[ THREAT ARCHIVE :: 2021 ]
EXPOSURE SCALE: 700,000,000+ RECORDS
LinkedIn 2021 Exfiltration — What Was Leaked & How to Check If You're In It
In June 2021, threat actor "TomLiner" posted a sample of 1M records on RaidForums, subsequently auctioning a full database containing over 700 million LinkedIn user profiles exfiltrated via abused developer APIs.
INCIDENT YEAR: 2021
ATTACK VECTOR: API Scraping & Insecure Direct Object Reference (IDOR)
SEVERITY RATING: HIGH
> COMPROMISED DATA ATTRIBUTES IN THIS BREACH:
[✓] Full Names
[✓] Email Addresses
[✓] Phone Numbers
[✓] Physical Addresses
[✓] Geolocation Records
[✓] LinkedIn Profile URLs
[✓] Salaries & Job Titles
> TECHNICAL POST-MORTEM & VECTOR ANALYSIS
- The adversary utilized automated distributed scrapers exploiting unthrottled LinkedIn REST APIs to harvest user records.
- While plain-text passwords were not exposed, the combination of verified work emails, phone numbers, and job titles catalyzed thousands of targeted spear-phishing campaigns.
- Records from this dump were subsequently merged into the Combatting Online Malicious Activity (COMB) combolist.
> VERIFY IF YOUR CREDENTIALS APPEARED IN THIS DUMP
Query the DARKLEDGER multi-source engine to check if your email, username, or phone number was indexed in the LinkedIn 2021 Exfiltration dataset.
> STEP-BY-STEP REMEDIATION PLAYBOOK
- Enter your primary professional and personal email into the DARKLEDGER zero-knowledge scanner below.
- Check if your associated phone numbers were linked to LinkedIn corporate profiles.
- Rotate your corporate password and enable Hardware 2FA (FIDO2 / WebAuthn) on all professional accounts.
> FREQUENTLY ASKED QUESTIONS ABOUT THIS BREACH
Q: Were passwords leaked in the LinkedIn 2021 breach?
No plain-text passwords or bcrypt hashes were included in the 2021 scrape. However, full names, emails, phones, and workplace data were completely exposed.
Q: How do I know if my LinkedIn account was in the 2021 scrape?
Enter your email into our free scanner below to query the indexed 700M archive.