Cybersecurity researchers estimate LinkedIn accounts for roughly 18% of reported social media account takeovers — a disproportionately high share given LinkedIn's smaller user base compared to Instagram or Facebook. That imbalance reflects how valuable a hijacked professional profile is for attackers: it's not just embarrassing photos or a private feed at stake, it's a ready-made launchpad for business email compromise (BEC) scams and targeted spear-phishing against your employer, colleagues, and connections. A hacker posting from your real LinkedIn account, with your real job title and your real network attached, is far more convincing than a random cold email ever could be.
That's what makes a LinkedIn hack uniquely dangerous compared to other social platforms. Attackers use compromised LinkedIn accounts to send fake job offers to your connections (often with malware-laced "offer letter" attachments), impersonate you in DMs to request money transfers or gift cards from colleagues who trust your name, scrape your connection list to build target lists for further phishing, and quietly damage the professional reputation you've spent years building — all before you even notice something is wrong. If you manage a Company Page as an admin, the blast radius extends to your entire business's public presence.
This guide walks through exactly what to do, in order, whether you still have partial access to your account or you're completely locked out. It covers LinkedIn's real, official recovery channels — not shortcuts, not third-party "recovery services," and not anything that requires handing your credentials to anyone but LinkedIn itself.
Unlike a hacked Instagram or TikTok account, where the worst-case outcome is usually embarrassing content or lost followers, a hacked LinkedIn account carries real business and financial risk for the people around you. Your connections have been trained — by years of legitimate use — to trust messages that appear to come from you specifically because LinkedIn is a professional context. That built-in trust is exactly what attackers exploit, and it's why recovering the account quickly and then actively warning your network matters just as much as locking the account down.
One important honesty note before you start
No IT company — including IT Cares — can log into LinkedIn on your behalf or bypass LinkedIn's identity verification. Only you can complete LinkedIn's own recovery process, because it's specifically designed so that nobody else can claim your account. What a technician can help with is everything around the hack: removing malware or a keylogger that may have stolen your password in the first place, setting up two-factor authentication correctly across all your business accounts, and hardening your devices so it doesn't happen again. Keep that distinction in mind as you read the rest of this guide.
Signs Your LinkedIn Account Has Been Hacked
Before jumping to recovery steps, confirm what you're actually dealing with. Not every strange notification means a full takeover — sometimes it's a legitimate new device sign-in you forgot about. Here's how to tell the difference.
| Warning Sign | What It Usually Means |
|---|---|
| Posts, articles, or comments you didn't write | Someone else has active access and is using your account to spread spam or scam links |
| Connection requests sent to strangers | Automated bot behavior — a common early sign of compromise before the attacker changes your password |
| Messages your real contacts say they received from you | Highest-priority sign — the account is actively being used for BEC or phishing against your network |
| Profile photo, headline, or summary changed | Attacker is rebuilding your profile to impersonate you more convincingly, or preparing to sell the account |
| "New sign-in" email from an unfamiliar city or country | Could be an early warning (you still have time to act) or confirmation the attacker is already in |
| Your password no longer works | The attacker has already changed it — you need the official compromised-account recovery process, not "Forgot password" |
| Your account email was changed | Full takeover — this is the most serious scenario and requires LinkedIn's identity verification to reverse |
If you're seeing any of the first five signs but can still log in normally, you're in the early-stage compromise category — move fast, because you still have the advantage. If your password or email no longer works, you're fully locked out and need to jump straight to the official recovery form covered further down.
What Attackers Actually Do With a Hacked LinkedIn Account
It helps to understand the actual motive, because it explains why speed matters so much. A hacked Instagram account is usually just posted-through for spam links. A hacked LinkedIn account is a far more valuable asset, and attackers typically move through a predictable playbook:
Business email compromise (BEC) setup. Your LinkedIn profile confirms your real name, real job title, and real employer to anyone who looks — information attackers use to craft a convincing "CEO fraud" or "vendor impersonation" email once they know exactly who reports to whom inside your company. A compromised LinkedIn account often isn't the final target; it's reconnaissance and social proof for a bigger email-based scam that follows days or weeks later.
