Popular Networking Platform Accused Of Secretly Harvesting Data From 405 Million Users

An investigation claims the data was then sent to an American-Israeli cybersecurity firm.

Enlarge text

Follow us on InstagramTikTok, and WhatsApp for the latest stories and breaking news.

A major data privacy controversy has hit professional networking platform LinkedIn after allegations that it has been secretly tracking user data, potentially affecting 405 million people worldwide

An investigation spearheaded by Fairlinked e.V., a European association representing commercial LinkedIn users, exposed the alleged practice under a campaign called BrowserGate.

The group describes it as one of the largest corporate espionage and data breach scandals in modern digital history.

SAYS.com

Image used for illustration purposes only.

Image via Zulfugar Karimov/Pexels

According to the findings, Microsoft allegedly injects a hidden JavaScript payload into the LinkedIn website to scan visitors' web browsers for installed third-party software applications and extensions

The underlying code reportedly targets over 6,000 specific browser extensions by tracking their unique identifiers, compiling the inventory, and sending the encrypted data bundles back to LinkedIn servers.

The data collection allegedly takes place in the background without explicit user consent, and LinkedIn does not disclose the practice in its public privacy policy.

Because LinkedIn accounts directly display real identities, including full names, current employers, and official job titles, any extracted browser data could be linked to identifiable individuals.

SAYS.com

Image used for illustration purposes only.

Image via panumas nikhomkhai/Pexels

The harvested data allegedly exposes highly sensitive personal attributes that could trigger severe professional and legal consequences

Fairlinked claims the platform scans for specialised tools identifying practising Muslims, extensions indicating specific political orientations, and assistive software built for neurodivergent users.

The code is said to monitor 509 distinct job-hunting tools, potentially identifying employees seeking new employment while their current employers monitor their profiles.

Under the European Union's General Data Protection Regulation (GDPR), processing such sensitive personal metrics strictly requires explicit consumer consent.

The investigation also claims that LinkedIn tracks more than 200 competing corporate software products, including Apollo, Lusha, and ZoomInfo, allowing it to map out the software infrastructure of rival businesses.

The investigation also claims that LinkedIn transmits the collected user datasets to HUMAN Security, an American-Israeli cybersecurity firm established in New York in 2012

The cybersecurity entity, which boasts an annual recurring revenue of approximately USD100 million (RM407.44 million), focuses on enterprise anti-fraud operations.

However, the company merged in 2022 with the Israeli firm PerimeterX, an organisation founded by former officers of Unit 8200, a highly specialised cyber warfare division operating within the Israeli Defence Forces.

The investigation argues that this connection has intensified public concern over how the collected data is ultimately used.

LinkedIn has rejected the allegations, saying the claims are inaccurate and have been addressed on its developer forums

A company representative explained that the platform uses the data solely to identify extensions that violate its terms of service, bolster its technical cyber defences, and maintain overall site stability against malicious scraping activities.

The firm emphasised that it does not use the system to infer sensitive information about individual members. It also noted that a German court had previously dismissed legal claims brought by the primary website owner behind these accusations, finding that the claimant's own data practices failed to comply with legal standards.

Read more trending stories on SAYS

You may be interested in: