LinkedIn Data Leak – What We Can Do About It

Scrubbed

Scrubbed

LinkedIn Data Leak – What We Can Do About It


The data leak on LinkedIn has been a hot topic this week, especially for those who use the platform for their professional networking. It has been reported that this was a significant data leak, affecting approximately 500 to 700 million LinkedIn user accounts. This is an alarming number and should be taken seriously, as it can have severe implications for both the company and its customers. The hackers gained access to names, emails, phone numbers, and other personal information — everything you would want to know about a person if you are trying to commit fraud or identity theft against them.


What Happened?

In June 2021, a hacker by the username “TomLiner” advertised for sale, on a darknet forum, information of 700 million LinkedIn users – that’s estimated to be around 90% of its total users! The data is now being sold for $5,000. If validated, this would be the largest LinkedIn data leak to date. The same seller was also behind the 500 million LinkedIn records advertised for sale last April 2021.  Later, a sample of 1 million users was published on the dark web, verified legitimate, and confirmed to be tied to real LinkedIn users. The data seems it was up-to-date with samples taken from 2020 to 2021.
How did it happen?
Recently, LinkedIn’s API (Application Programming Interface) was misused by a third party to gain access to the personal data of millions of users. The misuse of this API opens up potential security risks for many people and companies who use LinkedIn as their primary platform for business connections. LinkedIn said it had taken steps to remedy the situation. In this latest data leak, LinkedIn claims that this was a case of data scraping and data aggregation from different sources and not a data breach. They claim that no private LinkedIn member data was exposed; rather, this data leak was an aggregation of data from several websites and companies, as well as publicly viewable member profile data.

What was exposed?


In the published sample of 1 million entries, it contained email addresses, full names, phone numbers, physical addresses, geo-location records, LinkedIn user profile, personal and professional background, gender, and other social media account usernames. The data being sold exposed no passwords or credit card details.
In any case, users are advised that there will be a risk of increased social engineering attempts. LinkedIn contact details were leaked, and this data can be used in phishing and identity theft attacks. This can happen, especially if people having LinkedIn accounts also have accounts on other platforms such as Facebook and Twitter, where they share information about themselves. Hackers can use this to create fake LinkedIn accounts or log in to other accounts.

What happens next? 


Due to the sheer nature of the data leak, LinkedIn users need to be on high alert for email scams, such as phishing scams that could look the same as LinkedIn emails. Users should also change passwords immediately if there is any sign of potential account compromise.
LinkedIn may already be aware of suspicious accounts that have or are trying to use the leaked data. As such, LinkedIn advises people to monitor their LinkedIn email addresses for any suspicious activity. They also notified law enforcers about this leak and are willing to cooperate with them in investigating the situation further. LinkedIn itself did not mention on how or why the leak occurred. 
Companies who use LinkedIn for business networking need to start strategizing on dealing with LinkedIn data leak fallout. LinkedIn users include a large number of people in every position and in every company. Companies need to be mindful of how this affects their daily business operations.
LinkedIn itself may also face some consequences due to this leak. Besides scrutiny from different groups, LinkedIn will likely see a decrease in new account sign-ups in the future.

What can Companies do about it?


LinkedIn is a widely used platform and companies should start alerting their employees of the data leak. Companies should also advise their employees to review and update their LinkedIn passwords and possibly other online accounts that share the same password. Further, companies should help educate employees on data hygiene and data privacy practices to protect themselves from future data breaches.
In addition to awareness, companies should deploy stricter spam controls and train their employees to spot social engineering and phishing campaigns. This is where information security awareness tools come in handy – tools such as PhishingQuiz with Google (https://phishingquiz.withgoogle.com) are an excellent example of this. More comprehensive training solutions like KnowBe4, which offers information security awareness training, can help educate the employees by increasing their knowledge on how hackers steal data from the workplace.
Lastly, and needless to say, companies should refrain from supporting sellers of stolen data and should avoid purchasing it.

What can regular LinkedIn users do about it?


LinkedIn users need to be on high alert for any suspicious online activity. If you have a LinkedIn account, make sure that it is protected with a strong password and having your two-factor authentication (2FA) activated for enhanced account security. This holds true not only for LinkedIn but for other online accounts as well. In addition, you should also be careful when installing browser extensions or any unchecked applications on your computer.
Check whether your email address or phone number has been compromised. Websites such as Have I Been Pwned are a great place to start (https://haveibeenpwned.com/). Be vigilant and try to reduce the damage that it can do to your online accounts. Think twice before you upload or share your information online and always assume that it may be exposed publicly.

