Tuesday, August 11, 2026 Digital Forensics & Evidence Sign in
Lars Daniel

Digital forensics expert & expert witness · The Forbes digital forensics columnist

AI Evidence

4.3 Billion Work Profiles Exposed: Scammers Now Know Where You Work

A 16TB database with 4.3 billion LinkedIn‑style work profiles was left wide open online, handing scammers perfect fuel to target you, your boss and your company.

Linkedin
A 16TB database with 4.3 billion LinkedIn‑style work profiles was left wide open online, handing scammers perfect fuel to target you, your boss and your company. Gado via Getty Images

A 16‑terabyte marketing database left wide open on the internet has exposed nearly 4.3 billion professional records built largely from LinkedIn‑style data, giving criminals a ready‑made blueprint for large‑scale, AI‑driven social‑engineering attacks, according to Cybernews’ investigation.

The MongoDB instance, discovered on Nov. 23, 2025, by cybersecurity researcher Bob Diachenko in collaboration with nexos.ai, required no password and was secured only after researchers notified the apparent owner two days later, with no clear way to know who else accessed it first. Inside, investigators found nine structured collections with names like “profiles,” “unique_profiles,” “people,” “companies,” and “sitemap,” containing what they describe as professional and corporate‑intelligence data scraped and enriched at industrial scale.

At least three of those collections held personally identifiable information on nearly two billion records, including full names, email addresses, phone numbers, LinkedIn URLs and profile handles, job titles, employers, employment histories, education, locations, skills, languages, social media accounts, and, in some cases, profile photographs and email confidence scores

. A “unique_profiles” collection alone contained more than 732 million records with image URLs, while a separate “people” collection added enrichment scores and an “Apollo ID” field that appears to tie into the Apollo.io sales‑intelligence ecosystem, although there is no evidence Apollo itself was breached.Timestamps in the database suggest much of the information was collected or updated in 2025 and spans multiple regions worldwide, reinforcing the view that this is a fresh, global lead‑generation trove rather than a dusty archive.

Cybernews reports that some sitemap‑style records link “/people” and “/company” paths to the website of a lead‑generation provider that advertises access to more than 700 million professionals, a figure that closely tracks the size of the “unique_profiles” collection, and the exposed instance went offline shortly after that company was notified, though the researchers stop short of formally naming the owner.The real danger is how neatly this kind of dataset fits into modern criminal workflows. Because the data is structured like a marketer’s dream—clean fields for role, seniority, employer, contact methods, and social links—it can be dropped straight into AI models and automation tools to generate convincing phishing emails, business email compromise attempts, and CEO‑impersonation messages at enormous scale.

A trove like this acts as a backbone for “profile enrichment,” where attackers fuse it with other leaks such as password dumps like the RockYou2024 compilation and huge composites such as the “Mother of All Breaches” to build surveillance‑grade dossiers tying job histories and contact data to credentials, device identifiers, and broader online activity.The exposure also highlights LinkedIn’s ongoing, separate fight with companies that scrape its platform and automate fake accounts. In a recent lawsuit against software firm ProAPIs, LinkedIn alleged that the company ran more than a million fake profiles and sold an “iScraper API” that offered “industrial‑scale” access to member data for up to $15,000 a month, in violation of its user agreement and computer‑abuse laws.

LinkedIn argues in court filings that when third‑party scrapers siphon profiles into private databases and combine them with other sources, neither the company nor its members can control where that information goes or how it is weaponized, which is precisely the risk illustrated by the newly uncovered 4.3‑billion‑record trove.For individuals and companies, the practical takeaway is uncomfortable but straightforward: assume that professional details shared on major platforms are already circulating in commercial and criminal data warehouses.

On the personal side, widely recommended safeguards—multi‑factor authentication everywhere possible, unique passwords managed by a password manager, and treating any message that references a job role or colleague as suspicious until verified remain the best defense.

Organizations, meanwhile, should behave as though attackers can see their org charts and key decision‑makers, tightening payment‑change procedures, requiring secondary confirmation for sensitive requests, and running phishing drills that use realistic LinkedIn‑style lures, because adversaries armed with a polished lead‑gen dataset and cheap AI now need far less imagination to make a scam look real.

LinkedIn did not respond to a request for comment by publication time.


This column originally appeared in Forbes.

The newsletter

Digital forensics, explained before you need it

AI evidence, deepfakes and cell phone forensics from an expert witness who works these cases. No hype, no fear-mongering. Free.

Check your inbox to confirm your subscription.