Sep 22, 2026 · 7 min read
LinkedIn Wins Order to Kill ProAPIs' Profile Scraping
A federal court in the Northern District of California has entered a consent judgment permanently barring ProAPIs and Netswift from scraping LinkedIn, selling what they took, or touching the site through fake accounts again. The interesting part is not the win. It is which legal theory did the work.
Somebody paid up to 15,000 dollars a month for a live feed of other people's careers. ProAPIs sold it as an API, marketed as a real time LinkedIn data fetcher and, per LinkedIn's complaint, supplied from a rotating pool of over a million counterfeit accounts. That business is now under a permanent injunction.
Key Takeaways
- A consent judgment in LinkedIn Corporation v. ProAPIs Inc., case 5:25-cv-08393 in the Northern District of California, permanently bars ProAPIs, Netswift and cofounder Rehmat Alam from scraping LinkedIn; The Record reported it was finalized on September 21, 2026.
- LinkedIn filed in October 2025, alleging the defendants spun up hundreds or thousands of fake accounts a day, each harvesting hundreds of profiles before detection caught it.
- The order forces them to stop scraping, stop selling scraped data, stop using fraudulent accounts, and delete everything already taken.
- The 2022 Ninth Circuit ruling in hiQ Labs v. LinkedIn held that scraping public pages is not unauthorized access under the Computer Fraud and Abuse Act, yet hiQ still ended up enjoined and paying LinkedIn 500,000 dollars for breach of contract.
- A consent judgment binds only its signatories, so every other scraper reselling LinkedIn profiles this morning is still reselling them tonight.
What Does the Order Require?
The judgment permanently prohibits ProAPIs, its joint operator Netswift, and their employees from reaching LinkedIn data through fake accounts, bots or other automated technology, and from selling it to anyone. It also compels deletion of the archive already built. The docket sits on CourtListener and govinfo.
What was taken is broader than a name and a title. The complaint lists member profiles, company pages, school details, posts, comments and reactions. Reactions are the part people forget they publish. Sarah Wight, who runs litigation and enforcement at LinkedIn, framed the outcome around ownership: your profile is yours, and what you share is meant for the professional community you are building, not for an outside company to scrape.
One caveat. A consent judgment is a negotiated settlement entered as a court order, not a merits ruling. No judge weighed the evidence; the defendants agreed to stop, and the court made that promise enforceable with contempt. Reporting did not name the judge.
Why Didn't hiQ v. LinkedIn Protect ProAPIs?
Because hiQ was about public pages and no accounts, and this case is about a million fake ones. In April 2022 the Ninth Circuit affirmed in hiQ Labs v. LinkedIn that scraping publicly accessible web pages is not access "without authorization" under the CFAA. Where no password gates the door, blocking one visitor does not make that visitor a hacker. That holding is why "scraping is legal" became internet common sense.
It is also why the common sense is wrong. In November 2022 the district court found hiQ had breached LinkedIn's User Agreement, holding that contract terms banning scraping and fake profiles are enforceable, an outcome Fenwick summarized at the time. A month later hiQ accepted a 500,000 dollar judgment and a permanent injunction requiring it to destroy every algorithm trained on scraped profiles. The company that supposedly legalized scraping was liquidated by it.
ProAPIs sat on the wrong side of that line from day one. Creating an account means clicking through the User Agreement, which turns every later request into a contract question rather than a hacking question. Creating a million of them, per the complaint using invalid credit cards for Premium access, adds fraud on top. The lesson: after hiQ, the CFAA is largely a dead end for platforms, and contract is where enforcement lives.
Who Buys Scraped LinkedIn Data?
Sales teams, mostly, and the pricing tells you how badly they want it. BleepingComputer reported that ProAPIs charged up to 15,000 dollars a month for a tier delivering 150 requests per second. One customer at that ceiling could issue roughly 13 million profile requests a day. That is not a recruiter checking candidates. That is a pipeline.
The downstream market is sales intelligence and cold outreach. A scraped profile alone is not directly monetizable, because LinkedIn does not hand out work email addresses. So the profile gets joined to a second service: take the name and the employer, generate every plausible address format against the company domain, then verify which one accepts mail. Name plus company equals a verified work inbox, at scale, from data you thought only colleagues saw. That market has been fed for years. A 2021 forum listing offered records on 700 million LinkedIn users, roughly 92 percent of the platform at the time, assembled by scraping rather than intrusion.
Why Email Users Should Care
The same enriched record that powers a cold sales sequence powers a spear phishing campaign, and neither buyer has to prove which one they are. Hand an attacker your verified work address plus your title, your reporting line and the projects you have posted about, and generic spam becomes a message naming your actual manager. Business email compromise runs on exactly that specificity.
LinkedIn is already a staging ground for this. We covered a phishing run that impersonated official LinkedIn warnings to harvest credentials, and separately looked at what LinkedIn's own emails record when you open them. The scraped profile is the ingredient that makes the pretext write itself.
The arithmetic has an uncomfortable implication. A million fake accounts each pulling hundreds of profiles does not reach a slice of LinkedIn; it reaches all of it, several times over. Assume your professional graph has already been copied, sold, and joined to an email address by somebody who is not a defendant here.
What a Scraper Can Rebuild About a Journalist
For a reporter, an NGO researcher or anyone with a real threat model, the exposure is not the profile page. It is the reconstruction. Employer and start date give a timeline. Connections give colleagues and, by inference, sources. School details give a hometown and a graduation year, which is half a security question. Reactions and comments, both named in the complaint, reveal leanings and who you engage with. None of it requires a breach, only a logged in account and patience. Same problem the Committee to Protect Journalists flagged when commercial ad tech location data turned out to be buyable on journalists: a legitimate market produces a surveillance capability as a side effect, then sells it to whoever pays.
What Can You Actually Change in Your Settings?
Four settings are worth an audit, and one honest limit applies to all of them:
- Public profile visibility. Turning your profile's public visibility off removes you from search engines and from anyone not signed in.
- Section controls. LinkedIn lets you choose which sections appear publicly, so education and past roles can come off while your current title stays on.
- Connections. Under Visibility, who can see your connections defaults to your first degree contacts. Switching it off removes the easiest way to map your network.
- Activity broadcasts. Silence updates about job changes and profile edits so a career move is not announced the day it happens.
Now the limit. None of it stops the attack in this case. ProAPIs was signed in as a million members, and a fake account sees what any member sees. Those settings defend against search engines and strangers, not a scraper wearing a member badge. What is left is deciding what goes on the profile at all. LinkedIn also runs aggressive collection of its own, including the browser extension enumeration we documented in April.
Looking Ahead
LinkedIn has taken two scraping operations off the board in five months, and that cadence matters more than either win. Litigation removes named defendants, not demand. While sales intelligence and AI training both want the same professional graph, the next ProAPIs is already selling subscriptions. The docket will show whether the deletion obligation gets audited or merely promised.
Watch the contract theory. If courts keep enforcing user agreement terms against scrapers while the CFAA stays narrowed by hiQ, terms of service become the operative privacy law for public profile data in the United States: written by the platform, enforced at its discretion, and unenforceable by the person whose data it is.