# LinkedInScrape

WHAT HAPPENED

In the first half of 2021, attackers collected data from hundreds of millions of
public LinkedIn profiles
[https://www.businessinsider.com.au/linkedin-data-scraped-500-million-users-for-sale-online-2021-4] and
later sold it online.

This was not a traditional data breach because the data came from public
profiles, not private LinkedIn systems.

Still, the information was shared widely in hacking communities. The scraped
data included about 400 million records, with 125 million unique email
addresses, as well as names, locations, genders, and job titles.


HOW TO STAY SAFE

 1. Go to https://www.linkedin.com/ [https://www.linkedin.com/]

 2. Click “Sign in“

 3. Click “Forgot Password?“

 4. Enter your email

 5. Click “Next“

 6. Enter the 6-digit code from email

 7. Click “Submit“

 8. Create a new password and repeat it

 9. Click “Submit“

Also, turn on Two-Factor Authentication, so your account is harder to access
even if your password is compromised again in the future. 


HERE’S HOW TO TURN ON 2FA:

 1.  Click “Me” in the top right-hand corner of your LinkedIn profile

 2.  Click “Settings & Privacy“

 3.  Click “Sign in & security“

 4.  Click “Two-factor authentication“

 5.  Click “Set up“

 6.  Enter the 6-digit code from email

 7.  Click “Submit“

 8.  Choose “Phone Number (SMS)“ from drop down

 9.  Click “Continue“

 10. Enter phone number and password

 11. Click “Send code“

 12. Enter the 6-digit code from SMS

 13. Click “Authenticate“

Also, be careful with unexpected messages about jobs, recruiters, business
offers, or LinkedIn profile updates. 

Since this breach included email addresses, names, locations, genders, and job
titles, scammers could use these details to make messages feel personal and
professional.


WHY THIS BREACH MATTERS

Even though this breach happened back in 2021, leaked data doesn't just expire.
It keeps getting bought, sold, and reused by scammers. 

And even if you've never used this exact site before, your email may have still
ended up in it through a partner, data broker, or another service behind the
scenes. 

If you've ever reused this password anywhere else, it's worth taking a minute to
secure it now.