LinkedIn URLs are being hijacked for phishing

Hook on Keyboard
(Image credit: wk1003mike / Shutterstock)

Cybersecurity researchers have caught hold of attackers using LinkedIn’s shortened URLs in phishing campaigns in order to trick email apps as well as the victims.

Researchers from Avanan have shared details of how hackers are taking advantage of LinkedIn’s automatic URL shortening service to launch a new credential harvesting campaign. 

In a blog post, the researchers shared an email that invited recipients to click on a LinkedIn shortened URL to enter missing details. 

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

“The URL (shortened to lnkd.in) passed through the LinkedIn short URL service, leading visitors across several redirects, landing on this phishing page,” the researchers note.

Brand hijack

Citing a recent Check Point Research report that rated LinkedIn as the sixth most impersonated brand in phishing attempts around the world in Q2 2021, Avanan argues that the latest phishing scam can target any employee. 

“Plus, more employees have access to billing and invoice information, meaning that a spray-and-pray campaign can be effective,” believes Avanan.

The use of URL shortening service in order to redirect recipients to a phishing page, isn’t exactly novel. 

Earlier this year, investigating a malicious message sent via Facebook Messenger, CyberNews researchers uncovered a large-scale phishing campaign that used a URL shortening service to trick close to 500,000 Facebook users. 

In fact, security researchers have long been advising users against clicking shortened URLs in instance messages, emails, and other forms of online communication from unfamiliar sources. 

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
Hacker silhouette working on a laptop with North Korean flag on the background
North Korean hackers are targeting LinkedIn jobseekers with new malware - here's how to stay safe
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
SVG files are offering cybercriminals an easy way in with new phishing attacks
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Marvel Rivals
Marvel Rivals will get two new hero skins for Moon Knight and Black Panther this week meaning I'll now need to farm even more Units
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
Klipsch Klipschorn AK7 in a room with lots of dark wood furniture and a bare brick wall
Klipsch just updated two of its most iconic stereo speaker designs, keeping these beautiful retro icons on your most-wanted list
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?