LinkedIn Data Leak – What We Can Do About It

Scrubbed

Scrubbed

LinkedIn Data Leak – What We Can Do About It


The data leak on LinkedIn has been a hot topic this week, especially for those who use the platform for their professional networking. It has been reported that this was a significant data leak, affecting approximately 500 to 700 million LinkedIn user accounts. This is an alarming number and should be taken seriously, as it can have severe implications for both the company and its customers. The hackers gained access to names, emails, phone numbers, and other personal information — everything you would want to know about a person if you are trying to commit fraud or identity theft against them.


What Happened?

In June 2021, a hacker by the username “TomLiner” advertised for sale, on a darknet forum, information of 700 million LinkedIn users – that’s estimated to be around 90% of its total users! The data is now being sold for $5,000. If validated, this would be the largest LinkedIn data leak to date. The same seller was also behind the 500 million LinkedIn records advertised for sale last April 2021.  Later, a sample of 1 million users was published on the dark web, verified legitimate, and confirmed to be tied to real LinkedIn users. The data seems it was up-to-date with samples taken from 2020 to 2021.
How did it happen?
Recently, LinkedIn’s API (Application Programming Interface) was misused by a third party to gain access to the personal data of millions of users. The misuse of this API opens up potential security risks for many people and companies who use LinkedIn as their primary platform for business connections. LinkedIn said it had taken steps to remedy the situation. In this latest data leak, LinkedIn claims that this was a case of data scraping and data aggregation from different sources and not a data breach. They claim that no private LinkedIn member data was exposed; rather, this data leak was an aggregation of data from several websites and companies, as well as publicly viewable member profile data.

What was exposed?


In the published sample of 1 million entries, it contained email addresses, full names, phone numbers, physical addresses, geo-location records, LinkedIn user profile, personal and professional background, gender, and other social media account usernames. The data being sold exposed no passwords or credit card details.
In any case, users are advised that there will be a risk of increased social engineering attempts. LinkedIn contact details were leaked, and this data can be used in phishing and identity theft attacks. This can happen, especially if people having LinkedIn accounts also have accounts on other platforms such as Facebook and Twitter, where they share information about themselves. Hackers can use this to create fake LinkedIn accounts or log in to other accounts.

What happens next? 


Due to the sheer nature of the data leak, LinkedIn users need to be on high alert for email scams, such as phishing scams that could look the same as LinkedIn emails. Users should also change passwords immediately if there is any sign of potential account compromise.
LinkedIn may already be aware of suspicious accounts that have or are trying to use the leaked data. As such, LinkedIn advises people to monitor their LinkedIn email addresses for any suspicious activity. They also notified law enforcers about this leak and are willing to cooperate with them in investigating the situation further. LinkedIn itself did not mention on how or why the leak occurred. 
Companies who use LinkedIn for business networking need to start strategizing on dealing with LinkedIn data leak fallout. LinkedIn users include a large number of people in every position and in every company. Companies need to be mindful of how this affects their daily business operations.
LinkedIn itself may also face some consequences due to this leak. Besides scrutiny from different groups, LinkedIn will likely see a decrease in new account sign-ups in the future.

What can Companies do about it?


LinkedIn is a widely used platform and companies should start alerting their employees of the data leak. Companies should also advise their employees to review and update their LinkedIn passwords and possibly other online accounts that share the same password. Further, companies should help educate employees on data hygiene and data privacy practices to protect themselves from future data breaches.
In addition to awareness, companies should deploy stricter spam controls and train their employees to spot social engineering and phishing campaigns. This is where information security awareness tools come in handy – tools such as PhishingQuiz with Google (https://phishingquiz.withgoogle.com) are an excellent example of this. More comprehensive training solutions like KnowBe4, which offers information security awareness training, can help educate the employees by increasing their knowledge on how hackers steal data from the workplace.
Lastly, and needless to say, companies should refrain from supporting sellers of stolen data and should avoid purchasing it.

What can regular LinkedIn users do about it?


LinkedIn users need to be on high alert for any suspicious online activity. If you have a LinkedIn account, make sure that it is protected with a strong password and having your two-factor authentication (2FA) activated for enhanced account security. This holds true not only for LinkedIn but for other online accounts as well. In addition, you should also be careful when installing browser extensions or any unchecked applications on your computer.
Check whether your email address or phone number has been compromised. Websites such as Have I Been Pwned are a great place to start (https://haveibeenpwned.com/). Be vigilant and try to reduce the damage that it can do to your online accounts. Think twice before you upload or share your information online and always assume that it may be exposed publicly.