Stay Prepared in a Changing Landscape
The LinkedIn data leak highlights just how important it is for businesses to stay vigilant when it comes to security and managing sensitive information. At Scrubbed, we understand the challenges companies face in navigating risks and staying compliant while also keeping their operations running smoothly.
Here are just a few ways we can support your business:

  • Risk Advisory: Helping you identify and address risks before they become issues.
  • Technical Accounting Services: Simplifying complex accounting processes.
  • Data and Analytics: Turning data into clear, actionable insights.
  • ESG Reporting Services: Developing strategies for sustainability and ethical practices.
  • Full-Service Bookkeeping & Accounting: Keeping your financials accurate and reliable.
  • Tax Compliance & Advisory: Ensuring you stay compliant while optimizing your tax strategy.
  • Accounting and Finance Staffing: Providing experienced professionals to fit your needs.
  • Transaction Advisory Services: Guiding you through critical financial decisions.
  • Corporate Finance: Supporting your plans for growth with sound financial advice.
  • CFO Support Services: Offering tailored financial leadership when you need it.
  • Biotech Accounting Services: Expert guidance for biotech financial, regulatory, and reporting requirements.

If the recent data leak has you rethinking your approach, now might be a good time to evaluate your systems and processes. Whether it’s enhancing security, streamlining operations, or planning for growth, we’re here to help.
If you’d like to learn more, feel free to reach out or explore our services.

ABOUT THE AUTHORS

Nicko has more than 6 years of combined Vulnerability Assessment and Penetration Testing (VAPT), information security audit, and security implementation experience. Before joining Scrubbed, he was part of the grassroots team that started the cybersecurity practice in one of the big four auditing firms in the Philippines.

John has more than 9 years of work experience with core competencies ranging from conducting financial due diligence reviews for acquisition and divestiture transactions, completion audit, strategy work, and assurance service lines. His industry experience covers power and energy, oil and gas, retail and consumer, manufacturing, telecommunications, real estate & property, food and beverage, banking and financial services, among others.

Chester has more than five years of relevant experience in accounting and audit. He started his career as an auditor in SGV & Co. (EY Philippines) and handled clients mainly in the construction, manufacturing and real estate industries. In May 2019, he joined Scrubbed handling clients in real estate and hospitality industries. His expertise includes monthly closing process and consolidation.

Sources:
https://www.foxbusiness.com/technology/linkedin-data-leak-cyberattack
https://www.privacysharks.com/exclusive-700-million-linkedin-records-for-sale-on-hackerforum-june-22nd-2021/ 
https://heimdalsecurity.com/blog/linkedin-data-of-700-million-people-leaked/
https://blog.malwarebytes.com/awareness/2021/06/second-colossal-linkedin-breach-in-3-months-almost-all-users-affected/
https://restoreprivacy.com/linkedin-data-leak-700-million-users/
https://heimdalsecurity.com/blog/linkedin-data-of-700-million-peopleleaked/
https://9to5mac.com/2021/06/29/linkedin-breach/
https://www.privacysharks.com/exclusive-700-million-linkedin-records-forsale-on-hacker-forum-june-22nd-2021/
https://news.linkedin.com/2021/april/an-update-from-linkedin 
https://www.inputmag.com/culture/hackers-used-linkedins-official-api-to-leak-tons-ofdataagain
https://www.onmsft.com/news/linkedin-data-leak-claim-more-users 
https://leaks.so/threads/sample-1-million-linkedin-data-leaked-22-june-2021-freedownload.16665/
https://www.privacysharks.com/exclusive-700-millionlinkedin-records-for-sale-on-hacker-forum-june-22nd-2021/june-22nd-2021/
https://www.privacysharks.com/exclusive-700-million-linkedinrecords-for-sale-on-hacker-forum-june-22nd-2021/
https://www.linkedin.com/help/linkedin/answer/56347/prohibited-softwareand-extensions?src=re-other&veh=www.privacysharks.com|or-search
https://www.privacysharks.com/exclusive-700-million-linkedin-records-for-sale-on-hacker-forum-june-22nd-2021/
https://cybernews.com/news/stolen-data-of-500-millionlinkedin-users-being-sold-online-2-million-leaked-as-proof-2/

