← Blog ·
LinkedIn account hacked? What to do in the first hour to recover it
Is it really a hack?
Signs of a takeover are changes you did not make: a new email address or phone number on the account, a password that no longer works, messages or invitations you did not send, posts you did not write, or a LinkedIn security email about a device you do not recognise. A forgotten password or a two-factor code that never arrives is a lockout, not a hack, and it has a different fix. If you cannot tell which you have, our LinkedIn account recovery team can look at it with you as a free diagnosis, and our guide to restricted, locked or hacked accounts sets the three side by side.
LinkedIn's compromised account page lists the usual ways in: a password taken through phishing or reused from another site, a shared or public computer where you stayed signed in, or an outdated email address or phone number on the account that someone else now controls. Keep those in mind, because the fix depends on which door was used.
Minutes 0 to 10: which doors do you lock first?
Speed matters most here, because an attacker who controls the account can keep changing it while you read.
- Secure the email account tied to LinkedIn. Change its password and turn on two-factor authentication for it, which LinkedIn's account security tips recommend. If the attacker controls this inbox, every LinkedIn reset code goes to them.
- If you can still sign in, change your LinkedIn password. In Settings & Privacy, under Sign in & security, choose Change password and select Require all devices to sign in with new password. LinkedIn's change password page says that signs you out everywhere you were logged in. Use a password you have never used anywhere else.
- End sessions you do not recognise. LinkedIn's Where you're signed in page shows each session's device, browser, IP address and location, and lets you sign out of all the others at once.
- If you cannot sign in, choose Forgot password. If the code goes to an address you no longer control, choose Can't access this email? and follow LinkedIn's no access to email steps, which end in a government ID check.
If the LinkedIn app asks whether a sign-in was you and it was not, tap No, it's not me. LinkedIn's sign-in prompt page says that denies the attempt immediately. If you tapped Yes by mistake, the same page says to return to the sign-in screen and reset your password as quickly as possible.
Minutes 10 to 20: how do you tell LinkedIn?
Submit LinkedIn's Report Unauthorized Account Access or Changes form, linked from its compromised account page, whether or not you are back in. Include your profile URL if you have it. LinkedIn says that if you cannot access the account, it will verify the account is yours and then help you regain access. If you can still sign in, it asks you to submit the form and secure the account at the same time.
Then, if you can reach settings, check the recovery details on the account:
- Every email address listed, and which one is primary
- Every phone number listed
- Two-factor authentication: on, and set to an authenticator app you control, which LinkedIn's two-factor overview recommends over text messages
- Connected third-party services, listed under Partners & services in your account preferences
An attacker who added their own email address or phone number can use it to take the account back after you reset the password, so remove anything that is not yours.
Minutes 20 to 40: how do you protect your contacts?
A hijacked profile is valuable to an attacker because your contacts trust it. Assume messages have gone out in your name, often with links, payment requests or job offers.
- Message your key contacts by email or phone, not through LinkedIn, to say the account was compromised and to ignore anything recent from it.
- Ask anyone who received something odd to report it. LinkedIn's compromised account page explains how a connection can report a profile as impersonating someone, after which LinkedIn investigates.
- If you run outreach from the profile, pause every sequence and tool connected to it, so nothing else goes out while you clean up.
- If you typed your password into a fake login page, LinkedIn's page on bad links and attachments says to change your password as soon as possible and, if financial details were exposed, to contact your bank and place fraud alerts.
Minutes 40 to 60: what can LinkedIn undo?
Once you have control again, LinkedIn can reverse some of what the attacker did. Its compromised account cleanup page says that, through a request form, it may:
- Move messages the attacker sent into recipients' spam folders or label them with a warning. This covers messages and InMails sent from your profile, Recruiter and Sales Navigator.
- Withdraw invitations that were not accepted, although the email notification for an invitation cannot be withdrawn.
- Remove posts and comments shared during the unauthorised access.
