What Are You Revealing on LinkedIn? The Cybersecurity Risks of Oversharing
LinkedIn can expose valuable business intelligence to attackers. Learn how to reduce the risk of reconnaissance, phishing, impersonation and social engineering.
LinkedIn is an incredibly useful business platform. It helps organisations promote their services, recruit employees, build relationships and establish credibility.
But from a cybersecurity perspective, it can also be a valuable reconnaissance tool.
The problem is not usually one individual piece of information. An employee mentioning that they have started a new role is unlikely to create a security incident. A company advertising for a Microsoft 365 administrator is not, by itself, a vulnerability.
The risk comes from aggregation.
An attacker can combine information from LinkedIn with your website, job adverts, DNS records, social media, public documents and other sources to build a surprisingly detailed picture of your organisation.
That information can then be used to identify high-value targets, understand your technology environment, develop convincing phishing attacks and construct believable social-engineering scenarios.
The question for SMEs is therefore not whether they should use LinkedIn.
It is:
What could an attacker learn about your organisation from what you publish publicly?
LinkedIn is a reconnaissance tool
An attacker does not necessarily need to compromise anything to learn a great deal about an organisation.
A company's LinkedIn presence can reveal:
- Employees
- Job titles
- Management structure
- Technologies used
- Office locations
- Customers
- Suppliers
- Projects
- Recruitment activity
- Company growth
- Security responsibilities
Individually, much of this information is harmless.
The security problem is what happens when those pieces of information are combined.
For example, an attacker might discover from LinkedIn who the IT manager is. A job advert might reveal that the organisation uses Microsoft Entra ID, VMware and a particular firewall platform. The company website might reveal employee email addresses, while social media posts reveal that the IT manager is attending a conference next week.
None of those pieces of information necessarily represents a vulnerability.
Together, however, they provide useful intelligence.
This is one of the fundamental principles of OSINT, or Open-Source Intelligence: information that is publicly available can become considerably more valuable when different sources are correlated.
Your employees can reveal your organisational structure
An employee's LinkedIn profile might describe them as:
IT Manager
Microsoft 365 Administrator
Responsible for Cybersecurity
Managing the company's Azure environment
That tells an attacker considerably more than simply:
Employee at Example Ltd.
It can help identify people responsible for:
- IT administration
- Finance
- HR
- Development
- Procurement
- Security
- Helpdesk
- Senior management
This matters because attackers rarely need to target everybody.
They can concentrate their efforts on the people most likely to have access to sensitive systems, financial information or administrative functions.
Job titles can identify high-value targets
Imagine an attacker finds the following profiles:
Global Administrator
Finance Director
Accounts Payable Manager
IT Support Manager
These are potentially attractive targets.
A generic phishing email sent to an arbitrary employee may be ignored. A carefully constructed message aimed at someone with financial authority or administrative privileges can be considerably more effective.
For example, an attacker who knows the Finance Director's name and role might attempt to impersonate a supplier, another director or a member of the finance team.
Likewise, identifying the person responsible for Microsoft 365 administration gives an attacker an obvious target for an account-compromise campaign.
This is why job titles can be more useful to an attacker than they initially appear.
"We're migrating to Microsoft 365"
Seemingly innocent announcements can also disclose useful technical information.
An employee might post:
"Excited to be leading our Microsoft 365 migration!"
Or:
"We've just moved our CRM to Salesforce."
For a marketing audience, these may be perfectly reasonable announcements.
For an attacker, they can reveal:
- Technology platforms
- Cloud providers
- Identity providers
- Software applications
- Suppliers
- Project timelines
- Organisational changes
More importantly, the information provides context for future attacks.
A phishing email referring to a Microsoft 365 migration is considerably more plausible if the attacker already knows that the organisation is actually migrating to Microsoft 365.
The attacker does not have to guess the pretext.
The organisation has potentially provided it.
Job adverts can reveal your attack surface
Job advertisements are particularly interesting from a security perspective.
Consider an advert looking for a systems administrator with experience managing:
- Windows Server 2022
- VMware
- FortiGate firewalls
- Veeam
- Microsoft Entra ID
The advert has effectively disclosed part of the organisation's technology stack.