Related Content

Blogs

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

If I had to name the first common mistake I see growing companies make when they tackle ESG reporting, it is foundational: They don’t know if the data they are using is complete and accurate. More than that, they often don’t even know if it is the data they should be using. For years, ESG reporting was largely voluntary, a way to answer the public’s demand for accountability and show investors you were responsible. But as optional guidelines transition into emerging laws and requirements, the landscape shifts. Investors and regulators no longer want marketing campaigns. They want accurate data provided with assurance. This brings us to a harsh reality I share with teams newly subject to these regulations: If you are required to file a report in 2027 based on 2026 data, and you wait until 2026 to start preparing, you are already late. Leaders often assume their existing accounting systems are naturally ready to handle ESG reporting. They almost never are. The Illusion of Alignment I see leadership teams fall into this trap constantly. They look at their organizational chart, see a separate Finance team and a separate ESG team, and assume they are covered. But in practice, these two teams are working in silos, speaking entirely different languages. I see this pattern constantly with companies that have been publishing ESG reports voluntarily for a number of years. As they prepare for mandated regulatory reporting, leadership feels secure because their ESG team is getting the exact reports they requested from Finance. But the moment you dig into the architecture and bridge the two teams, the gaps become obvious. Here is how the breakdown usually happens: The Ask: The ESG team needs data to calculate emissions, so they ask Finance for certain reports. The Hand-off: Finance, wanting to be helpful, pulls the data and hands it over. The Gap: Finance teams are wired to be compliant with accounting standards, but they aren’t trained to understand ESG reporting. ESG teams are great at translating finance data into emissions, but they don’t have the concept of an audit. Because the ESG team didn’t have an audit background, they didn’t know how to establish completeness and accuracy. They didn’t know how to look for certain accounting transactions that would otherwise be considered emission or non-emissive (i.e., advance or duplicate payments, reversed entries in the vendor reports). They were running calculations on raw data. The people didn’t fail: the structure simply wasn’t built to translate between the two departments. The Reality of Retroactive Cleanup The true operational complexity of ESG reporting reveals itself when you try to force accounting data into sustainability buckets. Take something as standard as a growing portfolio of leased facilities. From a purely financial perspective, a company might have these perfectly recorded. But you cannot translate that 1:1 to ESG data. For ESG, you have to review the business structure to see who actually holds ‘operational control’ so you can assign those facilities to the proper emissions categories.. When a company’s data architecture isn’t set up for this level of granularity, teams are forced to go back and manually revisit hundreds of outstanding contracts. What should take a minute to encode upfront easily turns into a multi-month project just to find the proper data sources. When you wait to build the system, you force your teams to look backward instead of forward. What You Need to Check Today The fix is actively bridging the technical gap. You need professionals who can translate complex sustainability metrics into an accounting standard, and vice versa. If you are a CFO or sustainability leader reading this today, before making your next public ESG commitment, take a hard look at your architecture. Ask yourself these three questions: Are my on-book activities scoped properly? Check if all financial transactions have been mapped to the appropriate ESG requirement. Are my off-book activities accounted for? Ensure your people management, technology, and operational data are fully captured. Are all stakeholders involved? If ESG reporting is falling entirely on your Finance team, or solely on your ESG team without Finance’s oversight, you have a translation gap. Operations, HR, and Tech must understand the why and the how of the data they are providing. A calm, predictable reporting cycle is designed, never improvised. Build the data architecture a year or two before the regulations hit, and ensure your financial execution naturally supports confident sustainability reporting.

