Breaches
3
3 verified
Records Exposed
310.1M
Total across all breaches
Data Types Leaked
9
1 high risk
Latest Breach
2023
LinkedInScrape2023

Breach History

LinkedInScrape2023
Nov 2023Medium
LinkedInScrape
Apr 2021Medium
LinkedIn
May 2012Critical
164.6M
Records exposed
2
Data types leaked
Verified
Status

In May 2016, LinkedIn had 164 million email addresses and passwords exposed. Originally hacked in 2012, the data remained out of sight until being offered for sale on a dark market site 4 years later. The passwords in the breach were stored as SHA1 hashes without salt, the vast majority of which were quickly cracked in the days following the release of the data.

Exposed Data Types
Email addressesPasswords
Policy Issues
  • The company does not claim to avoid processing sensitive data; instead, it states that users have a choice to include sensitive information on their profiles, implying it is processed if provided.
  • The company explicitly states using automated systems and AI for personalization, recommendations, and insights, which constitutes automated decision-making and profiling.
  • The company claims not to sell data for direct marketing without permission, which is consistent with its detailed explanation of sharing data with advertising partners under specific conditions (e.g., hashed IDs, explicit permission, or public data), rather than outright selling.
  • The company does not claim 'no third-party sharing' but rather states it works with 'trusted third parties' for research and 'service providers' for cookies, which is a common practice for service delivery and creates a tension with a general expectation of no sharing.
  • The company explicitly states sharing data with 'partners' and 'ad networks' for advertising purposes, which directly contradicts a claim of no third-party sharing.
  • The company's policy details sharing data with a broad range of third parties including affiliates, customers, partners, service providers, and ad networks, which directly contradicts a claim of no third-party sharing.
  • The company claims transparency and explicitly details its use of inferences, including for age and gender, which aligns with its transparency claim.
  • The company claims transparency and explicitly details its targeted advertising practices and offers user choices, which is consistent with its transparency claim.
Incident Status
Data breachYes
Data brokerYes
Policy contradictionsYes
Data Broker Detected0.9% confidence
    Exposed Data Types
    Email addressesLow risk
    GendersLow risk
    Geographic locationsLow risk
    Job titlesLow risk
    NamesLow risk
    Professional skillsLow risk
    Social media profilesLow risk
    Education levelsLow risk
    PasswordsHigh risk