An attacker may be able to identify:
- Operating systems
- Firewalls
- VPN technologies
- Cloud platforms
- Security products
- RMM platforms
- Programming languages
- Databases
- Remote-access technologies
- Virtualisation platforms
This is especially useful when combined with other sources.
For example, a company might publish a job advert mentioning a particular technology. An attacker could then research that product, identify its common vulnerabilities and determine whether there are public-facing components associated with the organisation.
The organisation has effectively published an inventory of technologies it uses.
Unlike a vulnerability scan, the organisation has provided the information voluntarily.
This does not mean technical information should never appear in job adverts. Recruitment often requires candidates to understand the technologies they will be working with.
It does mean that organisations should consider whether every technical detail in an advert needs to be publicly disclosed.
Announcing new customers can help attackers
Businesses naturally want to announce new customers.
A post such as:
"We're delighted to welcome XYZ Ltd as our newest customer."
may be excellent marketing.
It can also reveal a business relationship that an attacker could later exploit.
An attacker might attempt to impersonate:
- The new customer
- An existing supplier
- An employee
- A director
- A business partner
For example:
"Hi Sarah, following our recent onboarding with XYZ, could you send over the account details?"
The request may appear credible because the attacker knows that the two organisations really do have a relationship.
This is an important characteristic of modern social engineering.
The attacker does not necessarily need to invent a convincing story from scratch. They can construct one from information the target organisation has already made public.
"Starting a new job" posts are surprisingly useful
People frequently announce new jobs on LinkedIn:
"Excited to join Example Ltd as Head of Finance!"
This provides several useful pieces of information at once:
- The person's name
- Their employer
- Their position
- Their approximate start date
- Their previous employer
- Their professional history
An attacker could use this information to create a targeted phishing campaign.
For example:
"Welcome to Example Ltd. Please complete your new starter Microsoft 365 registration..."
The message becomes more convincing because the attacker knows that the recipient really has just started a new job.
The attacker may also know who their manager is, what their previous employer was and what responsibilities they are likely to have.
Again, the information itself is not necessarily sensitive.
The combination is what creates the risk.
Don't forget conference and event posts
Posts about conferences, exhibitions and business events can reveal:
- Where employees will be
- When they may be away from the office
- Who they are meeting
- What projects they are discussing
- Which suppliers or partners they work with
For example:
"Heading to Manchester tomorrow for three days at [event]."
There is nothing inherently wrong with posting this.
But organisations should consider what an attacker could infer from the wider context.
The point is not that employees should never mention where they are going.
It is:
Think about what an attacker could infer by combining the information you are publishing.
Photos can reveal more than the caption
Images are another frequently overlooked source of information.
A photograph from an office might unintentionally expose:
- Office layouts
- Computer screens
- Whiteboards
- ID badges
- Door access systems
- Equipment
- Server rooms
- Network equipment
- Company documents
- Customer information
A caption might simply say:
"Our new office is finally ready!"
But the photograph could reveal considerably more.
A whiteboard in the background might contain project names. A computer monitor could display an application or internal hostname. A photograph of a server room might reveal hardware vendors or network infrastructure.
Before publishing photographs, consider the entire image rather than just the subject of the photograph.
Personal information can make phishing more convincing
LinkedIn profiles often contain a considerable amount of personal and professional information, including:
- Previous employers
- University
- Professional qualifications
- Location
- Interests
- Colleagues
- Career history
Attackers can use these details to construct believable conversations.
For example:
"I saw you worked at [previous employer]..."
That might be enough to establish familiarity and encourage the recipient to continue a conversation.
This isn't necessarily sophisticated hacking.
It is social engineering supported by publicly available information.
The more information an attacker has about a target, the easier it becomes to make an attack appear legitimate.
LinkedIn can help attackers map relationships
Another useful concept is relationship mapping.
An attacker may be able to determine relationships such as:
CEO
↓
Finance Director
↓
Accounts Manager
↓
External Accountant
Or:
CEO
↓
IT Manager
↓
MSP
↓
Security Provider
This information can help an attacker decide who to impersonate and who to contact.
For example, rather than sending a generic request to an accounts employee, an attacker could impersonate a known supplier and reference an existing relationship.
Alternatively, they might impersonate an employee's manager and make a request that appears to be part of an existing business process.
