Site navigation

LinkedIn Accused of Global Browser‑based “Spying Operation”

Tom Quinn

,

Linkedin
A European privacy group has accused LinkedIn of tracking rival tools and building “stolen customer lists” using browser data, claims the platform strongly rejects.

LinkedIn has been accused of running a global “spying operation” after claims that the social platform injects a hidden JavaScript on every computer that visits its website, collecting user data and searching browsers for extensions.

The allegations, dubbed “BrowserGate”, have been published by the Germany-based privacy group Fairlinked, which claims that the Microsoft-owned social site scans users’ devices for more than 6,200 Chromium browser extensions, including those from “every major competitor” to Microsoft’s products.

According to Fairlinked’s investigation, among the extensions being targeted are those from B2B platforms such as Salesforce, Apollo and Lusha, as well as job search tools from the likes of Indeed, Glassdoor, and Monster.  

Fairlinked claims that every time a user opens LinkedIn in a Chrome-based browser, it executes a silent scan probing for specific extensions, then transmits the encrypted results back to its servers, activities which are not laid out in the platform’s privacy policy, said the campaigners.

The privacy group alleged that, because the platform has access to the names, employers, and job titles of logged-in visitors through their LinkedIn profile, these scans effectively create “detailed profiles of companies, institutions and government agencies” that expose the software tools those organisations rely on.

The investigators allege that LinkedIn scans for more than 200 sales and prospecting extensions, totalling 3.4 million users, as well as those from hundreds of software vendors, which they claim allows the platform to build “stolen customer lists” extracted from users’ browsers.

“This is the kind of competitive intelligence that, if obtained by an employee walking out of a company with a USB drive, would result in criminal prosecution,” said Fairlinked.

Going further, Fairlinked accused LinkedIn of a “massive data breach of sensitive data”, arguing that these scans could also reveal users’ political opinions and religious beliefs, employment status, as well as disabilities and neurodivergence.

For example, Fairlinked said that if LinkedIn detects the “Anti-Zionist Tag” or “No more Musk” extensions, it has collected political opinion data tied to a specific person at a specific organisation, or if a user has the PordaAI extension installed, that could indicate an account belongs to a practising Muslim.

“LinkedIn is the world’s largest verified professional directory. It has 1.2 billion registered members across 200 countries…In many industries, having a LinkedIn profile is not optional. It is a prerequisite for being hired,” said Fairlinked campaigners.

“This means LinkedIn does not just know that someone has a religious browser extension installed. It knows that person’s name, employer, job title, department, location, and professional network. And it knows the same about every one of their colleagues who also uses LinkedIn.

“That is not a privacy breach. That is an intelligence operation.”

Fairlined alleged that these practices run contrary to GDPR, specifically Article 9, citing previous rulings by the EU that found data capable of revealing protected characteristics is regulated and restricted, even if a company does not intend to collect this sensitive information. 


Recommended reading


In response, a statement from LinkedIn shared with BleepingComputer said that the allegations are “plain wrong”, and that the person behind Fairlinked’s claims “is subject to an account restriction for scraping and other violations of LinkedIn’s Terms of Service”.

“To protect the privacy of our members, their data, and to ensure site stability, we do look for extensions that scrape data without members’ consent or otherwise violate LinkedIn’s Terms of Service,” reads the statement.

“We use this data to determine which extensions violate our terms, to inform and improve our technical defenses, and to understand why a member account might be fetching an inordinate amount of other members’ data, which at scale, impacts site stability. We do not use this data to infer sensitive information about members.”

LinkedIn argues the allegations trace back to a recent lawsuit filed by an extension developer in Germany suspended from the platform for unauthorised scraping, a case the platform ultimately won.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data