TL;DR:

  • LinkedIn is actively used by scammers to research targets for business email compromise (BEC) and invoice fraud — your public profile is reconnaissance data
  • Fake LinkedIn job offers are a primary delivery mechanism for malware targeting professionals, particularly in finance, legal, and tech
  • Two-factor authentication and reviewing which apps have LinkedIn access are the two most important immediate steps

Most small business owners think of LinkedIn as a sales and networking platform. Attackers think of it as a database. Your profile tells them your job title, company size, who your colleagues are, which suppliers you use (often visible in your recommendations or posts), and sometimes your direct contact details. All of this is useful for crafting convincing fraud.

The LinkedIn Threats Facing UK Small Businesses

Business Email Compromise research: Before a BEC attacker sends a fake invoice or payment change request, they often spend time on LinkedIn identifying who handles payments at your business, who your suppliers are, and the names of your leadership team. A public LinkedIn profile showing “Finance Manager at Smith & Co” is exactly the kind of targeting data they need. The NCSC has documented BEC attacks in the UK that began with LinkedIn research.

Fake job offers delivering malware: This is primarily a threat to your employees, but it reaches your business network through them. A convincing LinkedIn InMail from a “recruiter” at a plausible firm offers a high-paying role and asks the target to complete an assessment. The “assessment” is a ZIP file or PDF that executes malware. North Korean state actors have used this technique extensively against finance and technology professionals. If an employee downloads something from a fake LinkedIn recruiter on their work laptop, your business network is at risk.

Account takeover and impersonation: Attackers compromise LinkedIn accounts and use them to contact the victim’s connections. Because the message appears to come from a trusted contact, the recipient is more likely to click a link or download a file. If your LinkedIn account is compromised, attackers can approach your clients, partners, and suppliers convincingly in your name.

Profile scraping for phishing personalisation: Automated tools scrape public LinkedIn profiles to build contact lists for highly personalised phishing emails. The more detail in your public profile, the more accurate the phishing. This is why NCSC guidance recommends reviewing what information your public profile actually needs to display.

The Immediate Priority: Two-Factor Authentication

LinkedIn offers two-factor authentication through authenticator apps (Google Authenticator, Microsoft Authenticator, Authy) and SMS. The authenticator app option is significantly more secure.

To enable it: Settings and Privacy → Sign In and Security → Two-step verification → Turn on. Choose “Authenticator App” rather than “Phone Number” — SMS codes can be intercepted through SIM swapping attacks, which are increasingly common against small business owners.

This single step blocks the vast majority of LinkedIn account takeover attempts, which rely on stolen passwords from data breaches.

Review Your Privacy Settings

LinkedIn’s default settings are configured for maximum visibility. For a small business owner, some of that visibility is useful (you want clients to find you) but some of it hands attackers useful data.

Go to Settings and Privacy → Visibility:

“Profile viewing options”: Choose how you appear when you view other profiles. On “Your name and headline”, your profile appears to everyone you view. Consider switching to “Private mode” when you’re researching competitors or investigating a potential fraud.

“Who can see your connections”: Default is “Your connections” — your full network list is visible to all first-degree connections. Change to “Only you” if you’re concerned about competitors mapping your client network, or attackers using your connections list to identify who to approach next.

“Email address visibility”: If your work email is visible, it feeds directly into spam and phishing campaigns. Limit this to connections only or remove it.

“Phone number”: Should not be visible to anyone other than your close connections, and arguably not even then. Your website or contact form is the right channel for inbound enquiries.

Third-Party App Access

LinkedIn apps and services can request access to your account. Over time, these permissions accumulate. Go to Settings and Privacy → Data Privacy → Permitted Services to see what has access.

Audit this list. Remove anything you don’t actively use. Old CRM integrations, trial apps, and social scheduling tools you stopped using years ago may still have read access to your profile, messages, or connections. Any one of these could be compromised independently, giving attackers a route into your LinkedIn presence without needing your password.

Recognising LinkedIn Scams

Too-good job offers: Unsolicited InMails offering significantly above-market salaries for your profile type, especially if they ask you to click a link, download a file, or complete an “assessment” as part of the initial contact. Legitimate recruiters don’t send assessments before a first conversation.

Fake supplier and partner connections: Someone connects claiming to be from a supplier you use, then after a short period of innocuous interaction, asks for a favour related to payments, invoices, or clicking a link. Check connection requests carefully — search the person’s name and company to verify they’re real.

WhatsApp migration requests: A message from an apparent contact asking you to continue the conversation on WhatsApp, often for “privacy”. This moves you off LinkedIn’s reporting systems.

Verification scams: A message claiming LinkedIn is running an “account verification” and asking you to confirm your login details. LinkedIn does not send verification requests through InMail.

What to Review on Your Profile

Think about what information a fraudster could use against your business or your contacts:

  • Does your profile reveal which bank you use, which payroll provider, which suppliers?
  • Does it show your direct email or phone alongside your company name?
  • Do your posts or activity reveal when you’re travelling or out of office?
  • Is your company structure visible enough that a fraudster could convincingly impersonate your finance department?

You don’t need to make your profile invisible — LinkedIn is a legitimate business tool. But trimming the information that’s useful to fraudsters (direct contact details, operational details, key supplier relationships) while retaining what’s useful to clients (your services, credentials, recommendations) is the right balance.

If Your Account Is Compromised

Act quickly. Go to linkedin.com/help and report the account compromise immediately. Change your password and sign out of all sessions (Settings → Sign In and Security → Where You’re Signed In → Sign Out of All Devices). Enable two-factor authentication if you haven’t already.

Then notify your connections — post an update and message your closest contacts directly — because your account may have been used to approach them. Report to Action Fraud (0300 123 2040) if you believe a crime has been committed.