Your Professional Reputation Has a Login Page
A stolen LinkedIn account is a fraud machine wearing your face. Attackers use hijacked profiles to run fake job offers, investment scams, and crypto pitches aimed at your own connections, who trust the message because it comes from you. Recruiters and executives are targeted hardest: their networks are larger and their endorsement carries more weight. By the time you recover the account, the damage to your reputation has already been done in your name.
LinkedIn also suffered one of the larger credential leaks in history years ago, and those old passwords still circulate in credential stuffing lists today. If your LinkedIn password predates that era, assume it's known.
How to Turn On LinkedIn Two-Step Verification
- Click your Me icon (profile photo) → Settings & Privacy.
- Open the Sign in & security tab.
- Click Two-step verification.
- Click Set up and choose your method.
- Confirm your password and follow the prompts.
On mobile: profile photo → Settings → Sign in & security → Two-step verification.
Choose the Authenticator App Method
LinkedIn offers two options:
Authenticator App (Recommended)
- Select Authenticator app as your method.
- LinkedIn shows a secret key or QR code.
- Scan or paste it into Google Authenticator, Authy, Microsoft Authenticator, or any TOTP app.
- Enter the six digit code to confirm.
Codes generate on your device every 30 seconds, immune to SMS interception. The mechanics are in our TOTP explainer, and you can watch a demo secret produce codes in our free 2FA generator.
Phone Number (SMS)
Available, but the weaker choice, and for professionals arguably the riskiest: your name, employer, and often your career history are public on the very platform being protected, which is exactly the data SIM swap social engineers use with carriers. The full attack is described in our SIM swapping guide.
The Recovery Codes Step
After enabling two-step verification, LinkedIn provides recovery codes in the same settings section. Save them in your password manager or print them: they're your way in if your phone is lost. Guidance on storing them well: our backup code storage guide.
LinkedIn Specific Scams to Recognise
- Fake recruiter messages with "job description" attachments that carry malware, or links to "application portals" that harvest credentials. Verify recruiters through the company's official careers page.
- Fake LinkedIn security emails: "Your account will be restricted, verify here." Check the sender domain and never log in through email links: type linkedin.com yourself. Pattern library in our phishing guide.
- Connection requests from cloned profiles of people you already know, used to make later scam messages look credible. Duplicate connection request from a colleague? Confirm through another channel.
- Investment DMs from hijacked accounts: the end use of stolen profiles. If a professional contact suddenly pitches crypto, their account is compromised: tell them outside LinkedIn.
Scams on LinkedIn convert better than anywhere else for one reason: the platform's whole culture is trusting strangers who look professional. 2FA keeps your profile from becoming the next convincing scammer.
Complete the Lockdown
- Review active sessions: Settings → Sign in & security → Where you're signed in. End anything unfamiliar.
- Unique, strong password: especially if yours dates back years. Our generator and strength checker take a minute.
- Confirm your email addresses are current under Sign in & security: recovery flows through them.
- Check connected services (Data privacy → Other applications) and remove stale integrations.
Frequently Asked Questions
Will two-step verification interrupt my daily LinkedIn use?
Barely. Recognised devices stay trusted, so prompts mainly appear on new devices or browsers. The trade of one occasional code for a protected professional identity is heavily in your favour.
I manage a company page. Does 2FA cover it?
Company pages are administered through personal accounts, so the page's security equals the weakest admin's security. Every admin should enable two-step verification, same logic as any shared asset.
What if I lose my phone?
Use a recovery code to sign in, then update your authenticator to the new device. If you have neither phone nor codes, LinkedIn's recovery may involve identity verification with a government ID, which works but takes days. The full prevention checklist is in our lost device guide.
Can I use the same authenticator app as my other accounts?
Yes: LinkedIn's TOTP entry lives happily beside Gmail, Facebook, and the rest in one app. One authenticator for everything is the intended usage.
Does LinkedIn Premium change anything about 2FA?
No: two-step verification is free and identical for all accounts. Premium changes visibility features, not security.