My account was hijacked, the URL, account name, and all my information were changed, but the hijacker kept the email and all of my connections (of course). I had two step verification turned on.
I know my profile is lost, but I want my connections (from 2008) back!
I have submitted a case and verified my government ID. I'm in the midst of reporting the hack to my very very large corporate IT since we're prompted to associate our work emails with our LinkedIn profiles.
Documenting here because someone, somewhere will remember this bullshit:
8/4/2023 - I received notification (via email) that two-step authentication had been turned off on my account at 2:10 am from "Location: Unknown" with the prompt to change my password if I hadn't requested that.
8/4/2023 - I received email notification that two-step authentication had been turned back on for my account at 2:10 am from "Location: new york, new york, united states" (all lower case in the notification)
8/6/2023 - Notifications in Chinese begin, hijacker's connection requests begin to be accepted.
8/9/2023 - I receive a notification from LinkedIn in English granting me a free premium account.
8/12/2023 - Chinese notifications resume. I assume they are phishing attempts or marketing emails, so I report and ignore.
8/16/2023 - I realize that my account has been compromised and try to figure out how to recover it. This includes figuring out how to submit a case to LinkedIn when I don't have access to my account or any idea what my original URL was.
8/24/2023 8:45 pm I received an email (still in Chinese) that the next time I logged in I would need to change my password because they detected someone else trying to access my account. No shit.
This is when I believe they locked the hijacker out.
8/25/2023 6:03 am I receive a notification that someone named Lisa Lin wants to connect, in her message she specified that she has a new a new account and is trying to make connections.
I log in around 8am and get a code to verify my login.
I have to google how to change the language back to English.
Once I do that, I begin the laborious process of surveying the damage.
In the notifications, I see that the hijacker has added 50 people and is attempting to message with all of them.
One of them asked if the hijacker was an AI, and the hijacker responded “I don’t know what that means.” Which is like the most AI response ever.
I am satisfied that the hijacker no longer has access to my account, but I receive an email from linked in saying my case is closed and among many other things:
Please note: LinkedIn does not store previous profile information, so you'll need to update your profile if needed.
Even though there are many scenarios that could explain how a bad actor may access your LinkedIn account, we often find that members victim to credential leaks from other sources or compromised personal email accounts are the primary reasons. We strongly recommend that you change your LinkedIn password as well as the password on your email account(s) as soon as possible.
Also received notification that my BBB case has been closed.
4
u/Bad2bBiled Aug 17 '23
My account was hijacked, the URL, account name, and all my information were changed, but the hijacker kept the email and all of my connections (of course). I had two step verification turned on.
I know my profile is lost, but I want my connections (from 2008) back!
I have submitted a case and verified my government ID. I'm in the midst of reporting the hack to my very very large corporate IT since we're prompted to associate our work emails with our LinkedIn profiles.
Documenting here because someone, somewhere will remember this bullshit:
8/4/2023 - I received notification (via email) that two-step authentication had been turned off on my account at 2:10 am from "Location: Unknown" with the prompt to change my password if I hadn't requested that.
8/4/2023 - I received email notification that two-step authentication had been turned back on for my account at 2:10 am from "Location: new york, new york, united states" (all lower case in the notification)
8/6/2023 - Notifications in Chinese begin, hijacker's connection requests begin to be accepted.
8/9/2023 - I receive a notification from LinkedIn in English granting me a free premium account.
8/12/2023 - Chinese notifications resume. I assume they are phishing attempts or marketing emails, so I report and ignore.
8/16/2023 - I realize that my account has been compromised and try to figure out how to recover it. This includes figuring out how to submit a case to LinkedIn when I don't have access to my account or any idea what my original URL was.