PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

LinkedIn Messages Are a Popular Protocol for Phishing Attacks

By Wesley Grant
November 17, 2025
in Analysts Coverage, Fraud & Security, Ransomware
0
0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
linkedin phishing

serious American businessman with necktie and gray hairs check business project, chat, shopping online via smartphone in modern city. Senior manager using company application to work outside office.

Cybercriminals are expanding their playbook. While email and text remain common phishing channels LinkedIn messages are quickly gaining traction as a new favorite target.

According to The Hacker News, LinkedIn has become an appealing target because many professionals—including company executives—access the platform on corporate devices. At the same time, many organizations haven’t put the same safeguards in place to identify and intercept fraudulent LinkedIn messages as they have for email.

“Social media accounts, including LinkedIn, are increasingly being used by cybercriminals to target employees, consumers, and executives,” said Tracy Goldberg, Director of Cybersecurity at Javelin Strategy & Research. “Beyond the lacking multi-factor authentication (MFA) noted in the article, social media channels give consumers false senses of security, because consumers inherently trust communications that come through social media.”

“Add to that the increasing sophistication of infostealers—which readily compromise credentials for account access by scraping and capturing browsing histories and stored cookies—and consumers are at ever-increasing risk of being manipulated by socially engineered attacks like phishing that prey on their psychological vulnerabilities,” she said.

A Launchpad for Campaigns

Infostealers are a powerful class of malware capable of extracting sensitive data from online sources at an alarming scale. Some experts attribute of billions of stolen personal credentials to these tools, driven in part by the vulnerabilities inherent in social media platforms.

“It’s incredibly easy to just take over legitimate accounts,” Goldberg said. “Some 60% of credentials in infostealer logs are linked to social media accounts, many of which lack MFA—because MFA adoption is far lower on nominally ‘personal’ apps where users aren’t encouraged to add MFA by their employer. This gives attackers a credible launchpad for their campaigns, slotting into an account’s existing network and exploiting that trust.”

Expanding the Scope

Although individuals are often the initial targets of LinkedIn phishing campaigns, the ultimate objective is typically to gain access to a larger organization—especially those with extensive cloud infrastructure.

Once an initial foothold is established, cybercriminals can infiltrate company systems to steal protected data for financial gain or launch ransomware attacks against the organization.

Given the rising costs associated with a single breach, organizations should broaden their phishing training and defensive strategies to specifically account for LinkedIn and other social media platforms.

0
SHARES
0
VIEWS
Share on FacebookShare on TwitterShare on LinkedIn
Tags: FraudinfostealersLinkedInMalwarephishingSocial MediaSpear Phishing

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    chatgpt payments

    How Merchants Should Navigate the Rise of Agentic AI

    January 30, 2026
    fraud passkey

    Why the Future of Financial Fraud Prevention Is Passwordless

    January 29, 2026
    payments AI

    When Can Payments Trust AI?

    January 28, 2026
    Contactless Payment Acceptance Multiplies for Merchants: cashless payment, Disputed Transactions and Fraud, Merchant Bill of Rights

    How Merchants Can Tap Into Support from the World’s Largest Payments Ecosystem

    January 27, 2026
    digital banking

    Digital Transformation and the Challenge of Differentiation for FIs

    January 26, 2026
    real-time payments merchant

    Banks Without Invoicing Services Are Missing a Small Business Opportunity

    January 23, 2026
    card program

    Should Banks Compete in the Credit Builder Card Market?

    January 22, 2026
    real-time payments, instant payments

    Getting Out in Front of Instant Payments—Before It’s Too Late

    January 21, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2024 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result