Topics Tools Books & Guides Talk to Securafy

Knowledge Hub / IT Operations

IT Operations

Beware of LinkedIn Smart Links Phishing Attacks

Beware of LinkedIn Smart Links Phishing Attacks

Randy Hall By Randy Hall Updated Jul 2024 4 min read Share

Cybercriminals commonly use phishing attacks to trick vulnerable users into giving away sensitive information. The latest threat of this kind targets LinkedIn users who use the Smart Links feature on the social media platform. This guide explains what you should know about the LinkedIn Smart Links phishing attacks and how to protect yourself. 

Basics of This Phishing Campaign

The email security research firm Cofense first uncovered this latest attack to hit LinkedIn. Cofense concluded that this campaign uses at least 80 Smart Links throughout 800 phishing messages. No matter which business or sector you work in, there's a chance that you could fall victim to this campaign since Cofense reports that these criminals sent phishing pages to workers in the following industries:

  • Construction
  • Mining
  • Healthcare
  • Insurance
  • Technology

The report points to workers in finance and manufacturing having higher volumes of phishing messages sent their way.

How Threat Actors Execute LinkedIn Smart Links Phishing Attacks

The cybercriminals who carry out this attack devise a plan consisting of a few phases. Below, we break down each phase and how it ultimately leads LinkedIn users to click on suspicious links that give hackers personal account credentials. 

Hackers Create or Hijack Business Accounts

The plan begins with threat actors using a LinkedIn business account to deceive vulnerable users. They either create a brand-new account or use an existing one that was stolen from a previous attack. Once the account is ready, they can use LinkedIn's Sales Navigator service to send Smart Links to other users. 

This feature works great for benign use because it allows accounts to track how recipients interact with the message. Business leaders can use this to their advantage for pitching new products. However, hackers manipulate the links to steal information. 

Cybercriminals Send Phishing Messages

Using a business account under an actual LinkedIn domain, hackers can use the Smart Links feature to send phishing messages to vulnerable users. These messages aim to trick users by mimicking legitimate senders with content regarding the following:

  • Hiring
  • Payment
  • Security notifications
  • Important documents

The message contains a link that will send users to a malicious site. Once hackers get victims to click on these fake links, they can obtain their credentials.

Information Is Stolen

The primary goal of this phishing campaign is to steal Microsoft account credentials from a business's LinkedIn account. Hackers can get this information once they get people to fall for their scam messages and click the link. Cybercriminals can continue with their attack once someone ends up on the credential-harvesting site. 

Rather than creating a new account, they can steal the information of other businesses and impersonate those brands. This increases the chance of getting more users to believe the phony messages. 

Keep Your Business Safe From Cyber Threats

Staying aware of emerging threats like the LinkedIn Smart Links phishing attacks can help you avoid malicious activity online. Help your business stay safe by contacting our experts for more tips on mitigating attacks. 

 

Join The Conversation

Have a question or perspective on this topic? Add it below.

Randy Hall

About The Author

Randy Hall · CEO & Founder

Randy Hall is the CEO and Founder of Securafy, with decades of experience helping organizations make smarter, safer decisions about technology.

A frequent speaker and instructor at national IT events, Randy has advised thousands of organizations, from startups and SMBs to large enterprises and U.S. government entities, on secure, practical technology adoption. He writes about the decisions business leaders are often expected to make without enough context, including cybersecurity, compliance, AI, cyber insurance, IT strategy, and business resilience.

Outside the office, you’ll often find Randy on Lake Erie enjoying time on his 38-foot Chris-Craft.

Writes about: Cybersecurity strategy, compliance, AI security, business resilience, cyber insurance, SMB risk, IT leadership

More From This Author →

Get Practical Cybersecurity Field Notes

Monthly cybersecurity, compliance, and IT strategy updates from Securafy, written for business owners who need clear next steps.

  • Practical security tips from our Cyber Security Drip series
  • The Securafy Times, our monthly roundup on compliance and IT strategy
  • Occasional updates on new tools, guides, and research
  • No spam — unsubscribe anytime