An unfamiliar LinkedIn session or message to your connections can indicate account access, but a fake profile imitating you is a different incident. LinkedIn says active sessions can remain open when a browser closes and can be ended from Settings & Privacy; changing the password also closes other active sessions. Contain the access, review contact and profile changes, then tell people who may have received fraudulent requests. If you are locked out, use LinkedIn's compromised-account reporting route.
Before you start
Use a device you trust. Capture the suspicious message, profile or session details without forwarding private conversations to strangers. Check whether your email account and phone number still belong to you; account recovery depends on them. If money was requested in your name, warn contacts through an independent channel after you have evidence.Do it step by step
- Open LinkedIn Settings & Privacy and inspect where you are signed in or active sessions. Identify your own phone and computer, then close unfamiliar or unneeded sessions.
- Change the LinkedIn password to a unique one. Enable or review two-step verification using a method you control. Secure the associated email account and check its forwarding and recovery settings.
- Inspect recent direct messages, invitations, job applications and changes to your profile or contact details. Preserve evidence of anything you did not authorize.
- Notify affected connections that any payment, code or document request should be ignored and verified independently. Do not send a vague mass warning that repeats a malicious link.
- If you cannot access the account, use LinkedIn's compromised-account form from an independently opened Help page. If the problem is an impersonating second profile, report that profile through its More, Report or Block route instead.
- Recheck sessions and account details after recovery. Ask the payment provider or employer to review any transaction or application submitted by an intruder.