Fake job offers sent to your connections. One of the most common patterns we see: the attacker messages dozens of your connections with a "job opportunity" that includes a malicious attachment or link disguised as an offer letter or job description. Because it comes from your real, verified account, recipients are far more likely to open it than they would a job offer from a stranger.
Direct requests for money or gift cards. Attackers impersonate you in DMs to close colleagues or clients, asking for an "urgent" wire transfer, gift card purchase, or invoice payment — a classic pretexting scam that works specifically because it appears to come from someone the recipient already trusts professionally.
Harvesting your connection list for future attacks. Even if the attacker never sends a single message, simply scraping your hundreds or thousands of connections gives them a high-quality target list of real names, real job titles, and real companies for future spear-phishing campaigns — against you and against everyone you're connected to.
Reselling the account itself. Aged LinkedIn accounts with an established connection count, a complete work history, and a clean reputation are traded on underground marketplaces specifically because they're useful for running long-term scams or fake-recruiter operations without raising suspicion. The older and more "legitimate-looking" your profile, the more valuable it is to a buyer.
Worried malware stole your password in the first place?
Our certified bilingual technician remotes in, scans for keyloggers and info-stealers, and hardens your device and business accounts against the next attempt — same day, from $119.99. No fix, no fee.
9 Steps to Recover a Hacked LinkedIn Account
If You Still Have Access: End Every Unrecognized Session Immediately
Speed matters more than anything else at this stage. Go to Settings & Privacy > Sign-in & security > Where you're signed in. LinkedIn lists every active session by device type, approximate location, and last-active time. For any entry you don't recognize, select "End these sessions." This immediately kicks the attacker out of your account on their end, buying you time to lock everything down before they can do more damage or change your password themselves. Do this step before anything else — even before reading further in this guide.
Change Your Password to a Unique, 12+ Character Password
Immediately after ending sessions, go to Settings & Privacy > Sign-in & security > Password and set a new one. It needs to be at least 12 characters and must not be reused from any other account — password reuse is one of the top reasons professional accounts get compromised in the first place, since a breach on an unrelated site gives attackers your LinkedIn credentials for free via "credential stuffing." Use a password manager to generate and store a truly random password rather than a variation of something memorable.
Enable Two-Step Verification
Still under Settings & Privacy > Sign-in & security, find Two-step verification and turn it on. LinkedIn supports authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) and SMS-based codes — an authenticator app is the stronger option since SMS can be intercepted via SIM-swapping. Once enabled, a stolen password alone is no longer enough for someone to get back in, since they'd also need your second factor. This single step blocks the overwhelming majority of follow-up attack attempts.
If You're Locked Out: Go Straight to LinkedIn's Official Compromised-Account Form
If your password no longer works and "Forgot password" isn't getting you anywhere, stop trying the normal login flow. Go directly to LinkedIn's "Report a Compromised Account" help page and the Report Unauthorized Account Access or Changes form, both reached at linkedin.com/help/linkedin/answer/a1340402. This is LinkedIn's dedicated channel for exactly this situation, separate from the standard login troubleshooting flow. If you still remember your own profile URL (e.g. linkedin.com/in/yourname), include it in the form — it speeds up verification significantly because it helps LinkedIn's review team locate the specific account and confirm it belongs to you, even though you can no longer log into it.
Start the Process From a Device and Network You've Used Before
Before you submit the compromised-account form, think about where you're doing it from. Starting the recovery process on a device, browser, and Wi-Fi network you've successfully signed in from before is genuinely useful — a recognized environment is less likely to trigger extra friction or be treated with suspicion compared to a brand-new device on unfamiliar Wi-Fi (say, a borrowed laptop at a coffee shop). If possible, use your usual work or home computer and your normal internet connection rather than a public network or a device you've never used with LinkedIn.
Complete Identity Verification (QR Code + Government ID)
For accounts where the attacker changed the recovery email or where LinkedIn's system flags unusual activity, the recovery flow will prompt you to "Verify your identity." This step typically involves scanning a QR code with your smartphone and then uploading a clear photo of a valid government-issued ID — a passport, driver's license, or national ID card. This exists specifically to stop an attacker (or anyone else) from claiming a compromised account by simply answering security questions. Only ever complete this step inside LinkedIn's own official recovery flow that you initiated yourself at linkedin.com — never in response to an unsolicited "verify your account now" email or text, which is a common phishing technique built to mimic this exact process.