Stay Prepared in a Changing Landscape
The LinkedIn data leak highlights just how important it is for businesses to stay vigilant when it comes to security and managing sensitive information. At Scrubbed, we understand the challenges companies face in navigating risks and staying compliant while also keeping their operations running smoothly.
Here are just a few ways we can support your business:

  • Risk Advisory: Helping you identify and address risks before they become issues.
  • Technical Accounting Services: Simplifying complex accounting processes.
  • Data and Analytics: Turning data into clear, actionable insights.
  • ESG Reporting Services: Developing strategies for sustainability and ethical practices.
  • Full-Service Bookkeeping & Accounting: Keeping your financials accurate and reliable.
  • Tax Compliance & Advisory: Ensuring you stay compliant while optimizing your tax strategy.
  • Accounting and Finance Staffing: Providing experienced professionals to fit your needs.
  • Transaction Advisory Services: Guiding you through critical financial decisions.
  • Corporate Finance: Supporting your plans for growth with sound financial advice.
  • CFO Support Services: Offering tailored financial leadership when you need it.
  • Biotech Accounting Services: Expert guidance for biotech financial, regulatory, and reporting requirements.

If the recent data leak has you rethinking your approach, now might be a good time to evaluate your systems and processes. Whether it’s enhancing security, streamlining operations, or planning for growth, we’re here to help.
If you’d like to learn more, feel free to reach out or explore our services.

ABOUT THE AUTHORS

Nicko has more than 6 years of combined Vulnerability Assessment and Penetration Testing (VAPT), information security audit, and security implementation experience. Before joining Scrubbed, he was part of the grassroots team that started the cybersecurity practice in one of the big four auditing firms in the Philippines.

John has more than 9 years of work experience with core competencies ranging from conducting financial due diligence reviews for acquisition and divestiture transactions, completion audit, strategy work, and assurance service lines. His industry experience covers power and energy, oil and gas, retail and consumer, manufacturing, telecommunications, real estate & property, food and beverage, banking and financial services, among others.

Chester has more than five years of relevant experience in accounting and audit. He started his career as an auditor in SGV & Co. (EY Philippines) and handled clients mainly in the construction, manufacturing and real estate industries. In May 2019, he joined Scrubbed handling clients in real estate and hospitality industries. His expertise includes monthly closing process and consolidation.

Sources:
https://www.foxbusiness.com/technology/linkedin-data-leak-cyberattack
https://www.privacysharks.com/exclusive-700-million-linkedin-records-for-sale-on-hackerforum-june-22nd-2021/ 
https://heimdalsecurity.com/blog/linkedin-data-of-700-million-people-leaked/
https://blog.malwarebytes.com/awareness/2021/06/second-colossal-linkedin-breach-in-3-months-almost-all-users-affected/
https://restoreprivacy.com/linkedin-data-leak-700-million-users/
https://heimdalsecurity.com/blog/linkedin-data-of-700-million-peopleleaked/
https://9to5mac.com/2021/06/29/linkedin-breach/
https://www.privacysharks.com/exclusive-700-million-linkedin-records-forsale-on-hacker-forum-june-22nd-2021/
https://news.linkedin.com/2021/april/an-update-from-linkedin 
https://www.inputmag.com/culture/hackers-used-linkedins-official-api-to-leak-tons-ofdataagain
https://www.onmsft.com/news/linkedin-data-leak-claim-more-users 
https://leaks.so/threads/sample-1-million-linkedin-data-leaked-22-june-2021-freedownload.16665/
https://www.privacysharks.com/exclusive-700-millionlinkedin-records-for-sale-on-hacker-forum-june-22nd-2021/june-22nd-2021/
https://www.privacysharks.com/exclusive-700-million-linkedinrecords-for-sale-on-hacker-forum-june-22nd-2021/
https://www.linkedin.com/help/linkedin/answer/56347/prohibited-softwareand-extensions?src=re-other&veh=www.privacysharks.com|or-search
https://www.privacysharks.com/exclusive-700-million-linkedin-records-for-sale-on-hacker-forum-june-22nd-2021/
https://cybernews.com/news/stolen-data-of-500-millionlinkedin-users-being-sold-online-2-million-leaked-as-proof-2/

Related Content

Blogs

Decoding the Digital Ledger: Navigating FASB’s New Standards for Crypto Assets and Intangibles (ASU 2023-08)

Decoding the Digital Ledger: Navigating FASB’s New Standards for Crypto Assets and Intangibles (ASU 2023-08)