The more accurate the relationship map, the more credible the pretext can become.
The problem isn't LinkedIn. It's uncontrolled information disclosure.
It is important not to overreact.
The answer is not:
"Don't use LinkedIn."
LinkedIn is an important business and marketing platform. For many organisations, having an active presence is essential.
The answer is to treat publicly available information as part of the organisation's attack surface.
Employees do not need to become secretive.
They need to understand the security implications of what they publish.
The objective is not to prevent legitimate marketing, recruitment or professional networking. It is to reduce unnecessary disclosure and make it harder for an attacker to assemble a detailed picture of the organisation.
What should employees think about before posting?
Before publishing something, consider whether it reveals:
- Internal technologies
- Security products
- Administrative responsibilities
- Customer relationships
- Supplier relationships
- Office locations
- Travel plans
- Internal project names
- System migrations
- Security controls
- Screens or documents
- Information about colleagues that could facilitate impersonation
A useful question is:
Could an attacker use this information to make a phishing or social-engineering attack more convincing?
If the answer is yes, consider whether the information needs to be published, or whether it could be presented in a less detailed way.
What should businesses do?
SMEs do not need to ban LinkedIn.
There are several practical measures they can introduce instead.
Establish a social-media policy
Define the types of information that should not be publicly disclosed.
This should cover employees as well as company marketing and recruitment activity.
Train employees
Training should explain why information matters rather than simply providing a list of things employees are not allowed to post.
People are more likely to make sensible decisions when they understand how seemingly harmless information can be abused.
Review job advertisements
Recruitment teams should consider the security implications of technical information before publishing job adverts.
There may be a legitimate reason to specify required technologies, but unnecessary detail should be avoided.
Review company posts
Marketing teams should understand that technical announcements, customer announcements and photographs can all contribute to an organisation's publicly visible attack surface.
Review public profiles
Senior staff, IT administrators, finance personnel and other high-value targets should be particularly conscious of the information they make publicly available.
Conduct periodic OSINT assessments
Organisations can periodically assess what an external party can discover about them using publicly available information.
This can be surprisingly revealing.
What can an attacker build from public information?
Consider how information from several different sources can be combined:
LinkedIn
→ Employees and organisational structure
Company website
→ Email addresses and business information
Job adverts
→ Technology stack
DNS
→ Public infrastructure
GitHub
→ Developers and projects
Social media
→ Locations and relationships
Public documents
→ Metadata, usernames and other technical information
None of these necessarily represents a vulnerability by itself.
Together, they can form an extremely useful reconnaissance dataset.
This is why cybersecurity cannot be reduced to vulnerabilities in software and configuration.
Sometimes the first stage of an attack is simply understanding the target.
The penetration-testing perspective
OSINT and reconnaissance are important components of an external penetration test.
A tester may ask:
What could an attacker learn about this organisation without sending a single packet to its infrastructure?
The objective isn't necessarily to find secret information.
It is to understand the organisation's externally visible attack surface and determine how readily an attacker could use publicly available information to identify targets, technologies, relationships and potential attack paths.
This can provide a different perspective from a traditional vulnerability assessment.
A vulnerability scanner might tell you that a particular service is exposed.
An OSINT assessment might tell you why an attacker would know that the service exists, who is likely to manage it and how they might construct a convincing attack against the organisation's employees.
That context matters.
Final takeaway
The information you publish on LinkedIn can become part of an attacker's reconnaissance.
A job title, a new customer announcement or a photograph from the office may seem insignificant. Combined with information from other public sources, however, those details can help an attacker identify high-value targets, understand your technology environment and construct highly convincing phishing or social-engineering attacks.
The answer isn't to stop using LinkedIn. It's to understand that publicly available information is part of your security perimeter.
For SMEs, a useful starting point is to look at your organisation from an attacker's perspective.
Search for your company.
Look at your employees.
Review your job adverts.
Examine your public documents.
Look at your DNS.
Review your social-media activity.
Then ask:
If I were trying to attack this organisation, what could I learn without having to break into anything?
You may be surprised by the answer.
Put this into practice.
Cyber Essentials, Cyber Essentials Plus, and penetration testing — fixed-price, plain English, and built to stay out of your way.