Phishing Attacks Impersonating LinkedIn are up 232% in the Last Month Alone!

Stu Sjouwerman | Mar 4, 2022

Phishing Attacks Impersonating LinkedInDuring the period the world has dubbed “the great resignation”, phishing scammers are shifting tactics to take advantage of those looking for a new career or place of employment.

When phishing scammers are coming up with a new campaign idea, they want a brand they can impersonate that has a significant reach to improve their chances of a successful attack. With an estimated 67 million monthly active users, LinkedIn is a pretty great choice. According to new data from security vendor Egress, a significant rise in the number of attacks since February 1, 2022 impersonating LinkedIn are being seen.

The attacks use verbiage very familiar to anyone who uses LinkedIn as the subject lines:

  • You appeared in 4 searches this week
  • You appeared in 9 searches this week
  • You have 1 new message
  • Your profile matches this job

The emails come from an unassociated email address, but do leverage LinkedIn branding, logos, colors, etc.:

linkedin_blog002

Source: Egress

The links in these emails connect victims to lookalike websites intent on harvesting the users credentials that can later either be used to impersonate the victim in future attacks on others.

Even at your organization, there are employees that are thinking about leaving. Seeing an enticing “job match” email could be just the thing to catch the interest of an employee. And while the attack above only harvests credentials, we have seen others that end up infecting business endpoints. Security Awareness Training is the one viable method to significantly reducing the threat surface when it comes to email-borne attacks.

Topics: Phishing

Stop Being a Target for Social Media Exploits

Social media is the new frontier for targeted spear phishing and credential theft. Use our Free Social Media Phishing Test to identify which users are likely to click malicious links or leak data on platforms like LinkedIn and X, and get your results in just 24 hours.

Get Your Free Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.