In a groundbreaking move reflecting the swift evolution of the financial landscape, the Financial Accounting Standards Board (FASB) has taken a significant step with the release of the final Accounting Standards Update (ASU) 2023-08 titled “Accounting for and Disclosure of Crypto Assets.” This authoritative guidance specifically addresses Crypto Assets within the Intangibles—Goodwill and Other category, marking a crucial advance in establishing standardized accounting practices for these assets. Bridging the Gap: A Brief Background The rise of digital assets, from cryptocurrencies like Bitcoin and Ethereum to unique non-fungible tokens (NFTs), has challenged traditional accounting norms. Without specific Generally Accepted Accounting Principles (GAAP) guidance, accounting professionals relied on analogies and interpretations, resulting in a diverse patchwork of practices.  Our article “Rise of Digital Assets in Business” explored the evolving landscape, highlighting the AICPA Practice Aid titled “Accounting for and Auditing of Digital Assets” as a crucial guide within the constraints of the existing accounting framework. We are witnessing a groundbreaking shift with the finalized FASB’s ASU on Crypto Assets, effective December 15, 2024, which will change how the world sees crypto assets. Who Will Be Affected? The new ASU applies to a wider range of entities than you might think. Any entity holding crypto assets that meet specific criteria will be impacted. These criteria include: Meet the definition of an intangible asset. Do not grant enforceable rights or claims on underlying goods, services, or assets. Exist on a blockchain-based distributed ledger or similar technology. Are secured using cryptography. Are fungible. Are not created or issued by the reporting entity or its related parties. Crypto assets falling within these criteria must be measured at fair value, with changes in value recognized in their income statement each reporting period. Moreover, transaction costs incurred in acquiring these assets, such as commissions and related fees, will be expensed unless other industry-specific guidance dictates otherwise. A Closer Look at the New ASU  Mandating Relevance: Fair Value Measurement  The update mandates the fair value measurement of crypto assets at each reporting period. This focus on fair value measurement stems from the belief that fair value offers investors more relevant information about the assets’ sale value and changes in that value. The Board rejected historical cost and net realizable value as alternatives due to limitations in reflecting downward and upward price movements. The existing guidance in Topic 820 was deemed sufficient for fair value measurement, given its applicability to other assets and current use by reporting entities. As financial reporting evolves, organizations offering ESG reporting services may also need to consider how such valuation updates intersect with broader transparency and sustainability disclosure requirements. Beyond Annual Assessment: Recognizing Both Gains and Losses Unlike the existing ASC 350 model, which mandates an annual assessment of crypto asset value that only recognizes gains upon sale, the update embraces a more dynamic approach. The new method captures both negative and positive market movements, addressing longstanding concerns about the traditional model’s failure to reflect the true and current economic nature of crypto assets at each reporting period. As well as providing a more comprehensive understanding of the underlying economics and an entity’s financial position, the shift signifies a progressive step toward a more responsive and accurate representation of the financial impact of market fluctuations on digital holdings. Enhancing Transparency: Disclosure Requirements The ASU prioritizes transparency, incorporating detailed disclosure requirements for asset categorization, impairment considerations, and, notably, the separate presentation of crypto assets from other intangible assets in the statement of financial position. Entities must disclose the following for annual and interim reporting periods: 1. Details of significant and less significant crypto asset holdings, including name, cost basis, fair value, and quantity. 2. Information on restricted crypto assets, covering fair value, nature, the remaining duration of restrictions, and circumstances for the potential lapse. For annual reporting periods, additional disclosures are required: 1. A roll forward of crypto asset activity, including additions, dispositions, gains, and losses. Specify the income statement line item for unrecognized gains and losses if not presented separately. 2. Detail dispositions of crypto assets, including sale price, cost basis difference, and relevant activities. 3. The method used to determine the cost basis of crypto assets. These changes enhance transparency and understanding of crypto asset holdings, ensuring comprehensive disclosure for annual and interim reporting periods. Nevertheless, entities immediately converting crypto assets received as noncash consideration or contributions into cash are exempt from the above annual additional disclosures. The Countdown Begins: Timeline and Adoption The final standard takes effect for all entities in reporting periods beginning after December 15, 2024, including interim periods within those fiscal years. Early adoption is permitted, allowing entities to embrace the changes ahead of the mandated timeline. However, early adopters must use a modified retrospective approach, requiring recording a cumulative effect adjustment to equity (or net assets) from the commencement of the adoption year. What Lies Ahead: Implications for the Future The issuance of the finalized ASU 2023-08 represents a proactive response to the growing significance of crypto assets in today’s financial landscape. The finalized ASU is a significant milestone in our journey toward a standardized and transparent future for crypto asset accounting, offering consistency in financial reporting across diverse industries engaged with crypto assets. The FASB’s move acknowledges the need for accounting standards that keep pace with technological advancements and reflect the realities of the modern economy. Stay tuned for further developments. How Scrubbed Can Help You? Navigating the opportunities and challenges of crypto assets demands expertise, whether you’re an individual investor or a business. At Scrubbed, our comprehensive range of services empowers you to stay ahead: • Compliance Experts: Navigate crypto regulations effortlessly with our seasoned professionals. From taxes to reporting, we’ve got your compliance needs covered. • Rock-Solid Controls: Establish secure systems and ensure compliance with the latest financial reporting standards like GAAP and IFRS. • Innovative Strategies: Beyond the numbers, we offer strategic insights about market tren ds and help you make wise decisions. As we collectively pioneer a new era of financial reporting, Scrubbed is committed to bridging the gap between traditional accounting norms and the groundbreaking shifts introduced by the FASB on Crypto Assets. Our Technical Accounting Group is ready to assist your business in decoding the digital ledger, ensuring effective operations, and maintaining compliance with evolving regulations. We also provide specialized biotech accounting services, supporting organizations in highly regulated industries with tailored financial reporting solutions. For a comprehensive consultancy assessment tailored to your specific needs, reach out to [email protected].

