29 Jul 2021

Cyber Security: The social network where everyone's been netted

By Stuart Slater

Social networks are one of the most common ways we communicate in the 21st century. We use them for entertainment, social interaction and even business. But with all the personal details we put on social media, how easy is it to use that information to manipulate somebody into doing something they shouldn’t? This is where phishing comes in…

Phishing

Well, it’s not to be confused with the activity of sitting in front of a lake for six hours in the pouring rain with nothing more than a rod and a net. Phishing is an attack performed by crafty criminals who attempt to trick a user into doing something they shouldn’t, such as visiting a dodgy website or downloading a malicious application.

There are many variations of types of phishing as well, which if referred to correctly will definitely impress your cyber security team:

  • Vishing
    An attack where an unsavoury character will call you up and ask for information about yourself, tricking you into providing personal confidential information. A common example of this is when you might get a call from somebody purporting to be from a certain large technology organisation’s support department, when in reality it’s a chap in a call centre with the aim of extorting money from you
  • Smishing
    Keeping on the same track as vishing, it involves your phone, however the method isn’t to call but to text message a user instead. A very common example that’s been in the news recently was the Royal Mail scam, where a group of individuals were sending messages to say a package was ready for delivery but required payment before collection

Why does all of this matter?

Well, we may be in for a tough ride over the next couple of months. As recently as March 2021, the National Cyber Security Centre reported that in the last 12 months 83% of businesses and 79% of charities have experienced a phishing attack.

Making matters worse, as of 27th June 2021, over 700 million LinkedIn records had been put on hacking forums and were being sold to anyone who wished to purchase them. What makes this different to other breaches is this is up-to-date and current data that was obtained as recently as this year. Often data breaches are a mixture of old records that aren’t relevant any more.

The one solace that we can take is that LinkedIn has said that no confidential information such as passwords has been stolen, however the following has:

  • Email addresses
  • Full names
  • Phone numbers
  • Physical addresses
  • Geolocation records
  • LinkedIn username and profile URL
  • Personal and professional experience/background
  • Genders
  • Other social media accounts and usernames

How was this data obtained?

It turns out the data was obtained using the publicly available LinkedIn API (a method where two different programs can talk to each other). This isn’t the first time this has happened either – a data leak using the same method occurred back in April 2021.

And for those wondering, I have confirmed that my own data has been leaked, and I am sure that given an estimated 92% of LinkedIn’s user base are affected, you may well be reading this and wondering whether you’re affected too.

So how do I find out if it’s been leaked?

The first thing to do is check the LinkedIn Data Breach Checker set up by CyberNews.

The second step is to check HaveIBeenPwned, a website that allows you to check your email address or mobile number across years’ worth of data breaches and see what information was leaked.

Once you’ve done both of those things, I would change your password on any affected accounts and the associated email addresses. If there is the ability to turn on multi-factor authentication (MFA/2FA) then do so.

What can I do to protect myself as an employee?

A common mantra used in cyber security is that humans are the first line of defence against attackers, but they’re also often the most vulnerable if not trained properly. Request from your employer any cyber awareness training that is available to you, and if not, check websites like the National Cyber Security Centre to find top tips on how to secure yourself from attackers.

Get in touch

Related insights

Three businesspeople in a meeting discussing reports

St Patrick's – Opportunity or false dawn for alternative education providers?

9 September 2026

Read
A casual business meeting between three people

Seven financial metrics that show the health of your business in 2026

7 September 2026

Read
Nick Harris in a suit and open necked shirt

Liquidators appointed to biomass boiler specialist BBSM Limited

7 September 2026

Read
Man and women looking at paperwork together in a kitchen

What is payable when surrendering an investment policy?

4 September 2026

Read
A person sitting at a desk, holding a coffee cup in one hand and typing on a laptop with the other. The desk has papers, glasses, and a small potted plant. There are large windows in the background letting in natural light.

Could your property make you UK tax resident?

1 September 2026

Read
People walking along bridge towards Big Ben in London.

What tax changes might John Healey introduce in his Budget on 28 October?

28 August 2026

Read
Two colleagues deep in thought discussing what they see on a laptop

Exceptional circumstances

25 August 2026

Read
A wooden house cut out lies on a desk, on top of a Post-it note inscribed in black marker with 'Stamp Duty Tax' .

SDLT issues for commercial development

21 August 2026

Read
Group of business people in discussions sitting down around a laptop

FRS 102 revenue recognition changes are coming: is your business ready?

20 August 2026

Read

Breaking UK tax residence: what does it mean and why does it matter?

19 August 2026

Read
Warehouse operative using a tablet to manage inventory in a logistics warehouse, surrounded by stocked pallets and shelving, representing supply chain and international trade operations.

Avoid these common pitfalls on the road to export success

18 August 2026

Read
business people sit around a table and one, a man stands talking, they are in a modern office and all wearing smart suits

Our response to the key elements of the latest SRA consultation

18 August 2026

Read