Before you submit it, write down what you saw and when: the first sign, what changed, and what you did at each step. Then review your recent connections, posts, likes and follows, as LinkedIn's compromised account page suggests, and note anything that was not you.
What if LinkedIn restricts the account while you are fixing it?
LinkedIn's account restrictions page says it may restrict an account proactively when it finds signs of a takeover, to protect your information, and that you regain access by verifying your identity. That is protection, not a penalty. Complete the ID check, which only the real owner can pass, and carry on with the steps above once you are in. Our walkthrough of what happens after LinkedIn asks for ID covers the check itself. If the case has turned into a restriction that needs a review, our guide on how to recover a restricted LinkedIn account covers the appeal.
How do you stop it happening again?
- Turn on two-factor authentication on LinkedIn and on the email account behind it.
- Use a unique password, kept in a password manager, which LinkedIn's security tips suggest.
- Add a second email address and a phone number to the account as recovery methods.
- Stop sharing your login. Section 2.2 of LinkedIn's User Agreement asks every member to keep their password confidential and not share their account, and an assistant or agency signing in as you widens the ways in. Our post on sharing LinkedIn login credentials compares the alternatives.
- Treat any email urging you to sign in to avoid suspension as suspect. LinkedIn's phishing page says it will never ask for your password or ask you to download programs, and that you can forward suspicious emails to phishing@linkedin.com.
One last warning about help. LinkedIn's contact page says it has no support phone number, does not charge for support, and will never ask for your password or access to your computer. Sites advertising paid LinkedIn phone support are not LinkedIn. If you want a person to look at your case, our recovery team starts with a free diagnosis and tells you plainly what LinkedIn's process can and cannot do.
Key takeaways
- Secure the email behind your LinkedIn first. Whoever controls it controls every reset.
- If you can sign in, change the password with Require all devices to sign in with new password, and end unknown sessions.
- Submit LinkedIn's Report Unauthorized Account Access or Changes form whether or not you are back in.
- Warn contacts outside LinkedIn, then ask LinkedIn to clean up messages, invitations and posts sent in your name.
- LinkedIn has no support phone line and never asks for your password. Paid phone support sites are not LinkedIn.
Frequently asked questions
How do I get my LinkedIn back if the hacker changed my email?
Choose Forgot password, then Can't access this email? on the code screen. LinkedIn's no-access-to-email flow lets you enter a new email address and then asks for a government ID to confirm you are the owner. Submit the compromised account form as well.
Can LinkedIn delete messages a hacker sent from my account?
Partly. LinkedIn's cleanup page says it can move those messages to recipients' spam folders or add a warning label, withdraw unaccepted invitations, and remove posts and comments made during the takeover. It cannot withdraw the email notifications for invitations already sent.
Does LinkedIn have a phone number for hacked accounts?
No. LinkedIn's contact page says it does not offer a phone number for customer support and does not charge for support. Use the compromised account form and the Help Center.
Will my account be restricted because it was hacked?
It can be. LinkedIn says it may restrict an account proactively when it finds signs of compromise, and that you regain access by verifying your identity. That restriction exists to protect you. Our account recovery FAQ covers what identity verification involves.
I tapped Yes on a sign-in prompt I did not start. What now?
LinkedIn's sign-in prompt page says to go back to the sign-in screen, refresh the page and reset your password as quickly as possible, and to contact LinkedIn if you are locked out.
Should I close my LinkedIn account after a hack?
Usually not. Once you have regained access and secured it, the account keeps its history and network, and LinkedIn's cleanup process can reverse much of what was sent. LinkedIn's data download page says that if you close your account you no longer have access to its data. Recover first, then decide.
Dealing with a restricted account right now? See how TechInRent's LinkedIn account recovery service works.
Want results like these on your LinkedIn?
We run done-for-you outreach + lead generation. Book a free strategy call.
Book a Free Call →