Read More >
Blogs

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

The ESG Translation Gap: Why Good Accounting Data Fails Sustainability Audits

If I had to name the first common mistake I see growing companies make when they tackle ESG reporting, it is foundational: They don’t know if the data they are using is complete and accurate. More than that, they often don’t even know if it is the data they should be using. For years, ESG reporting was largely voluntary, a way to answer the public’s demand for accountability and show investors you were responsible. But as optional guidelines transition into emerging laws and requirements, the landscape shifts. Investors and regulators no longer want marketing campaigns. They want accurate data provided with assurance. This brings us to a harsh reality I share with teams newly subject to these regulations: If you are required to file a report in 2027 based on 2026 data, and you wait until 2026 to start preparing, you are already late. Leaders often assume their existing accounting systems are naturally ready to handle ESG reporting. They almost never are. The Illusion of Alignment I see leadership teams fall into this trap constantly. They look at their organizational chart, see a separate Finance team and a separate ESG team, and assume they are covered. But in practice, these two teams are working in silos, speaking entirely different languages. I see this pattern constantly with companies that have been publishing ESG reports voluntarily for a number of years. As they prepare for mandated regulatory reporting, leadership feels secure because their ESG team is getting the exact reports they requested from Finance. But the moment you dig into the architecture and bridge the two teams, the gaps become obvious. Here is how the breakdown usually happens: The Ask: The ESG team needs data to calculate emissions, so they ask Finance for certain reports. The Hand-off: Finance, wanting to be helpful, pulls the data and hands it over. The Gap: Finance teams are wired to be compliant with accounting standards, but they aren’t trained to understand ESG reporting. ESG teams are great at translating finance data into emissions, but they don’t have the concept of an audit. Because the ESG team didn’t have an audit background, they didn’t know how to establish completeness and accuracy. They didn’t know how to look for certain accounting transactions that would otherwise be considered emission or non-emissive (i.e., advance or duplicate payments, reversed entries in the vendor reports). They were running calculations on raw data. The people didn’t fail: the structure simply wasn’t built to translate between the two departments. The Reality of Retroactive Cleanup The true operational complexity of ESG reporting reveals itself when you try to force accounting data into sustainability buckets. Take something as standard as a growing portfolio of leased facilities. From a purely financial perspective, a company might have these perfectly recorded. But you cannot translate that 1:1 to ESG data. For ESG, you have to review the business structure to see who actually holds ‘operational control’ so you can assign those facilities to the proper emissions categories.. When a company’s data architecture isn’t set up for this level of granularity, teams are forced to go back and manually revisit hundreds of outstanding contracts. What should take a minute to encode upfront easily turns into a multi-month project just to find the proper data sources. When you wait to build the system, you force your teams to look backward instead of forward. What You Need to Check Today The fix is actively bridging the technical gap. You need professionals who can translate complex sustainability metrics into an accounting standard, and vice versa. If you are a CFO or sustainability leader reading this today, before making your next public ESG commitment, take a hard look at your architecture. Ask yourself these three questions: Are my on-book activities scoped properly? Check if all financial transactions have been mapped to the appropriate ESG requirement. Are my off-book activities accounted for? Ensure your people management, technology, and operational data are fully captured. Are all stakeholders involved? If ESG reporting is falling entirely on your Finance team, or solely on your ESG team without Finance’s oversight, you have a translation gap. Operations, HR, and Tech must understand the why and the how of the data they are providing. A calm, predictable reporting cycle is designed, never improvised. Build the data architecture a year or two before the regulations hit, and ensure your financial execution naturally supports confident sustainability reporting.