Warn Your Network About What Happened
The moment you regain access, assume the attacker sent messages or connection requests to at least some of your real contacts while they had control. Post a short, clear update on your feed explaining the account was compromised and that any strange messages, job offers, or links sent during that window did not come from you. Then directly message any close colleagues, clients, or connections who are likely to have received something — a quick heads-up prevents them from clicking a malicious link or wiring money based on a fake request that appeared to come from someone they trust. This step matters most for business owners and recruiters, whose contacts are more likely to act on a "trusted" message.
Review Everything the Attacker May Have Touched
Once you're back in, do a full audit before considering the incident closed. Check Settings & Privacy > Sign-in & security for any new email addresses, phone numbers, or connected apps added without your knowledge and remove them. Review your Sent messages folder for anything you didn't write. Check your posts and articles for spam content and delete it. Review your connections list for accounts you don't recognize accepting new requests. If you use LinkedIn Premium, Recruiter, or Sales Navigator, verify no saved searches, InMail credits, or candidate pipelines were tampered with or exported — these paid tools hold business-sensitive data that's worth a specific check.
Keep Watching Your Email During and After the Review
LinkedIn's compromised-account review process is not instant, and it isn't always a single email either — you may receive a request for additional information, a confirmation that access has been restored, or a follow-up notice about further account security steps. Keep watching the email address tied to the account closely during this period, including your spam folder, so you don't miss a time-sensitive request from LinkedIn's review team that could delay your recovery further.
If you're an admin of a Company Page
A compromised personal account that also has admin rights on a business Company Page puts the Page itself at risk — an attacker with admin access could post as your company, message leads under your business's name, or add other admins of their own. As soon as your personal account is secure again, go to the Page's Admin settings > Manage admins and remove anyone you don't recognize. If another trusted admin still has access while you're locked out, have them check the admin list immediately rather than waiting for your recovery to complete. Going forward, always keep at least two trusted people as Page admins so a single compromised account never leaves the Page unmanaged.
Should You Tell Your Employer or IT Department?
If you use LinkedIn in a professional capacity — which is essentially the point of the platform — a compromise is not purely a personal matter, and treating it as one can leave real gaps. If your company's name, clients, or colleagues were referenced in any message the attacker sent, or if you suspect the compromise originated from a work device, notify your employer's IT or security team as soon as you've secured the account. This isn't about assigning blame; it's about giving your organization a chance to warn other employees who may receive a follow-up phishing attempt built on information the attacker gathered from your account, and to check whether the same credentials were reused anywhere inside company systems.
For solo business owners and freelancers without a formal IT department, the equivalent step is simply being transparent with any business partners, close clients, or collaborators who might reasonably be targeted next using details scraped from your account — such as project names, mutual connections, or ongoing deals visible in your message history. A two-line heads-up email takes a minute and can prevent a much more costly follow-up scam against someone you work with.
How LinkedIn Accounts Actually Get Hacked
Understanding the entry point matters, because recovering the account without fixing the entry point just invites a repeat. The most common causes we see:
Fake "LinkedIn security alert" phishing emails. These are extremely common and mimic LinkedIn's real notification design closely — same logo placement, same "You have a new sign-in" or "Your account was flagged" wording, same blue call-to-action button. The link goes to a look-alike login page that captures your real username and password the moment you type them in. Always check the actual sender domain (it should end in linkedin.com, not a look-alike) and hover over links before clicking — or better, skip the email link entirely and type linkedin.com into your browser directly.
Reused passwords exposed in unrelated data breaches. If you used the same password on LinkedIn and on some other site that later got breached, attackers run automated "credential stuffing" tools that try millions of leaked username/password combinations across major platforms, including LinkedIn, until one works.
Malware and keyloggers on your device. Info-stealing malware that logs keystrokes or steals saved browser passwords is a growing cause of professional account takeovers, especially on personal devices used for both work and browsing. This is exactly the scenario where a device-level security check — not a password change alone — is the real fix, since changing your password on an infected device just hands the attacker your new password too.
