LinkedIn Account Hacked? How to Recover It and Protect Your Career
If your LinkedIn account was hacked, secure your email, use LinkedIn's official recovery and identity verification, sign out other sessions and warn your network about fake messages.
If your LinkedIn account was hacked, secure the email address linked to it first, then reset your password from LinkedIn’s sign-in page. If the attacker changed your email or password, use LinkedIn’s Help Center to report a hacked account, and be ready to verify your identity. Once you’re back in, sign out of every other session, turn on two-step verification, check any Company Pages you manage and warn your connections about messages you didn’t send.
LinkedIn is tied to your professional name, so a hack can reach colleagues, clients and recruiters. The steps below restore access first, then limit the damage to your career.
Signs your LinkedIn account was hacked
- You can’t sign in, or LinkedIn emailed you about a password, email or phone change you didn’t make.
- Connections tell you they received messages from you offering jobs, investments, crypto or “urgent” favors.
- Your name, headline, photo, work history or contact details have changed.
- You see connection requests you didn’t send, or posts and comments you didn’t write.
- Your active sessions show devices or locations you don’t recognize.
- You’ve lost admin access to a Company Page, or a new admin has appeared on one.
- Unexpected Premium, Sales Navigator or ad charges appear on your card.
Step 1: Secure your email first
Password resets go to your email. If an attacker controls it, they can take LinkedIn back after you recover it.
- Change your email password to a strong, unique one and turn on two-factor authentication.
- Check recovery details and forwarding rules, removing anything you didn’t set.
- Look for LinkedIn’s security emails in your inbox, spam and trash. If the email on your account was changed, LinkedIn typically notifies the previous address, and the message may offer a way to secure the account.
- If you use a work email for LinkedIn, tell your IT team. A compromised work email is a security issue for your employer too.
If your personal email was taken over, recover it first. Our guides to a hacked Gmail account and Microsoft account recovery cover the most common providers.
Step 2: Recover the account through LinkedIn
- Reset your password. On LinkedIn’s sign-in page, choose the forgotten password option and enter any email or phone number on your account. If the reset reaches you, set a new password.
- Report a hacked account. If resets go to the attacker, search LinkedIn’s Help Center for the hacked account option and follow the recovery steps. It’s LinkedIn’s official route when you can’t sign in.
- Verify your identity if asked. LinkedIn may ask you to confirm who you are, for example with a photo of a government-issued ID, to match you to the account. Complete this only through LinkedIn’s own site or a link in a genuine LinkedIn email.
- Keep records. Note your case number, the dates you contacted LinkedIn and what the attacker changed.
LinkedIn doesn’t publish a fixed recovery time. It depends on what was changed and how quickly identity checks can be completed.
Step 3: Lock it down once you’re back in
- Change your password again to one you’ve never used elsewhere.
- Sign out of all other sessions in LinkedIn’s sign-in and security settings.
- Turn on two-step verification, preferably with an authenticator app rather than text messages. Add a passkey if LinkedIn offers one on your device.
- Check your email addresses and phone numbers and remove any the attacker added.
- Review permitted services: remove third-party apps and services you don’t recognize.
- Check Company Pages, groups and ad accounts you manage for new admins, changed details or new campaigns. Our guide to hacked business social media accounts covers the business side.
- Check billing for Premium, Sales Navigator, job posts or ads, and contact your card issuer about charges you didn’t make.
Step 4: Warn your network and repair your profile
A LinkedIn account hacked by scammers is valuable because your connections trust you professionally. Common scams sent from hacked accounts include fake job offers, fake investment tips and requests to “review a document” that lead to phishing pages. Our guide to LinkedIn scams explains how to spot them.
- Restore your profile: name, headline, photo, experience and contact information. Recruiters and clients may check it after hearing about the hack.
- Delete posts, comments and messages the attacker created, after taking dated screenshots.
- Withdraw connection requests you didn’t send and remove new connections that are clearly fake.
- Post a short, professional notice and message the people who were contacted.
A note to my network: my LinkedIn account was compromised earlier this week and has now been secured. Messages sent from my account about job openings, investments or shared documents during that time were not from me. Please don’t open those links, and if you did, change your passwords. Thank you to those who flagged it.
If you work for a regulated firm or handle client data, tell your compliance or security team as well. They may need to know which contacts were reached.
A worked example
This is an illustrative scenario, not a real client. A sales manager receives a LinkedIn message that appears to come from a recruiter, with a link to “view the role description”. The link asks her to sign in to LinkedIn again. Two days later, several clients tell her they’ve received messages from her about a “private investment opportunity”.
- Email: she changes her email password, turns on two-factor authentication and finds an email forwarding rule she didn’t create, which she removes.
- Recovery: her password was changed, so she uses LinkedIn’s hacked account route and completes an identity check.
- Lockdown: once back in, she signs out of all sessions, turns on two-step verification and removes an unknown app.
- Company Page: she checks her employer’s Page, where she’s an admin, and confirms no admins were added.
- Network: she posts a short notice, messages each client who was contacted and tells her company’s IT team.
Not sure where to start?
Get a free audit of your search results and review profiles, with a prioritized fix list.
Get a free auditHow LinkedIn accounts usually get hacked
- Fake recruiter and job messages leading to fake sign-in pages.
- “Shared document” phishing that imitates file-sharing services.
- Reused passwords leaked in breaches of other sites. Our guide to Have I Been Pwned explains how to check your email.
- A compromised email account, which lets an attacker reset the LinkedIn password.
- Malicious browser extensions or tools that promise LinkedIn automation.
Protecting your professional reputation afterwards
A hack can make you look careless or even complicit to people who don’t know what happened. Most people understand once they hear it plainly, so be direct and consistent.
- Tell key contacts personally: your manager, important clients and anyone who received a scam message.
- Search your name on Google and LinkedIn to check for copycat profiles. If someone set up a fake profile in your name, report it and see our guide to online impersonation.
- Review what’s public. Our guide to LinkedIn privacy settings covers who can see your connections, email and activity.
- Rebuild visible activity with a few genuine posts over the following weeks, so your recent activity reflects you, not the attacker.
If the hack has damaged how you appear to clients or employers, our personal reputation management service can help assess and repair your search results.
Common mistakes to avoid
- Recovering LinkedIn but not the email. The attacker can reset the password again.
- Skipping Company Page and ad account checks. An attacker may have added themselves as an admin.
- Sending your ID to anyone other than LinkedIn. Identity checks happen only through LinkedIn’s own process.
- Staying silent. Contacts who received scam messages may assume the worst.
- Creating a new profile. Duplicate profiles confuse recruiters and can break LinkedIn’s rules. Recover the original first.
Frequently asked questions
How long does LinkedIn take to recover a hacked account?
It depends on what was changed and whether identity verification is needed. A password reset can take minutes; a hacked account report with identity checks can take longer. LinkedIn doesn’t publish a fixed timeframe.
Is it safe to send LinkedIn a photo of my ID?
Only through LinkedIn’s official recovery or verification process, reached from LinkedIn’s site or a genuine LinkedIn email. Never send ID to someone who contacts you by message claiming to be LinkedIn.
What if the hacker removed me as admin of our Company Page?
Recover your own account first, then use LinkedIn’s Help Center to request admin access to the Page. Other admins at your company can also restore your role. Our guide to hacked business social media accounts covers business-side recovery in more detail.
Should I tell my employer my LinkedIn was hacked?
If the hack involved your work email, a Company Page, or messages to clients or colleagues, yes. Your IT or security team may need to act, and telling them early protects you.