LinkedIn has been accused of running a global “spying operation” after claims that the social platform injects a hidden JavaScript on every computer that visits its website, collecting user data and searching browsers for extensions.
The allegations, dubbed “BrowserGate”, have been published by the Germany-based privacy group Fairlinked, which claims that the Microsoft-owned social site scans users’ devices for more than 6,200 Chromium browser extensions, including those from “every major competitor” to Microsoft’s products.
According to Fairlinked’s investigation, among the extensions being targeted are those from B2B platforms such as Salesforce, Apollo and Lusha, as well as job search tools from the likes of Indeed, Glassdoor, and Monster.
Fairlinked claims that every time a user opens LinkedIn in a Chrome-based browser, it executes a silent scan probing for specific extensions, then transmits the encrypted results back to its servers, activities which are not laid out in the platform’s privacy policy, said the campaigners.
The privacy group alleged that, because the platform has access to the names, employers, and job titles of logged-in visitors through their LinkedIn profile, these scans effectively create “detailed profiles of companies, institutions and government agencies” that expose the software tools those organisations rely on.
The investigators allege that LinkedIn scans for more than 200 sales and prospecting extensions, totalling 3.4 million users, as well as those from hundreds of software vendors, which they claim allows the platform to build “stolen customer lists” extracted from users’ browsers.
“This is the kind of competitive intelligence that, if obtained by an employee walking out of a company with a USB drive, would result in criminal prosecution,” said Fairlinked.
Going further, Fairlinked accused LinkedIn of a “massive data breach of sensitive data”, arguing that these scans could also reveal users’ political opinions and religious beliefs, employment status, as well as disabilities and neurodivergence.
For example, Fairlinked said that if LinkedIn detects the “Anti-Zionist Tag” or “No more Musk” extensions, it has collected political opinion data tied to a specific person at a specific organisation, or if a user has the PordaAI extension installed, that could indicate an account belongs to a practising Muslim.
“LinkedIn is the world’s largest verified professional directory. It has 1.2 billion registered members across 200 countries…In many industries, having a LinkedIn profile is not optional. It is a prerequisite for being hired,” said Fairlinked campaigners.
“This means LinkedIn does not just know that someone has a religious browser extension installed. It knows that person’s name, employer, job title, department, location, and professional network. And it knows the same about every one of their colleagues who also uses LinkedIn.
“That is not a privacy breach. That is an intelligence operation.”
Fairlined alleged that these practices run contrary to GDPR, specifically Article 9, citing previous rulings by the EU that found data capable of revealing protected characteristics is regulated and restricted, even if a company does not intend to collect this sensitive information.
Recommended reading
- 1 in 4 Privacy Pros Expecting a Major Breach in 2026
- How Prepared Are You For The Inevitable Data Breach?
- 45 Years of Data Privacy: Why 2026 Feels Riskier Than Ever
In response, a statement from LinkedIn shared with BleepingComputer said that the allegations are “plain wrong”, and that the person behind Fairlinked’s claims “is subject to an account restriction for scraping and other violations of LinkedIn’s Terms of Service”.
“To protect the privacy of our members, their data, and to ensure site stability, we do look for extensions that scrape data without members’ consent or otherwise violate LinkedIn’s Terms of Service,” reads the statement.
“We use this data to determine which extensions violate our terms, to inform and improve our technical defenses, and to understand why a member account might be fetching an inordinate amount of other members’ data, which at scale, impacts site stability. We do not use this data to infer sensitive information about members.”
LinkedIn argues the allegations trace back to a recent lawsuit filed by an extension developer in Germany suspended from the platform for unauthorised scraping, a case the platform ultimately won.





