SecurCheckCyber Centre

LINKEDIN · B2B · RECRUITMENT

How to check a hacked LinkedIn account: B2B assessment guide

Secur Cloud ·

LinkedIn supports B2B prospecting, commercial relationships and recruitment. Taking over a leader’s, salesperson’s or recruiter’s profile can make spear-phishing messages appear credible, expose conversations and harm an employer brand.

Here is how to perform a LinkedIn account assessment and respond to observed signs. If unauthorised activity is visible, start securing access and alert support without waiting to complete the checklist.

1. Warning signs of a LinkedIn intrusion

  1. An unusual sign-in notification

    An unfamiliar browser, device or location appears. Check in LinkedIn opened directly: an email imitating an alert may be phishing. Approximate location or a VPN does not alone prove intrusion.

  2. Unauthorised messages or InMails

    Clients or connections report suspicious links, fake investments or unexpected documents sent from your profile. Confirm through another channel and preserve useful evidence.

  3. Changed contact details or experience

    Your email address, phone number or profile details change without approval. Unfamiliar contact details may facilitate another takeover: review recovery methods promptly.

  4. Unfamiliar posts or comments

    Fraudulent content, fake jobs or crypto promotions appear under your name. Also review Pages and business services your profile can actually access.

2. Assess the account without exposing access

Never share your password, a 2FA code or a backup code with a third-party assessment tool. Perform checks in official interfaces opened directly.

  1. Review active sessions

    In Settings & Privacy, open Sign in & security then Where you’re signed in. Compare devices, browsers and recent activity. End unrecognised sessions; labels may vary by interface.

  2. Review permitted services and partners

    Under Data privacy, look for Permitted services under Other applications. Also review Partners & services in Account preferences. Remove unfamiliar or unnecessary permissions after checking their business purpose. Ending a session and removing OAuth access are separate checks.

  3. Check addresses and recovery

    Check every registered email address and phone number, not just the primary address. Also secure the linked mailbox. Address unauthorised additions while retaining a recovery method you control.

3. Regain control according to your situation

  1. Secure access from a trusted device

    If an infostealer is suspected, do not enter your new password on the affected endpoint: alert IT and use a trusted device. Change your LinkedIn password to a long, unique secret stored in a password manager. Change it wherever it was reused.

  2. End sessions and remove unauthorised access

    End unfamiliar sessions, use the offered global sign-out option and review the list again. Separately check authorised apps, contact details and any business management permissions. Signing out does not retrieve data already copied.

  3. Enable two-step verification

    Under Sign in & security, configure two-step verification, preferably with an authenticator app. Follow the offered options and check recovery methods. Do not approve sign-in prompts you did not initiate. This does not neutralise an infected device or every session-theft scenario.

  4. Alert connections and affected teams

    Alert IT and communications as soon as fraudulent activity is identified. Preserve useful screenshots and times, then have malicious content addressed. Warn recipients through a trusted channel not to open affected links; review potential impact on candidates, clients and managed Pages.

4. Lost access: report a compromised account

Open official LinkedIn help and use the unauthorised account access report form. Include your profile URL if known. LinkedIn may require checks before restoring access; do not share identity documents or codes with a supposed recovery specialist contacted by direct message.

Report a compromised LinkedIn account

Build professional security habits

Verify unexpected partnerships, shared documents and security alerts through official channels. Learning to check a suspicious LinkedIn account complements third-party access reviews, endpoint security and mailbox protection. Monitor the profile after an incident for new anomalies.

Read also: has my account been hacked?

Deploy SecurCheck Business to support your teams every day

Official LinkedIn references