Signs your LinkedIn account may be compromised
LinkedIn compromise often shows up through other people first, since the point is usually to send connection requests or messages that look like they come from a trusted professional contact.
- Connections or colleagues report receiving strange messages or investment pitches from your account
- Posts, articles, or connection requests you do not remember making
- A login notification email for a location or device you do not recognize
- You are suddenly logged out and your usual password no longer works
Immediate recovery steps
Move quickly, since an attacker with access can message your entire professional network before you regain control.
- Try to log in and reset your password immediately if you still have access
- If locked out, use LinkedIn's official 'Report a compromised account' process rather than searching for third-party recovery services
- Be ready to verify your identity, which may include a government-issued ID, since LinkedIn's trust and safety review is stricter for accounts that were used to spam connections
- Check and revoke active sessions once you regain access, from the account's security settings
What to check for after regaining access
Regaining login access is not the end of the cleanup. Attackers often leave changes behind that are easy to miss.
- Review recent posts, articles, and messages sent while the account was compromised, and delete anything fraudulent
- Check connected third-party apps and remove any you do not recognize
- Confirm the recovery email and phone number on the account are yours and unchanged
- Warn close connections directly that any strange messages during the compromise window were not from you
Locking it down so it does not happen again
Most LinkedIn takeovers trace back to a reused password exposed in an unrelated data breach, or a phishing page mimicking the LinkedIn login screen.
- Set a unique password not used on any other account, ideally through a password manager
- Enable two-step verification, preferably through an authenticator app rather than SMS
- Be cautious of urgent 'LinkedIn support' messages, which are a common phishing vector on the platform itself
- Periodically review active sessions and connected apps even without a specific reason to suspect compromise
Frequently asked questions
How long does LinkedIn take to restore a hacked account?
Straightforward cases can resolve within a few days once identity is verified. Accounts flagged for spam or impersonation behaviour during the compromise may face a longer trust-and-safety review with no guaranteed timeline, which is another reason to act at the first sign of trouble rather than waiting.
Should I pay a third-party service to recover my LinkedIn account?
No. Recovery should go through LinkedIn's official help center. Third-party 'recovery services' advertised online are commonly scams targeting people who are already anxious about losing access to their account.
Can a hacked LinkedIn account be used for more than spam?
Yes. It can be used to run investment or job scams against your real connections, who are more likely to trust a message that appears to come from you. This is why warning your network promptly matters as much as regaining access.