Fake job-offer or recruiter DMs with malicious attachments. Attackers impersonate recruiters or hiring managers and send a "job description" or "offer letter" file that installs malware when opened, sometimes specifically to harvest LinkedIn session cookies that bypass the login screen entirely.
Over-permissioned third-party apps and browser extensions. Career tools, resume builders, and "auto-apply" browser extensions that ask you to connect your LinkedIn account sometimes request far more access than they need. A malicious or poorly secured third-party app with an active OAuth connection to your LinkedIn account can be used to post, message, or read your data without ever needing your password at all. Periodically review Settings & Privacy > Data privacy > Permitted services and revoke anything you no longer use or don't recognize.
Session hijacking on public Wi-Fi. On unsecured public networks (airports, cafes, conference venues — all common for professionals who travel for work), it's possible for an attacker on the same network to intercept an active login session rather than needing your password directly. This is a lower-frequency cause than phishing or reused passwords, but it's a real risk for frequent business travelers, and a VPN largely eliminates it.
Anatomy of a Fake "LinkedIn Security Alert" Phishing Email
Because this is the single most common entry point, it deserves a closer look. A convincing fake LinkedIn security email typically checks every visual box: the LinkedIn blue color scheme, a familiar logo, professional formatting, and urgent-but-plausible subject lines like "New sign-in to your LinkedIn account," "We've restricted your account," or "Verify your identity to keep your account active." The email body often includes a real-looking device name, city, and timestamp to add credibility, then a large blue button reading "Review Activity" or "Secure My Account."
The tell is almost never in the visual design — it's in the details most people don't check. Before clicking anything in a LinkedIn security email, verify: the sender's actual email domain (hover over or tap the sender name — it must end in an official linkedin.com address, not a look-alike domain with extra characters or a different top-level domain); whether the email creates artificial urgency ("your account will be permanently disabled in 24 hours" is a pressure tactic real security teams rarely use in this exact wording); and whether the link destination shown when you hover over the button actually points to linkedin.com rather than a similar-looking domain. When in doubt, don't click the email link at all — open a new browser tab, type linkedin.com manually, and check your notifications and security settings directly from there.
Secure Your Devices and Business Accounts After a Hack
IT Cares can't log into LinkedIn for you, but we can find and remove the malware or keylogger that stole your password, set up two-factor authentication correctly across your business accounts, and harden your devices so this doesn't happen again. Remote sessions available same-day.
Protecting Premium, Recruiter, and Sales Navigator Accounts
If your LinkedIn account carries a paid subscription tier, the stakes of a compromise go up considerably, because these tools hold data and paid credits that are directly valuable to an attacker or a competitor. LinkedIn Recruiter accounts contain saved candidate pipelines, private notes on candidates, and InMail credits that can be spent sending messages under your name before you even notice they're gone. Sales Navigator accounts hold saved lead lists and account mapping that represent real business development work — if a competitor gained access, that pipeline data has real commercial value. LinkedIn Premium Career and Premium Business subscriptions include "Who's Viewed Your Profile" history and InMail credits that are similarly exposed.
After regaining access to a business-tier account, don't stop at the standard checks in Step 8. Specifically review your InMail credit balance and sent InMail history for messages you didn't send, export or screenshot your saved lead lists and candidate pipelines as a backup in case anything was deleted or altered, and check the billing section to confirm no subscription changes or renewals were made without your knowledge. If your company pays for a LinkedIn Recruiter or Sales Navigator seat through a centralized admin (common in larger sales and HR teams), loop in whoever manages that contract immediately — they may need to review audit logs on their end that aren't visible from your individual account.
What NOT to Do During Recovery
A few reactions are understandable but counterproductive, and worth naming directly:
Don't pay a third-party "account recovery service." Search results and social media ads sometimes surface services promising guaranteed, fast LinkedIn account recovery for a fee. LinkedIn does not use or endorse any third-party paid recovery process — the only legitimate path is the official form at linkedin.com/help/linkedin/answer/a1340402. Paying a stranger for "recovery help" typically means handing over even more personal information to a second bad actor.
