[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2ipoiapy5t3cp":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":4,"isMalware":38,"company":39},"68e3266eda11adda48825278","LinkedInScrape2023","LinkedIn Scraped and Faked Data (2023)","linkedin-scraped-and-faked-data-2023","linkedin.com","2023-11-04T00:00:00.000Z","2023-11-07T07:12:02.000Z","2024-06-04T19:46:37.000Z","2026-07-19T21:23:15.480Z","Unknown","https:\u002F\u002Fwww.troyhunt.com\u002Fhackers-scrapers-fakers-whats-really-inside-the-latest-linkedin-dataset\u002F",[16,18,19],"https:\u002F\u002Fnews.linkedin.com\u002F2021\u002Fjune\u002Fan-update-from-linkedin","https:\u002F\u002Fwww.linkedin.com\u002Flegal\u002Fuser-agreement",19788753,"known",null,"email_identifiers","Critical",[26,27,28,29,30,31,32],"Email addresses","Genders","Geographic locations","Job titles","Names","Professional skills","Social media profiles","\u003Cp>\u003Cstrong>The 2023 dataset associated with LinkedIn\u003C\u002Fstrong> is a mixed scraping and generation list containing 19,788,753 email identifiers.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>\u003Cstrong>The listed data classes\u003C\u002Fstrong> are email addresses, names, genders, geographic locations, job titles, professional skills and social-media profiles. names, employers, titles, skills and profile links are largely genuine data scraped from public profiles, while a substantial proportion of the email addresses were algorithmically generated by combining a person's name with an employer's domain. Every listed address must not therefore be assumed to exist or receive mail. Passwords, private messages, phone numbers and LinkedIn's access-controlled internal account data are not among the confirmed classes for this event. The 19,788,753 figure on this page represents unique email strings, not the number of genuine LinkedIn accounts or compromised mailboxes.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The first claim appeared on 4 November 2023 under the name “LinkedIn Database 2023” and referred to roughly 2.5 million profile records. On 7 November, the same actor posted a larger package claimed to contain 35 million lines. Detailed analysis found genuine LinkedIn profile identifiers and public professional fields alongside emails created by applying the same name pattern to unrelated company domains. The final canonical catalogue contains 19,788,753 unique email identifiers and is flagged as a spam list because of its mixed composition. The entry is not entirely fabricated: it contains real addresses that completed double opt-in and almost one million addresses already observed in other datasets. Those findings do not establish that LinkedIn systems were hacked in 2023, that a password database was accessed or that private member data was extracted.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People at greatest risk are those whose public LinkedIn profiles identify an employer, job title, location or skills and whose corporate email pattern is easy to predict. Even when a generated address does not exist, the association between a real name, company and role can support targeted phishing and social engineering. People whose genuine address appears in the list may receive fake recruitment messages, partnership proposals, invoice requests, file-sharing notifications or sign-in alerts. If a company domain accepts mail through a catch-all configuration, algorithmically generated addresses may be deliverable even when they were never assigned to a particular employee, bringing unwanted messages into the corporate system. Appearing in the list does not prove that a person's LinkedIn account was accessed, password stolen or mailbox compromised. \u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>\u003Cstrong>Your first step\u003C\u002Fstrong> is to establish whether the matched email address genuinely belongs to you and can receive mail. It may have been generated only from your name and a current or former employer's domain; if the mailbox never existed, do not interpret the match as an account compromise. If the address is real, be alert to unexpected recruitment, file-sharing, password-reset and corporate sign-in messages. Enable multi-factor authentication on email and LinkedIn accounts, then review active sessions and recovery options. Passwords are not present in this dataset, so changing every password solely because of this match is not required; replacing weak or reused passwords with unique values remains good security practice. Corporate security teams should monitor mail sent to nonexistent but predictable addresses, catch-all behavior and domains that imitate the organization.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Balance the professional information needed to describe your work against details that make impersonation easier. Do not place personal email addresses, phone numbers or full street addresses in public profile text, and review contact visibility and profile-discovery settings regularly. Organizations should avoid publishing employee email patterns unnecessarily, deploy SPF, DKIM and DMARC policies and monitor registrations of look-alike domains. Train employees that a message containing an accurate name and job title is not proof that the sender is legitimate. LinkedIn's terms prohibit using automated tools to scrape or copy profiles and service data; information visible to the public is not automatically authorized for bulk redistribution. Continuous breach alerts and domain monitoring help identify when genuine or generated addresses appear in later lists.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>To determine whether you appear in this record, check current and former corporate email addresses separately through a trusted data-exposure search. After a match, establish whether the address was ever created, when it was used and whether the employer relationship in the result is accurate. The result may mean that public profile information was collected or that an address was guessed from your name; it does not mean that your LinkedIn account or mailbox was breached. Even when a matched address never existed, the presence of your real name, company or career history in a bulk file means targeted fraud risk should not be ignored completely. Report the finding to the security team without redistributing personal information and retain suspicious message samples with their header data. Do not query another person's address without permission; use results only to protect your own accounts or organizational domains you are authorized to administer.\u003C\u002Fp>","","LinkedIn Scraped and Faked Data (2023) (19.8 Million Email Identifiers)","LinkedIn Scraped and Faked Data (2023). 19.8 Million email identifiers were reported. Reported data: Email addresses, Genders, Geographic locations. Review…","\u002Fuploads\u002Flogo\u002Flinkedin_com.webp",false,{"name":40,"sector":41,"country":42,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":22},"LinkedIn-associated scraped dataset","Other","Global"]