This is why you should be very careful who you connect with on LinkedIn

LinkedIn

LinkedIn is obviously a very handy tool when it comes to the world of work, but far too many users of the social network are happy to connect with strangers, who could be malicious parties looking to cherry-pick precious data.

That's the headline from a new survey of 2,000 people in the UK, carried out by Intel Security, which found almost a quarter of respondents (24%) had connected with someone they didn't know on LinkedIn.

There's a chance that said unknown person could be a criminal type who simply wants to rifle through their potential victim's profile, in order to find personal details which could make a crafted spear phishing attack look far more realistic (and far more likely to be swallowed).

Raj Samani, CTO EMEA Intel Security, observed: "When a person in a similar industry to us, or a recruiter, requests to connect on LinkedIn, it may look harmless, but hackers prey on this as a means to target senior level professionals and ultimately the corporate network."

Samani further noted that attackers may start by targeting junior or middle management staff, subsequently using connections with these colleagues as a way to concoct a more successful campaign against senior execs.

Ultimately all this could lead up to a CEO fraud attack where the cybercriminal goes after the chief executive for a major payload. Samani observes that this is "a type of attack which is continuing to affect more victims and lead to even greater financial losses according to assessments by the FBI."

Lack of thought

Most of those surveyed admitted that they hadn't even wondered about whether somebody on LinkedIn might not be who they say they are – 69% of respondents in fact.

Also, 87% of those questioned said their employer had never made them aware of any social media policy pertaining to LinkedIn. Although there's a good chance many organisations don't have such a policy – as we saw in another piece of research yesterday, only half of all businesses have a policy in place.

The answer to helping combat these dangers? Naturally, it's training staff to be aware of LinkedIn imposters, and the way phishing scams are put together in general.

As ever, you should never take anything at face value, particularly links and attachments, and remember that emails may not be from who they appear to be sent by (email spoofing being another growing danger).

TOPICS

Darren is a freelancer writing news and features for TechRadar (and occasionally T3) across a broad range of computing topics including CPUs, GPUs, various other hardware, VPNs, antivirus and more. He has written about tech for the best part of three decades, and writes books in his spare time (his debut novel - 'I Know What You Did Last Supper' - was published by Hachette UK in 2013).

Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring