The Business Case for Locking Down Your Profile

LinkedIn is the one social network where your real name, current employer, job title, and years of work history sit in public view by design. That is exactly why a hijacked LinkedIn account is worth more to a criminal than a hijacked Instagram account. A stolen profile is not used to post embarrassing photos. It is used to run investment pitches, fake job offers, and "urgent business opportunity" messages against your actual coworkers, former classmates, and clients, all of whom trust the message because your name and face are attached to it.

The people hit hardest are not random users. Recruiters, hiring managers, sales professionals, and executives carry the biggest networks and the most implicit trust, so their accounts are worth the most effort to steal. If you post under a company page, manage outreach for a business, or your job title includes words like "talent," "recruiting," "founder," or "business development," assume you are a specific target, not a random one.

There is also a data problem specific to LinkedIn. The platform suffered one of the largest credential leaks in internet history years ago, and those old email and password combinations still circulate today in credential stuffing lists that bots run against LinkedIn, Gmail, and banking sites around the clock. If your LinkedIn password predates that breach and you never changed it, treat it as already known to attackers.

Turning On Two-Step Verification

  1. Click your Me icon (your profile photo) in the top navigation and choose Settings & Privacy.
  2. Open the Sign in & security tab in the left menu.
  3. Click Two-step verification.
  4. Click Set up and choose your verification method.
  5. Confirm your password when prompted, then follow the on-screen steps.

On the mobile app the path is nearly identical: tap your profile photo, then Settings, then Sign in & security, then Two-step verification.

Authenticator App vs SMS: The Professional's Choice

LinkedIn gives you two options here, and for professionals the gap between them matters more than it does on a casual account.

Authenticator App (Recommended)

  1. Choose Authenticator app as your method.
  2. LinkedIn displays a secret key or QR code.
  3. Scan it, or paste the key manually, into Google Authenticator, Authy, Microsoft Authenticator, or any standard TOTP app.
  4. Enter the six digit code it generates to confirm setup.

The code rotates every 30 seconds and is generated entirely on your device, so there is nothing traveling over the phone network for an attacker to intercept. If you want to see the math behind that rotation, our TOTP explainer covers it, and our free 2FA generator lets you watch a demo secret produce live codes in your browser.

Phone Number (SMS)

SMS codes work, but they are the weaker option, and for a LinkedIn account specifically they carry an unusual extra risk: your employer, job title, and career trajectory are already public on the exact platform you are trying to protect. That is precisely the kind of personal detail a social engineer reads off your profile before calling your mobile carrier's support line and talking their way into a SIM swap. The mechanics of that attack are covered in our SIM swapping guide. If you have a choice, take the app.

Save Your Recovery Codes Before You Close This Tab

Once two-step verification is active, LinkedIn shows you recovery codes in the same settings section. These are your way back in in if your phone is lost, stolen, replaced, or simply not near you when you need to sign in on a new device. Copy them into your password manager or print a physical copy and store it somewhere safe. Our backup code storage guide walks through the tradeoffs between a password manager entry, a printed sheet, and a safe.

If You Administer a Company Page

Company pages do not have their own login. They are controlled entirely through the personal accounts of whoever LinkedIn lists as an admin, which means a company page's security is only as strong as its weakest admin's personal password and 2FA setup. This becomes a real liability during staff turnover: when a marketing coordinator or social media manager leaves the company, their admin access to the page usually is not revoked the same day, sometimes not for months. Two things fix this. First, every single admin on a company page should have two-step verification turned on, no exceptions, because one unprotected admin account undoes the security of everyone else. Second, page owners should audit the admin list quarterly through Page Settings and remove anyone who has left the organization or changed roles. A former employee with lingering admin rights and no 2FA is a bigger practical risk to most companies than an external hacking attempt.

Scam Patterns Built for LinkedIn's Culture

  • Fake recruiter messages carrying a "full job description" attachment loaded with malware, or a link to an "application portal" that is really a credential harvesting page. Verify unexpected recruiter outreach through the company's own careers page rather than clicking anything in the message.
  • Fake LinkedIn security emails warning that your account will be restricted unless you "verify here." Check the sender's actual domain, and never log in through a link in an email. Type linkedin.com into your browser yourself. Our phishing guide has a fuller pattern library.
  • Cloned connection requests that duplicate the name and photo of someone already in your network, sent so that a later scam message from the fake profile looks credible because you already "know" them. A second connection request from someone you are certain you already added is worth confirming through another channel before you accept.
  • Investment or crypto DMs from a real, previously trustworthy contact. This is usually the end result of a hijacked account, not a new scammer. If a professional contact suddenly starts pitching you an investment opportunity out of nowhere, assume their account is compromised and tell them through a different channel, not LinkedIn itself.

LinkedIn scams convert better than scams on almost any other platform for one simple reason: the entire culture of the site is built around trusting strangers who present themselves professionally. Two-step verification is what keeps your own profile from becoming the next convincing one.

Finish the Rest of the Lockdown

  • Review active sessions under Settings & Privacy > Sign in & security > Where you're signed in, and end any session on a device or browser you don't recognize.
  • Rotate to a strong, unique password if yours is more than a couple of years old. Our password generator and strength checker take under a minute together.
  • Confirm your recovery email addresses are current under Sign in & security, since LinkedIn's account recovery flows run through them.
  • Audit connected third party apps under Data privacy > Other applications, and remove anything you no longer use or don't recognize. Old integrations are a quiet way for an attacker to keep reading your data even after you change your password.

Frequently Asked Questions

Will two-step verification slow down my daily LinkedIn use?

Barely, if at all. Devices and browsers you use regularly stay trusted once verified, so the code prompt mainly shows up on a new phone, a fresh browser install, or after you clear your cookies. Trading one occasional six digit code for a professional identity that cannot be quietly stolen is a heavily lopsided trade in your favor.

I manage a company page. Does turning on my personal 2FA protect the page too?

Yes, and it is required reading if you skipped the section above: a company page's security is the security of its least protected admin, not its best protected one. Every admin needs two-step verification enabled, and the admin list should be reviewed whenever staff change roles.

What happens if I lose my phone?

Use one of your saved recovery codes to sign in, then set up your authenticator app again on the new device. If you have lost your phone and cannot find your recovery codes, LinkedIn's account recovery process may ask for identity verification with a government issued ID, which works but can take several days to process. Our lost device guide has the full prevention checklist so you never have to go through that.

Can I use the same authenticator app for LinkedIn as my other accounts?

Yes. LinkedIn's TOTP setup sits happily alongside Gmail, Facebook, your bank, and everything else in one authenticator app. That is exactly how these apps are meant to be used, one app holding every account's codes rather than a separate app per service.

Does upgrading to LinkedIn Premium change anything about account security?

No. Two-step verification is free and works identically regardless of subscription tier. Premium changes what you can see and who can message you, not how your login is protected.

Should I worry about old LinkedIn data breaches if I already changed my password since?

Less, but not zero. If you reused that old password anywhere else, including on accounts you have since forgotten about, it is still floating in credential stuffing lists and could unlock those other accounts. It is worth a quick pass through a password manager's breach checker for anything you have not touched in years, and pairing that with the QR decoder if you ever need to inspect a suspicious login QR code someone sends you before scanning it blindly.

Shoyeb Akter

Written by

Security Tools Developer and creator of 2FA Fast, a privacy-first browser-based authenticator and security tools platform.