Don't delete the account out of frustration. If you're locked out and tempted to just create a brand-new profile from scratch, consider that your original account holds years of connections, recommendations, and work history that generally cannot be transferred. Pursue recovery of the original account first; only consider starting fresh as a genuine last resort.
Don't skip warning your network because it feels embarrassing. Business owners in particular sometimes hesitate to publicly acknowledge a hack out of concern for how it looks. In practice, a short, factual post explaining the account was compromised reads as responsible, not careless — and it's the single most effective way to stop a colleague or client from acting on a fraudulent message before you can reach them individually.
How to Prevent It From Happening Again
Once you're back in control, spend fifteen minutes on prevention — it's far cheaper than another recovery cycle. Use a unique password for LinkedIn that you use nowhere else, ideally generated and stored by a password manager rather than something you can memorize (memorable passwords are guessable passwords). Keep two-step verification turned on permanently, preferably with an authenticator app rather than SMS. Get in the habit of checking the sender domain on any "LinkedIn security" email before clicking anything inside it — when in doubt, navigate to linkedin.com manually instead of clicking the email link. Periodically review Settings & Privacy > Sign-in & security > Where you're signed in even when nothing seems wrong, just to catch an unfamiliar session early. And if you're a business owner or recruiter managing a team, make sure your colleagues know the same rules — a single compromised account on your team can be used to phish everyone else in the company.
Timeline: What to Expect
| Scenario | Typical Timeline |
|---|---|
| Still have access — end sessions, change password, enable 2FA | Minutes |
| Locked out, form submitted with profile URL, familiar device/network | A few hours to 2-3 business days |
| Locked out, email/recovery info changed, identity verification required | 2-7 business days, depending on review volume and how complete your ID submission is |
Frequently Asked Questions
How do I know if my LinkedIn account was hacked?
Watch for posts or messages you didn't send, connection requests to strangers, a changed profile photo or headline, "new sign-in" alerts from unfamiliar locations, a password that suddenly stops working, or contacts telling you they received a strange message from you. Any of these means you should start the recovery steps right away.
How long does LinkedIn account recovery take?
If you still have access, ending sessions, changing your password, and enabling two-step verification takes minutes. If you're fully locked out and need LinkedIn's official compromised-account form with identity verification, expect anywhere from a few hours to several business days depending on how quickly LinkedIn's review team can confirm your identity.
What if the hacker changed my LinkedIn email and I can't get in at all?
You can't use "Forgot password" if the attacker changed the recovery email — go straight to LinkedIn's Report a Compromised Account form at linkedin.com/help/linkedin/answer/a1340402. Include your old profile URL if you remember it, and be ready to complete identity verification with a government-issued ID to prove ownership.
Is LinkedIn's ID verification (QR code + photo ID) safe to use?
Yes, when it happens inside LinkedIn's own official recovery flow that you started yourself at linkedin.com. It exists to stop anyone else from claiming your compromised account. Never complete this step in response to an unsolicited email or text — that's a phishing tactic mimicking the real process.
How do I protect my company's LinkedIn Page if my admin account is hacked?
Secure your personal account first (end sessions, change password, enable two-step verification), then check the Page's Manage Admins list and remove anyone you don't recognize. Keep at least two trusted admins on every Company Page so one compromised account never leaves it unmanaged.

Comments (3)
As a small business owner I panicked when I saw my LinkedIn was sending fake "investment opportunity" messages to my clients. Ending the sessions first before even changing the password was the tip that mattered most — my instinct was to change the password right away but the attacker was still logged in and could have just changed it back. Recovered same day.
I'm actively job hunting so a hacked LinkedIn felt like a nightmare — recruiters were seeing spam posts under my name. The compromised account form took about 36 hours including the ID verification step. A bit nerve-wracking to upload my passport photo but it worked exactly as described and nothing shady happened with it.
I'm a recruiter and one of my colleagues got a "job offer" attachment from what looked exactly like my LinkedIn account — that's how I found out I'd been hacked. Had IT Cares check my laptop afterward and they found a keylogger from a fake PDF reader I'd installed months earlier. Glad I didn't just change the password and call it done.
Leave a Comment