Hackers are on a spree of Hijacking LinkedIn Accounts, in some cases monetizing the attacks by demanding a small ransom from users to regain access an
Hijacking LinkedIn Accounts

Hackers are on a spree of Hijacking LinkedIn Accounts, in some cases monetizing the attacks by demanding a small ransom from users to regain access an

Though LinkedIn, a subsidiary of Microsoft, has not yet commented publicly about the campaign, it has affected people worldwide over the last few weeks. Conversations on social media and Google searches indicate a "significant surge in the past 90 days" of account hacks on the professional-oriented social media platform, according to a recent report published by Cyberint.

LinkedIn support response time for users has lengthened under the high volume of support requests, indicating that something is amiss, Coral Tayar, a security researcher at Cyberint, wrote in the report.

"[Google] search queries such as 'LinkedIn account hacked' or 'LinkedIn account recovery' have experienced a substantial upward trend … while the term 'breakout' in place of percentage indicates that the search term grew by over 5,000%," she wrote.

Two Attack Scenarios

Two Attack Scenarios

Despite its silence so far on the matter — which has caused some ire among users — LinkedIn appears to be aware of suspicious account-related activity. LinkedIn did not immediately respond to a request for comment today.

"Absolutely furious with LinkedIn right now!" one person raged on X, formerly Twitter, according to a comment published in the report. "Fell victim to a hack and their pathetic excuse for a security system couldn't stop it. No response from them either."

However, in reports of account hacks posted online, two scenarios have emerged, one in which LinkedIn already has taken some action on the part of users. In that scenario, LinkedIn temporarily locks a person's account due to suspicious activity or hacking attempts and then notifies the user of the action, asking that they verify accounts and update their passwords to regain access.

"In this case, the threat actors possibly attempted to breach accounts with two-factor authentication or tried brute-force attacks on passwords, leading LinkedIn to block these attempts," Tayar wrote.

The second scenario is more unfortunate in that victims’ LinkedIn accounts are fully hacked in such a way that it's impossible for them to recover their accounts independently. In this instance, attackers gain access to the account and alter the account’s associated email address to another email address, often using potentially generated addresses using the mail system of rambler ru

Attackers then proceed to change the password of the account and, since they changed the account email address, the user can't recover their login details using the previous email address linked to the account, as might typically occur.

"Some victims have received ransom messages (typically requesting a few tens of dollars) to regain access, while others have witnessed their accounts being deleted outright," Tayar wrote.

History of Targeting LinkedIn

History of Targeting LinkedIn

LinkedIn is no stranger to being a target of cybercriminals; Last year, the platform was deemed the most abused brand in phishing attempts, likely due to its recognizability and widespread use in the corporate world. And as recently as June of this year, North Korean APT Lazarus was spotted using fake LinkedIn profiles to target security researchers in a phishing campaign.

In another spear-phishing campaign discovered last July, attackers targeted LinkedIn as part of an effort to take over Facebook Business accounts to run malvertising schemes.

While the motive behind the recent account-takeover campaign remains unclear, there is a range of malicious activity that threat actors can engage in using compromised profiles, Tayar noted. Attackers can use someone's LinkedIn profile to socially engineer phishing campaigns by impersonating a trusted colleague or supervisor.

They also can glean valuable information by accessing conversations between business colleagues, or cause reputational damage to victims by using their accounts to make posts containing malicious content or send damaging or threatening messages to business connections.

Indeed, "we live a significant part of our lives online, and we don't want our online identities in the wrong hands," notes Emily Phelps, director of threat intelligence firm Cyware.

Fellow Me (: Gaurav Duvey, Arun Kumar

Confirm LinkedIn Account Access Now

Confirm LinkedIn Account Access Now

Due to the potential scope and seriousness of the breaches, Cyberint strongly advises users to log in to accounts and confirm access promptly. Users also should ensure that all contact information found within their accounts is genuinely theirs, and contact LinkedIn immediately if they're locked out and can't recover the account using email.

Shoring up password security and adding two-step verification, a feature that LinkedIn and other platforms offer for account access, also can further secure someone's profile against compromise.

David Phelps

CEO at Global Creations Inc

5 个月

ALL HACKERS! Need to pay a price that will make them think twice, actually I think they are too stupid to think twice.

回复
David Phelps

CEO at Global Creations Inc

5 个月

All hackers need to be hung

Logan Fulcher

Comms @VineLayerZero | Certified Advanced Scrum Product Owner | Community Management | Graphic Arts | Writing & Editing | DeFi Specialist | Board Game Design

8 个月

Happened to me TWICE IN A WEEK. The hack took four minutes and I was locked out of my account. Linkedin did a great job coming in to restore my email - I changed my passwords across many websites as a security measure, as well as on my linked in, and figured they couldn't get in again. I was wrong. Somehow, they were able to hack the account again. I'm not sure how they got the code numbers out of my email. I have since turned on 2 factor authentication, after reclaiming my account a second time. I still can't figure out what they wanted or were trying to do.

回复

HI Dear Few days ago someone reset my passowrd and then link other email and now i am not able to see in account from my this email account .Can it get back my all data ?

回复
Raden Christantus Teja Kusumah

Remote Video Editor | Social Media Content Creator | Freelance Videographer

1 年

Hello, i've changed my pass but seems like the hacker still get into my account and sending scam message to others. I've check the online session is only on my trusted device. Any solution?

回复

要查看或添加评论,请登录

Gaurav Duvey的更多文章

  • Google Chrome Users Warned By Indian Govt About Major Security Issue: What You Should Do

    Google Chrome Users Warned By Indian Govt About Major Security Issue: What You Should Do

    Google Chrome users across the country have a got new security scare from the government this month. The latest Chrome…

  • How to Delete Facebook Account.

    How to Delete Facebook Account.

    Deactivating & Deleting Your Account If you deactivate your account: You can reactivate whenever you want. People can't…

    1 条评论
  • Get the Best Termite Treatment in Bangalore:

    Get the Best Termite Treatment in Bangalore:

    What are Termites? Termites are small, pale insects that feed on wood and other cellulose-based materials. They live in…

    1 条评论
  • CSIR NET Life Science syllabus 2024-2025

    CSIR NET Life Science syllabus 2024-2025

    CSIR-UGC (NET) Exam for Award of Junior Research Fellowship and Eligibility for Lectureship shall be a Single Paper…

  • How To Delete Experience on LinkedIn (2024)

    How To Delete Experience on LinkedIn (2024)

    Go to your LinkedIn profile page by clicking your profile picture at the top right corner of the screen. Scroll down to…

    6 条评论
  • How to recover Hacked Facebook page.

    How to recover Hacked Facebook page.

    I think that my Facebook Page was hacked or taken over by someone else Classic Pages on Facebook are updating to the…

    15 条评论
  • Hacking definition: What is hacking?

    Hacking definition: What is hacking?

    If a hacker is a person with deep understanding of computer systems and software, and who uses that knowledge to…

  • How to Restore Deleted WhatsApp Messages Without Backup

    How to Restore Deleted WhatsApp Messages Without Backup

    WhatsApp often shows you notifications asking you to keep a backup of your messages so that you can restore the backup…

    81 条评论
  • Report a Compromised Account ??

    Report a Compromised Account ??

    We take the responsibility of protecting our members, their accounts and their data on our services seriously…

  • Hackers target LinkedIn, hijack user accounts: Report

    Hackers target LinkedIn, hijack user accounts: Report

    LinkedIn is facing a wave of account hijacking attacks globally resulting in victims losing access to their accounts…

    1 条评论

社区洞察

其他会员也浏览了