become “back to bullying”
Why LinkedIn is a hunting ground for threat actors – and how to protect yourself
Phil Muncaster · 2026-01-16 · via WeLiveSecurity

Social Media

The business social networking site is a vast, publicly accessible database of corporate information. Don’t believe everyone on the site is who they say they are.

16 Jan 2026  •  , 4 min. read

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

In November, Britain’s Security Service began notifying members of parliament (MPs) and their staff of an audacious foreign intelligence-gathering scheme. It claimed two profiles on LinkedIn were approaching individuals working in British politics in order to solicit “insider insights”. The revelations from MI5 precipitated a £170 million ($230 million) government initiative to tackle espionage threats to parliament.

It may be the most recent high-profile case of threat actors abusing LinkedIn to further their own nefarious goals. But it’s by no means the first. The site can also be a treasure trove of corporate data that can be used to support fraud or threat campaigns. It’s time professionals got wise to the risks of digital networking.

Why is LinkedIn a target?

LinkedIn has amassed more than one billion “members” worldwide since its founding in 2003. That’s a lot of potential targets for state-backed and financially motivated threat actors. But why is the platform so popular? A few reasons stand out:

  • It’s a fantastic information resource: By digging into the site, threat actors can find out the roles and responsibilities of key individuals in a targeted company, including new joiners. They can also piece together a pretty accurate picture of the relationships between individuals, and the kind of projects they might be working on. This is all invaluable intelligence which can then feed into spear-phishing and BEC fraud efforts.
  • It provides credibility and cover: Because LinkedIn is a professional networking site, it’s frequented by high-value executives and low-level workers alike. Both might have their uses to a threat actor. Victims are more likely to open a DM or InMail from someone on the site than they are an unsolicited email. In fact, when it comes to C-suite execs, it might be the only way to target them directly, as emails are often checked only by subordinates.
  • It bypasses 'traditional' security: Because messages travel through LinkedIn’s servers rather than corporate email systems, the corporate IT department is blind to what’s going on. Although LinkedIn has some built-in security measures, there’s no guarantee that phishing, malware and spam messages won’t get through. And because of the credibility of the site, targets may be more likely to click through on something malicious.
  • It’s easy to get up and running: For threat actors, the potential ROI for attacks using LinkedIn is massive. Anyone can register a profile and start prowling the site for profiles to extract intelligence from, or to target with phishing and BEC-style messages. Attacks are relatively easy to automate for scale. And to add legitimacy to phishing efforts, threat actors may want to hijack existing accounts or set up fake identifies before posing as job seekers or recruiters. The wealth of compromised credentials circulating on cybercrime forums (thanks in part to infostealers) makes this easier than ever.

Which attacks are most common?

As mentioned, there are various ways threat actors can operationalize their malicious campaigns via LinkedIn. These include:

  • Phishing and spearphishing: By using information that LinkedIn users share on their profiles, they can tailor phishing campaigns to improve their success rate.
  • Direct attacks: Adversaries may reach out directly with malicious links designed to deploy malware such as infostealers, or promote job offers intended to harvest credentials. Alternatively, state-backed operatives may use LinkedIn to recruit ‘insiders’ as MI5 warned.
  • BEC: As per the phishing example, LinkedIn provides a wealth of intelligence which can then be used to make BEC attacks more convincing. It might help fraudsters identify who reports to who, what projects they’re working on, and the names of any partners or suppliers.
  • Deepfakes: LinkedIn may also host videos of targets, which can be used to create deepfakes of them, for use in follow-on phishing, BEC or social media scams.
  • Account hijacking: Fake LinkedIn (phishing) pages, infostealers, credential stuffing and other techniques can be used to help threat actors takeover users’ accounts. These can be used in follow-on attacks targeting their contacts.
  • Supplier attacks: LinkedIn can also be trawled for details on partners of a targeted company, who can then be targeted with phishing in a “stepping stone” attack.

Examples of threat groups using some of the above include:

  • North Korea’s Lazarus Group has posed as recruiters on LinkedIn to install malware on the machines of individuals working in an aerospace company, as discovered by ESET Research. Indeed, the researchers also recently described the Wagemole IT worker campaigns in which North Korea-aligned individuals attempt to gain employment at overseas companies.
  • ScatteredSpider, called MGM's help desk posing as an employee it found on LinkedIn, in order to gain access to the organization. The ensuing ransomware attack resulted in $100 million in losses for the firm.
  • A spearphishing campaign dubbed “Ducktail” targeted marketing and HR professionals on LinkedIn, with info-stealing malware delivered via DM links. The malware itself was hosted in the cloud.

Staying safe on LinkedIn

As mentioned, the challenge with LinkedIn threats is that it’s difficult for IT to get any real insight into how extensive the risk is to its employees, and what tactics are being used to target them. However, it would make sense to build LinkedIn threat scenarios of the sort described above into security awareness courses. Employees should also be warned about oversharing on the site, and provided with help on how to spot fake accounts and typical phishing lures.

To avoid their own accounts being hijacked, they should also be following policy on regular patching, installing security software on all devices (from a trusted provider, of course), and switching on multi-factor authentication. It may be worth running specific training course for executives, who are often targeted more often. Above all, ensure your employees realize that, even on a trusted network like LinkedIn, not everyone has their best interests at heart.


Let us keep you
up to date

Sign up for our newsletters