Read More >
Blogs

Sustainable Spaces: From Compliance to Commitment

Sustainable Spaces: From Compliance to Commitment

Climate change is a pressing issue, and the building and construction sector is a major contributor. A staggering 40% of energy-related CO2 emissions come from buildings, and, according to the UN Environment Programme’s 2022 Global Status Report for Buildings and Construction, the industry falls short of decarbonization targets, with CO2 emissions currently reaching new highs. From materials used to construction practices and daily operations, traditional methods take a toll on the environment. Sustainable building—architecture focusing on environmental responsibility—offers a solution. Looking for Innovative Solutions for a Rapidly Changing ESG Landscape? Click here! Building Green: A New Approach Sustainable design is about creating buildings that meet the needs of the present without compromising the ability of future generations to meet their own needs. Its key principles include: Eco-friendly materials: Responsibly harvested wood, recycled steel, and locally sourced materials reduce embodied carbon and transportation emissions. Innovations like carbon-neutral concrete further reduce environmental impact. Energy-efficient glasses in façades minimize heat gain and reliance on cooling and lighting. Passive & active design strategies: Passive strategies utilize natural elements for energy efficiency and comfort. Daylighting, natural ventilation, and well-insulated walls and roofs improve energy efficiency and resource optimization. On the other hand, active design utilizes technologies like solar panels and wind turbines to generate electricity, working alongside passive strategies for a more sustainable future. Water conservation: Rainwater harvesting systems, low-flow fixtures, and efficient irrigation minimize freshwater demand and water wastage, preserving resources and cutting costs. Sustainable Leaders Around the Globe Many companies are embracing sustainable practices, showcasing the power of green building. Some prominent examples are: Apple Park (Cupertino, California): Features one of the largest on-site solar installations globally, alongside natural cooling systems and extensive green spaces. Googleplex (Mountain View, California): Utilizes solar power, recycled water for irrigation, and a building management system that monitors energy use. Pixel Building (Melbourne, Australia): Australia’s first carbon-neutral office building boasts efficient daylighting, wastewater processing, and a recycled aluminum façade. Bank of America Tower (New York City, New York): Uses 32% less energy than a typical office tower. Abundant daylighting, district-chilled water for cooling, and a green roof prioritize energy efficiency and resource conservation. The Edge (Amsterdam, Netherlands): Cutting-edge energy efficiency and occupant comfort technologies include a “digital ceiling” with sensors optimizing lighting and an aquifer-based temperature regulation system. Global Standards and Certifications Transitioning to sustainable spaces can unlock exciting opportunities, such as attracting investment from environmentally conscious businesses and consumers. Sustainable building practices are not just good for the planet but also good for business and several frameworks exist to guide the design and construction of sustainable spaces: LEED (Leadership in Energy and Environmental Design): A comprehensive framework for designing, constructing, and operating green buildings. It evaluates energy efficiency, water conservation, and indoor environmental quality. BREEAM (Building Research Establishment Environmental Assessment Method) : Evaluates energy, materials, ecology, and water usage, promoting sustainable material usage and energy-efficient systems. WELL Building Standard: Prioritizes air and water quality, user well-being, and environmental sustainability for healthier buildings. Living Building Challenge: The most rigorous standard for sustainability, it emphasizes regenerative design principles, reducing energy consumption, and promoting on-site water harvesting. By prioritizing sustainable design principles, utilizing innovative materials and technologies, and adhering to global green building standards, we can transform our physical environment into a responsible and regenerative force for a healthier planet. This transition not only benefits the environment but fosters economic growth in new and innovative ways.

