People search LinkedIn data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 8 LinkedIn-linked incidents, with headline counts up to 700M+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why LinkedIn breach history matters
LinkedIn operates in Social Media (United States). Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2021 — 700M records
Cataloged incident. An attacker used automated scraping to collect data from LinkedIn profiles. A dataset of roughly 700 million users was put up for sale, including full names, email addresses, phone numbers, and other profile data. LinkedIn stated this was scraping of public profile data combined with data from other sources, not a new breach of their systems. Exposed categories include Email addresses, Names, Addresses, Phone numbers. BreachHistory cites approximately 700M+ affected records in this row. See the exyj and canonical BreachHistory entry.
2021 — — Linkedin: Hacking, 70,000,000 records
Cataloged incident. The hacker appears to have misused the official LinkedIn API to scrape the data, the same method used in a similar breach back in April. Exposed categories include Personal and demographic data. BreachHistory cites approximately 70M+ affected records in this row. See the linkedin2021-iib and canonical BreachHistory entry.
2016 — — LinkedIn: What initially seemed to be a theft of 6, 117.0M records
Cataloged incident. May 2016. What initially seemed to be a theft of 6.5 million passwords has actually turned out to be a breach of 117 million passwords. BreachHistory cites approximately 117M+ affected records in this row. See the linkedin2016 and canonical BreachHistory entry.
2013 — — LinkedIn: A breach that involved keylogging software affected…
Cataloged incident. A breach that involved keylogging software affected at least 93,000 websites. The virus may have originated on a server located in the Netherlands. It first started collecting passwords and usernames on October 21. Approximately 860 computers in the United States were affected. More than 99% of the computers that were affected were outside of the United States. Exposed categories include Personal information. BreachHistory cites approximately 2M+ affected records in this row. See the linkedin2013 and canonical BreachHistory entry.
2012 — password breach (hashes leaked 2016)
Cataloged incident. In 2012 LinkedIn suffered a breach where password hashes were stolen. The hashes were SHA-1 without per-user salts. In 2016 a trove of 164 million email and hashed password pairs was put up for sale; many hashes were cracked due to weak hashing. Exposed categories include Email addresses, Passwords (hashed). BreachHistory cites approximately 164M+ affected records in this row. See the dhrs and canonical BreachHistory entry.
2012 — — LinkedIn: Hacker 'dwdm' uploaded a file containing 6, 8.0M records
Cataloged incident. Hacker 'dwdm' uploaded a file containing 6.5 million passwords on a Russian hacker forum. Soon after another 1.5 million passwords were discovered. On analysis, 93% of the passwords could be found in the Top 10,000 password list. BreachHistory cites approximately 8M+ affected records in this row. See the linkedinu and canonical BreachHistory entry.
2012 — — LinkedIn: Information about a 2012 data breach has just come…
Cataloged incident. Information about a 2012 data breach has just come to light. BreachHistory cites approximately 117M+ affected records in this row. See the linkedinu1 and canonical BreachHistory entry.
2012 — 6.5M passwords (scope later 117M)
Cataloged incident. June 2012 breach. Passwords posted on forums. Scope expanded to 117M in 2016. Yevgeniy Nikulin convicted. Exposed categories include Email addresses, SHA-1 hashed passwords (unsalted). BreachHistory cites approximately 6.5M+ affected records in this row. See the linkedin2012 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple LinkedIn catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the LinkedIn company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/linkedin · Latest: exyj.
Sources: BreachHistory catalog (8 rows for LinkedIn), company and regulator disclosures cited in individual breach records.