The post LinkedIn DM Attack Warning — What Users Need To Know appeared on BitcoinEthereumNews.com. Beware the latest LinkedIn attack, security experts warn. NurPhoto via Getty Images Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence. ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For BillionsBy Davey Winder LinkedIn Users Warned To Beware This New Direct Message Attack The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource. ​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.” In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is… The post LinkedIn DM Attack Warning — What Users Need To Know appeared on BitcoinEthereumNews.com. Beware the latest LinkedIn attack, security experts warn. NurPhoto via Getty Images Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence. ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For BillionsBy Davey Winder LinkedIn Users Warned To Beware This New Direct Message Attack The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource. ​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.” In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is…

LinkedIn DM Attack Warning — What Users Need To Know

2025/10/31 21:21

Beware the latest LinkedIn attack, security experts warn.

NurPhoto via Getty Images

Gmail passwords leaked, PayPal users warned of attacks, even Twitter, sorry X, issuing an account lockdown warning, are all, sadly, par for the cybersecurity news headlines course these days. What isn’t is attacks that focus on LinkedIn, the professional and business networking platform that boasts more than a billion users. If you are one of them, then I apologize, but you need to be aware of just such an occurrence.

ForbesWhatsApp Confirms Sudden Backup Passkey Security Move For Billions

LinkedIn Users Warned To Beware This New Direct Message Attack

The last time I wrote a LinkedIn-specific news story was way back in February, when I warned of a Lazarus attack that targeted the wrong user. That LinkedIn doesn’t feature more in security news reports is a good thing; it means the platform is doing something right. This latest warning, however, is worth taking seriously, as the attackers are targeting the right users — at least in terms of potentially profitable outcomes. Push Security researcher Dan Green has confirmed that business executives on the networking platform are vulnerable to a “high-risk LinkedIn phishing attack,” via the LinkedIn direct messaging resource.

​​This is particularly worrying because LinkedIn itself, “while often used for work and commonly accessed from corporate devices,” Green warned, “sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot.”

In the case detailed by Green, in technical glory for those who like such things, the victim received a malicious LinkedIn direct message which redirected them a total of three times, through Google Search, a supposed payroll site and ultimately to a custom landing page hosting various documents. “Upon clicking on one of the document links on the page, the victim is prompted to view with Microsoft,” and, well, you can probably guess the rest. A cloned Microsoft page requires credentials to be entered and 2FA authentication to be completed, at which point the attacker has that Microsoft session stolen.

ForbesGoogle Chrome Crash Warning For 3 Billion — No Fix Available

LinkedIn As An Attack Platform Is A Clever Move By Scammers

Using LinkedIn to launch such attacks is a clever move by threat actors, not least as many users will be expecting contacts from outside of their organization to talk about work. By not using email, this also adds to the detection-evasion toolkit. The attackers then used a chain of legitimate sites to avoid being flagged as suspicious and to cloak the ultimate URL destination..

“Just because the attack happens over LinkedIn doesn’t lessen the impact,” Green said, “these are corporate credentials and accounts being targeted, even if it is nominally a ‘personal’ application.”

I reached out to LinkedIn, and a spokesperson provided the following statement: “Sophisticated phishing scams are a problem across the internet, and our teams use a variety of automated technology and trained investigation experts to detect and stop harmful behavior. Our free verification features enable members to make more informed decisions on who they’re interacting with. We also proactively share safety tips including how to report any suspicious messages to us, and how to enable the optional advanced safety feature which can help identify potentially harmful or fraudulent content.”

ForbesGoogle Security Gets Game As Inoculation Theory Put To The Test

Source: https://www.forbes.com/sites/daveywinder/2025/10/31/linkedin-dm-attack-warning—what-users-need-to-know/

Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact service@support.mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.
Share Insights

You May Also Like

Filecoin (FIL) Rises Over 4% as Token Rebounds

Filecoin (FIL) Rises Over 4% as Token Rebounds

The post Filecoin (FIL) Rises Over 4% as Token Rebounds appeared on BitcoinEthereumNews.com. FIL$1.5382 posted a 4.3% gain over the last 24 hours, amidst a rally in wider crypto markets, bouncing from yesterday’s big declines. The broader market gauge, the CoinDesk 20 index, was 2.5% higher at publication time. The decentralized storage token traded from a low of $1.40 to highs near $1.52, as traders tested critical support and resistance levels within an ascending channel structure, according to CoinDesk Research’s technical analysis model. The model showed a key development hit at Oct. 30 17:00 when volume spiked to 5.46 million tokens. This was 98% above the 24-hour moving average. The surge coincided with a decisive low at $1.41, according to the model. Critical support held firm on subsequent retests. Each recovery wave showed increasing buying interest on declining volume. This suggests institutional accumulation above the $1.41 zone. Technical Analysis: Critical support established at $1.41 with secondary support at $1.48; resistance emerging near $1.52 with potential extension to previous highs High-volume accumulation pattern at $1.41 support with 98% surge above average; declining volume on subsequent rallies suggested controlled institutional buying Ascending channel structure intact with higher lows pattern; $1.516 ceiling test successful with measured retreat Upside target at $1.52 resistance zone; risk management below $1.41 support with stop-loss considerations around $1.38 for aggressive positions Disclaimer: Parts of this article were generated with the assistance from AI tools and reviewed by our editorial team to ensure accuracy and adherence to our standards. For more information, see CoinDesk’s full AI Policy. Source: https://www.coindesk.com/markets/2025/10/31/filecoin-rises-over-4-rebounding-from-thursday-s-drop
Share
BitcoinEthereumNews2025/11/01 11:45
$300M Frozen as Crypto Crime Unit Boosts Global Financial Crime Prevention

$300M Frozen as Crypto Crime Unit Boosts Global Financial Crime Prevention

The post $300M Frozen as Crypto Crime Unit Boosts Global Financial Crime Prevention appeared on BitcoinEthereumNews.com. Global momentum against crypto crime is accelerating as Tether, TRON, and TRM Labs drive a powerful enforcement alliance that has frozen over $300 million in illicit assets, redefining blockchain’s role in global financial integrity and security. Global Crackdown on Crypto Crime Advances as $300M in Assets Frozen Global cooperation against crypto-related financial crime is accelerating […] Source: https://news.bitcoin.com/300m-frozen-as-crypto-crime-unit-boosts-global-financial-crime-prevention/
Share
BitcoinEthereumNews2025/11/01 12:33