Read More >
Blogs

Sustainable Spaces: From Compliance to Commitment

Sustainable Spaces: From Compliance to Commitment

Climate change is a pressing issue, and the building and construction sector is a major contributor. A staggering 40% of energy-related CO2 emissions come from buildings, and, according to the UN Environment Programme’s 2022 Global Status Report for Buildings and Construction, the industry falls short of decarbonization targets, with CO2 emissions currently reaching new highs. From materials used to construction practices and daily operations, traditional methods take a toll on the environment. Sustainable building—architecture focusing on environmental responsibility—offers a solution. Looking for Innovative Solutions for a Rapidly Changing ESG Landscape? Click here! Building Green: A New Approach Sustainable design is about creating buildings that meet the needs of the present without compromising the ability of future generations to meet their own needs. Its key principles include: Eco-friendly materials: Responsibly harvested wood, recycled steel, and locally sourced materials reduce embodied carbon and transportation emissions. Innovations like carbon-neutral concrete further reduce environmental impact. Energy-efficient glasses in façades minimize heat gain and reliance on cooling and lighting. Passive & active design strategies: Passive strategies utilize natural elements for energy efficiency and comfort. Daylighting, natural ventilation, and well-insulated walls and roofs improve energy efficiency and resource optimization. On the other hand, active design utilizes technologies like solar panels and wind turbines to generate electricity, working alongside passive strategies for a more sustainable future. Water conservation: Rainwater harvesting systems, low-flow fixtures, and efficient irrigation minimize freshwater demand and water wastage, preserving resources and cutting costs. Sustainable Leaders Around the Globe Many companies are embracing sustainable practices, showcasing the power of green building. Some prominent examples are: Apple Park (Cupertino, California): Features one of the largest on-site solar installations globally, alongside natural cooling systems and extensive green spaces. Googleplex (Mountain View, California): Utilizes solar power, recycled water for irrigation, and a building management system that monitors energy use. Pixel Building (Melbourne, Australia): Australia’s first carbon-neutral office building boasts efficient daylighting, wastewater processing, and a recycled aluminum façade. Bank of America Tower (New York City, New York): Uses 32% less energy than a typical office tower. Abundant daylighting, district-chilled water for cooling, and a green roof prioritize energy efficiency and resource conservation. The Edge (Amsterdam, Netherlands): Cutting-edge energy efficiency and occupant comfort technologies include a “digital ceiling” with sensors optimizing lighting and an aquifer-based temperature regulation system. Global Standards and Certifications Transitioning to sustainable spaces can unlock exciting opportunities, such as attracting investment from environmentally conscious businesses and consumers. Sustainable building practices are not just good for the planet but also good for business and several frameworks exist to guide the design and construction of sustainable spaces: LEED (Leadership in Energy and Environmental Design): A comprehensive framework for designing, constructing, and operating green buildings. It evaluates energy efficiency, water conservation, and indoor environmental quality. BREEAM (Building Research Establishment Environmental Assessment Method) : Evaluates energy, materials, ecology, and water usage, promoting sustainable material usage and energy-efficient systems. WELL Building Standard: Prioritizes air and water quality, user well-being, and environmental sustainability for healthier buildings. Living Building Challenge: The most rigorous standard for sustainability, it emphasizes regenerative design principles, reducing energy consumption, and promoting on-site water harvesting. By prioritizing sustainable design principles, utilizing innovative materials and technologies, and adhering to global green building standards, we can transform our physical environment into a responsible and regenerative force for a healthier planet. This transition not only benefits the environment but fosters economic growth in new and innovative ways.

Read More >

Contact Information

SF Bay Area Headquarters
111 Anza Boulevard, Suite 320, Burlingame, CA 94010, United States

Phone: (800)837-5160
Email: [email protected]

"Scrubbed" is the brand name under which Scrubbed Advisory, LLC and Scrubbed Assurance, LLP provide professional services. Scrubbed Advisory, LLC and Scrubbed Assurance, LLP practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. Scrubbed Assurance, LLP is a licensed independent CPA firm that provides attest services to its clients, and Scrubbed Advisory, LLC provides tax, finance, and support services to its clients. Scrubbed Advisory, LLC is not a licensed CPA firm.

Copyright © Scrubbed. All rights reserved.