TL;DR: LinkedIn has had two separate incidents: a 2012 breach that exposed 164.6 million email addresses and unsalted SHA1 password hashes (most cracked within days, but the scale wasn't public until 2016), and a 2021 incident where data scraped from about 700 million public profiles was posted for sale (LinkedIn disputes calling this a "breach" since no passwords or private data were taken). Either way, if you've had a LinkedIn account since before 2012 or your profile was public in 2021, your email and profile details are almost certainly in one of these datasets. Run a free check to see exactly what's exposed.
LinkedIn is one of the most-cited names in breach databases, but "the LinkedIn breach" actually refers to two different events with very different severity. Knowing which one might affect you — and what was actually exposed — decides what you need to do next.
The 2012 LinkedIn breach: what actually happened
In June 2012, attackers stole a database of LinkedIn user credentials. At the time, LinkedIn said around 6.5 million password hashes were posted online. The real scale wasn't known until May 2016, when the full dataset resurfaced for sale on a dark web marketplace: 164.6 million email addresses and passwords, according to Have I Been Pwned's breach record. The passwords were stored as unsalted SHA1 hashes — a weak method even by 2012 standards — and the large majority were cracked within days of the original 2012 leak.
LinkedIn forced a second password reset for affected accounts in 2016 once the full scope became clear. See Krebs on Security's coverage of that reset for the full timeline.
The 2021 LinkedIn data-scraping incident
In 2021, someone advertised a dataset covering roughly 700 million LinkedIn profiles — about 92% of LinkedIn's user base at the time — for sale on a hacker forum. Unlike 2012, this wasn't a break-in: the data was compiled by scraping publicly visible profile fields (name, email, job title, location, links to other social accounts) using LinkedIn's own API and public pages. LinkedIn publicly disputed the "breach" label, pointing out that no passwords, financial data, or private messages were included.
That distinction matters for what to do about it, but not for whether your data is exposed: if your profile was public in 2021, your name, job history and contact details are very likely in that dataset regardless of what it's called.
What was exposed in each incident
- 2012 breach: Email addresses and password hashes (164.6 million accounts).
- 2021 scraping incident: Names, email addresses, phone numbers (where public), job titles, employers, and links to other social profiles (roughly 700 million profiles).
Neither incident is unique to LinkedIn — see the biggest data breaches in history for how these compare in scale, and credential stuffing explained for why an old password breach still matters years later if you reused that password anywhere else.
How to check if your LinkedIn data was exposed
- Run your email through the free Scan My Shadow checker — it checks your email against known breach datasets including LinkedIn's.
- Search your email directly on Have I Been Pwned.
- If you reused your LinkedIn password anywhere else, check if that password has been leaked too.
What to do if you were affected
- Change your LinkedIn password — and any other account where you reused it.
- Turn on two-factor authentication on LinkedIn and your email account.
- Watch for phishing that references your real job title or employer — the 2021 data makes convincing fake recruiter and business-email-compromise scams easier to write. See social engineering explained.
- Consider a broader exposure check — if your email surfaces in the LinkedIn dataset, it's usually in others too. See whether identity theft protection is worth it for your situation.
FAQs
Was I affected by the LinkedIn data breach?
If you had a LinkedIn account before June 2012, your email and password hash are likely in the 2012 breach dataset. If your profile was public at any point before mid-2021, your name and job details are likely in the 2021 scraped dataset. Run your email through a breach checker to confirm.
Is the 2021 LinkedIn incident really a "breach"?
LinkedIn disputes that label, since the data came from public profile fields via scraping rather than a break-in of its systems. No passwords or private data were included. Practically, though, your public information is still exposed the same way it would be in a breach.
Were LinkedIn passwords actually leaked?
Yes, in the 2012 incident: 164.6 million email-and-password-hash pairs. The 2021 incident did not include passwords.
Do I need to change my LinkedIn password now?
If you haven't changed it since 2012 or have reused it elsewhere, yes — change it and enable two-factor authentication. LinkedIn already forced resets for known-affected accounts in 2016, but reused passwords on other sites remain a risk.
How do I check if my email was in the LinkedIn breach specifically?
Have I Been Pwned lists "LinkedIn" as a named breach source when you search your email. The Scan My Shadow checker also flags which known breaches your email appears in as part of its report.
Curious what's already out there? Scan My Shadow checks a phone number and email across 1,500+ sources and sends a clear report — no guesswork, just facts. Start your scan.
Sources
- Have I Been Pwned — LinkedIn breach record
- Krebs on Security — 2016 LinkedIn password reset coverage
- Computer Weekly — LinkedIn's response to the 2021 scraping incident
- Wikipedia — 2012 LinkedIn hack, full timeline and citations