This piece appeared in The Hamilton Spectator on September 22, 2026.
Your LinkedIn account is one of the most prized social media accounts traded on the dark web marketplaces, according to data from cybersecurity company NordVPN.
According to NordVPN’s dark web research that studied data from January 2025 to February 2026, stolen LinkedIn accounts are sold on illicit online marketplaces for a median price of $299, making them one of the most valuable social media accounts traded by cybercriminals, the company said.
Why is your LinkedIn profile information valuable to cybercriminals?
Lester Chng, senior trainer and practice lead for cybersecurity at the Toronto Metropolitan University’s Rogers Cybersecure Catalyst, told Metroland Media many professionals trust the platform because it is widely accepted as a professional networking site.
Many prominent figures, including heads of state, also actively use it to grow their social media presence.
Cybercriminals exploit this trust on the platform and use it for targeted phishing that impersonate colleagues, clients, recruiters and executives.
LinkedIn profiles are also highly valuable for cybercriminals because “LinkedIn’s user base is older and has higher purchasing power, Chng said adding “it has also recently become an active marketplace for professional services and digital products.”
“People underestimate how much damage a hijacked professional account can do. It’s not just your profile, it’s your contacts, your messages, your credibility. Attackers use all of it to make their next scam look legitimate,” Adrianus Warmenhoven, cybersecurity advisor at NordVPN said in a news release.
What can hackers do with your hacked LinkedIn account?
A hacked professional profile is a gold mine of information that can be used for highly targeted spear phishing campaigns and BEC or business email compromise.
One way they can exploit the victim directly is by threatening to use the account for malicious activities or release sensitive information.
This, he explained, can have a reputational and privacy impact on the victim.
In many instances, however, cybercriminals use the stolen account to impersonate the victim and exploit the victim’s network of contacts.
The victim’s network may have a high level of trust and may respond to direct messages from the victim,
he said adding because of this trust, network contacts may share more sensitive information with the victims through the compromised LinkedIn account.
“In more elaborate cases, cybercriminals may also use the victim’s account to sell consulting services and purchase digital products, which can lead to other fraudulent transactions,” he said.
What are spear phishing and business email compromise?
Spear phishing is a highly targeted form of phishing that involves prior research on the target’s background to make personalized scam emails, texts or calls.
BEC or business email compromise is a specific form of spear phishing using email. It involves fraudsters impersonating a trusted person to trick employees or customers into making a payment or purchase, sharing data, divulging sensitive information or giving access to their device or system.
According to the U.S. Federal Bureau of Investigation (FBI) BEC is one of the most financially damaging online crimes and it may look like:
A vendor your company regularly deals with sending an invoice with a supposed updated mailing address.A company CEO asking her assistant (the target) to purchase dozens of gift cards to send out as employee rewards. She asks for the serial numbers so she can email them out right away.A homebuyer receiving a message from his title company with instructions on how to wire his down payment.
Versions of this scam have happened to real victims but the messages were all fake, the FBI said.
Fraudsters may use a person’s professional profile to analyze interactions and company connections. Then they can piece data together along with other specific details like projects, initiatives, and programs that the persons and their contacts are involved in to make a BEC attack highly convincing.
How to protect your LinkedIn account from hackers
In an email to Metroland Media, LinkedIn said the platform helps members stay safe and in control of their data by providing built-in safety features to avoid potential scams and through setting options that help them manage their off-platform visibility.
“We also encourage each member to enable two-factor authentication (2FA) to help reduce unauthorized access to their LinkedIn account,” the company said in the statement.
On LinkedIn’s account security best practices page, the company recommends that users use strong passwords, keep their password secure, keep their antivirus software updated and only connect with people they know and trust.
How to check for suspicious devices accessing your LinkedIn account
To check for suspicious devices accessing your LinkedIn account, you can check “Active sessions” by following these steps.
From home click the circle icon showing your profile image (on browsers click “Me” with the downward arrow below your image)Scroll down then click “Settings & Privacy” Then click “Sign in & Security” Click “Where you’re signed inCheck all the devices accessing your LinkedIn account and click “End” to log it out of any device and device location you don’t recognize
Active sessions will list all devices with an estimate of the IP address which may be located within the country, region and city where the device is accessing the account.
It may have additional information such as if the device is accessing the LinkedIn account using the LinkedIn mobile app or a specific type of browser as well as when the account was last accessed using this device.
If you see a suspicious device you do not recognize, end the session on that device, change your passwords and enable MFA (multifactor authentication) right away. Also review your profile for changes you did not make, check your LinkedIn inbox for messages or contacts you don’t recognize, and watch out for email or phone number changes on your account.