In November, Britain's Secret Intelligence Service (MI5) warned MPs and their staff about an audacious foreign espionage plot. According to the service, two fake LinkedIn profiles were approaching people active in British politics, attempting to extract "confidential inside information."
The MI5 revelations led the government to launch a £170 million initiative to tackle spying threats to Parliament.
“This may be the latest high-profile case of malicious actors exploiting LinkedIn to further their ends, but it is by no means the first,” explains Phil Muncaster from the team at global cybersecurity firm ESET.
In this context, he recalls some characteristic incidents:
"Members of Lazarus team North Korean recruiters have appeared on LinkedIn with the aim of installing malware on employees of aerospace companies, according to ESET Research. Researchers also recently described the Wagemole IT worker campaigns, in which individuals with ties to North Korea try to find work at companies abroad.
Correspondingly, in another case, team member scattered Spider pretended to be an MGM employee, using information gleaned from LinkedIn, to trick the support department. The ensuing ransomware attack caused $100 million in damages.
And let's not forget the Ducktail spear-phishing campaign "which targeted marketing and HR professionals via malicious links in private messages, with malware hosted in the cloud," notes Muncaster, emphasizing that "The platform is also a treasure trove of corporate data that can be exploited for fraud or threat campaigns. It's time for professionals to realize the risks posed by digital professional networks."
Why the LinkedIn is it a target?
LinkedIn has amassed more than a billion members worldwide since its founding in 2003. That translates into a huge number of potential targets for state-sponsored or financially motivated threat actors. But why is the platform so attractive to them?
- It is a rich source of information: Through LinkedIn, perpetrators can track roles and responsibilities of key executives of a target company. At the same time, they can form a fairly accurate picture of the professional relationships and projects these individuals are involved in. This information is particularly valuable for spear-phishing attacks and Business Email Compromise (BEC) scams.
- It offers reliability and coverage: As a professional network, LinkedIn is home to both top executives and lower-level employees. Both types of employees can be useful to a threat actor. Victims are often more willing to open a private message or InMail on LinkedIn than an unsolicited email. In the case of senior executives, it may be the only way to communicate directly, as company emails are often checked by assistants.
- Bypassing "traditional" security: LinkedIn messages are routed through the platform’s servers rather than through corporate email systems, which limits visibility for IT departments. While LinkedIn has built-in security measures, there’s no guarantee that phishing, malware, or spam messages won’t reach users. Additionally, the platform’s perceived trustworthiness often makes targets more likely to click on malicious links.
- Ease of use and operation: The potential ROI for attacks via LinkedIn is high. Anyone can create a profile and start collecting information or sending phishing and BEC messages. Attacks can be automated on a large scale, and the abundance of compromised credentials circulating on online forums (often thanks to infostealer malware) makes easier than ever taking over accounts or creating convincing false identities.
The most frequent attacks
As mentioned, there are several ways threat actors can carry out their malicious campaigns through LinkedIn. These include:
- Phishing and spearphishing: Customized attacks based on information from user profiles.
- Direct attacks: Sending malicious links designed to install malware, such as infostealers, fake job advertisements, or attempts to harvest credentials. In some cases, state-backed actors target individuals with access to “inside information,” as MI5 has warned.
- Business Email Compromise: LinkedIn provides a wealth of information that can then be used to BEC attacks (cybercriminals pretend to be high-ranking executives or associates) more convincing. It can help fraudsters create the organizational chart of the company's internal structure, the projects being implemented, and the names of partners or suppliers.
- Deepfakes: Using LinkedIn videos to create fake audiovisual materials exploited in further phishing, BEC or social media scams.
- Accounts receivable: Through phishing pages, infostealers, and credential stuffing, perpetrators gain access to accounts and then target their contacts.
- Attacks on suppliers: Identifying a company's partners for "stepping stone" attacks, where the attacker uses intermediary, compromised organizations.
Stay safe on LinkedIn
The main challenge with LinkedIn threats is that IT departments struggle to get a complete picture of the threats employees face. However, scenarios like the ones above should be incorporated into security awareness training programs.
Employees should avoid oversharing information, learn to recognize fake accounts and typical phishing techniques, and follow basic cybersecurity practices: regular software updates, installing security software from a trusted provider, and enabling multi-factor authentication. Special emphasis should be placed on training senior executives, who are often prime targets.
Above all, it is critical for users to understand that even on a seemingly trustworthy professional network like LinkedIn, not everyone has the best intentions.
Although the press releases will range from very select to rare, I said I'd pass...because sometimes the editors hide.

