Data breach
- Records
- 400,100,434
- Breach date
- 8 April 2021Estimated
- Added
- 1 December 2024
What was exposed
17 types of data · 2 more reported
- Education history1
- End date1
- Grades1
- Majors1
- Minors1
- Schools1
- Start date1
- Summary1
- Qualifications1
- Email addresses1
- Facebook profiles1
- Names1
- GitHub profiles1
- Home addresses1
- Interests1
- Phone numbers1
- X / Twitter profiles1
- GenderReported, not counted
- SalariesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
A large dataset tied to LinkedIn profiles surfaced for sale on a hacking forum in 2021, and our investigation team has indexed it as part of this listing. The dataset contains more than 400 million records, with an estimated breach date of April 8, 2021. LinkedIn has disputed that a breach occurred, saying the data was scraped and aggregated rather than stolen from its systems. The company acknowledged in public statements that the dataset includes information scraped from LinkedIn along with data obtained from other websites.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
Breach Timeline
April 6, 2021: CyberNews reported that data taken from roughly 500 million LinkedIn profiles was listed for sale on a well-known hacker forum.
April 8, 2021: LinkedIn published a statement describing the April incident as scraped, publicly viewable profile data combined with information from other websites, and said it was not a data breach.
June 22, 2021: A seller using the name TomLiner began advertising a database of 700 million LinkedIn user records on the Raid Forums marketplace, according to SiliconAngle, including a sample of one million records.
June 29, 2021: LinkedIn responded that the newly offered dataset was not a breach, that no private member data was exposed, and that it included the same data covered in its April 2021 scraping update.
What Information Was Compromised?
Our analysis found the following data types in this breach: email addresses, phone numbers, names, home addresses, interests, and education details, including education names, types, majors, minors, grade point averages, summaries, and start and end dates. The dataset also included usernames or handles for GitHub, Twitter, and Facebook accounts.
Reporting on the sample data adds further context. BBC News, citing researchers who examined a free sample, reported that it included full names, email addresses, gender, phone numbers, and industry information. Fortune reported that the data examined did not include login credentials or financial information, but did include details useful for impersonating someone, and that LinkedIn said phone numbers, gender, inferred salary, and physical addresses in the dataset did not come from LinkedIn.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
This dataset is not a password dump, so direct account takeover is less likely than in credential breaches. The risks are different but real. With an email address, phone number, employer, education history, and social media handles combined, criminals can build convincing profiles of individuals. That supports targeted phishing, in which a scammer references your job or workplace to appear credible. It also enables smishing, or text message fraud, because phone numbers are included.
Home addresses and inferred salary data raise the stakes further. These details can support identity fraud, scams aimed at your workplace or clients, and in some cases physical harassment or stalking. Because the data covers hundreds of millions of people, it can circulate widely and resurface in future breach compilations even years later.
What Is LinkedIn Doing in Response?
LinkedIn investigated both the April and June 2021 listings and stated publicly that no private member data was exposed and no breach of its systems occurred. The company said scraping violates its terms of service and that it works to stop and hold accountable those who take member data without permission. LinkedIn also told Fortune that its investigation found no evidence the data was new or from 2020 and 2021.
What Should You Do If You Were Affected?
Be skeptical of unexpected emails or texts that reference your job, employer, or professional background, even when they know personal details.
Never click links or enter credentials in unsolicited messages; go to linkedin.com directly instead.
Turn on two-factor authentication for LinkedIn and any account tied to the exposed email address.
Use a unique password for every account, and consider a password manager to keep them separate.
Watch your financial statements and credit reports for unexplained activity, since addresses and personal details are exposed.
In the news
- LinkedIn newsroom statement on scraped datanews.linkedin.com (opens in a new tab)
- Reuters: LinkedIn says some user data scraped and posted for salereuters.com (opens in a new tab)
- BBC News: How your personal data is being scraped from social mediabbc.com (opens in a new tab)
- SiliconAngle: Database of 700M LinkedIn users found for sale on a hacking forumsiliconangle.com (opens in a new tab)
- Fortune: LinkedIn data theft exposes personal information of 700 million usersfortune.com