Read More >
Blogs

Sustainability Beyond Profit: ESG Trends for Nonprofit Organizations

Sustainability Beyond Profit: ESG Trends for Nonprofit Organizations

Environmental, Social, and Governance (ESG) principles have traditionally been associated with for-profit businesses. However, in recent years, there has been a growing recognition of ESG’s relevance for nonprofit organizations (NPOs) as well. Why ESG Matters for NPOs For NPOs, ESG can be a strategic opportunity. As businesses and investors become more ESG-focused, they will be more selective in choosing NPO partners. NPOs with strong governance frameworks and clearly defined ESG practices will be seen as more trustworthy and impactful. ESG reporting also plays a role in enhancing transparency and accountability for NPOs, which can align well with your mission and reputation. Since following reporting standards also allows NPOs to be held to the same expectations as other sectors, it can also be seen as a way to strengthen your legitimacy and credibility. Internally, ESG reporting can also help focus your NPO constructively on self-assessment, measuring your impact, and continuously improving your practices. ESG in Day-To-Day Operations Some NPOs are already integrating ESG considerations into their day-to-day operations. Here are some ways they are doing this: Aligning mission and action: By their nature, NPOs address social or environmental issues. Integrating ESG ensures your organization’s business practices directly support your goals. For example, an environmental NPO might adopt sustainable practices in its offices, like using recycled paper or energy-efficient appliances. Proactive risk management: Thinking through ESG metrics helps NPOs identify and mitigate potential risks. This includes reputational risks tied to environmental practices, social justice concerns, or even regulatory compliance. Strong ESG practices can make your NPO more resilient. Boosting efficiency: Sustainable operations can lead to cost savings. This could mean reducing energy consumption, minimizing waste, or implementing a recycling program. These practices not only benefit the environment but also free up resources that NPOs can then direct towards the core mission. Building trust with stakeholders: A strong ESG commitment can increase donor and grantor confidence in your organization. Being transparent about your ESG practices fosters trust and credibility, leading to more fundraising opportunities and greater community involvement. Strengthening governance: Clear policies, procedures, and reporting mechanisms around ESG enhance the smooth running of your organization and provide greater transparency and accountability. Demonstrating strong governance makes your organization more efficient and also improves stakeholder trust and public support for your mission. Ensuring long-term viability: By embracing ESG, NPOs become more adaptable and sustainable in the long run. Strong ESG practices can help position your organization to navigate future challenges and continue delivering on your mission. Navigating Guidance and Frameworks Several frameworks have been developed to guide ESG reporting. While these tend to be aimed at the for-profit sector, they can still be valuable resources for NPOs. Global Reporting Initiative (GRI): GRI offers general sustainability reporting guidelines that NPOs can adapt. These guidelines cover strategy, organizational profile, material aspects, stakeholder engagement, and more. The GRI website also provides implementation guidance. GRI Sector Disclosure G4 for NGOs: This GRI guidance specifically addresses reporting for NPOs. It recommends focusing on disclosures most relevant to the NPO’s mission and activities. The guidance suggests that specific standard disclosures per category should only be reported if they have been identified as material, in addition to the general standard disclosures mentioned. Task Force on Climate-related Financial Disclosures (TCFD) : NPOs can use the TCFD framework to improve their reporting on climate-related risks and opportunities. TCFD offers a structured approach to assessing and communicating climate risks and opportunities. Carbon Disclosure Project (CDP): The CDP platform encourages organizations to disclose environmental impacts, risks, and opportunities. While often used by corporations, it is also a valuable tool for NPOs seeking to be more environmentally transparent. Industry-Specific Guidance As non-profit organizations (NPOs) operate across various sectors, each catering to different societal needs, specific disclosure requirements are necessary, differing from the standard disclosures for the for-profit industry. The Sustainability Accounting Standards Board (SASB) delineates detailed requirements per sector, such as healthcare, education, home builders and more. For instance, in healthcare, additional disclosures focus on patient privacy, electronic health records, and quality of care, also necessitating qualitative descriptions of policies and practices for securing personal health data and quantitative data on data breaches and patient readmissions. Similarly, education sector disclosures cover the quality of education and gainful employment, mandating disclosure of graduation and job placement rates. Furthermore, the home-building sector demands disclosures on the community impacts of new developments, encompassing details such as the total number of controlled lots and delivered homes. These tailored requirements reflect the unique operational landscapes and stakeholder interests of NPOs in various sectors that are not typically seen in the same sectors in the for-profit industry. We would also suggest following other NPOs that have already begun integrating ESG reporting into their work. For example, the American Red Cross has published a comprehensive ESG report that aligns with GRI standards and sets a baseline for the Red Cross to measure future progress. Currently, NPOs are free to tailor the forms and content of reporting as long as they meet the minimum requirements of the standard they opt to use and disclose only credible and factual information. ESG is no longer just a concern for for-profit businesses; it is becoming increasingly important for NPOs. By embracing ESG principles, NPOs can enhance transparency, strengthen stakeholder confidence, improve operational efficiency, and position themselves for long-term success.

Read More >

Contact Information

SF Bay Area Headquarters
111 Anza Boulevard, Suite 320, Burlingame, CA 94010, United States

Phone: (800)837-5160
Email: [email protected]

"Scrubbed" is the brand name under which Scrubbed Advisory, LLC and Scrubbed Assurance, LLP provide professional services. Scrubbed Advisory, LLC and Scrubbed Assurance, LLP practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Scrubbed Assurance, LLP is a licensed independent CPA firm that provides attest services to its clients, and Scrubbed Advisory, LLC provides tax, finance, and support services to its clients. Scrubbed Advisory, LLC is not a licensed CPA firm.

Copyright © Scrubbed. All rights reserved.