Dev News Daily ENDE

A court order ends a scraping ring built on fake LinkedIn accounts

A California federal judge has finalised an agreement between LinkedIn and the software companies ProAPIs and Netswift, The Record reported on 21 September 2026. The firms must stop scraping user data at scale, stop selling or transferring it, stop reaching LinkedIn through fake accounts, and delete what was already taken.

The numbers in LinkedIn's complaint, filed last October, describe the shape of the operation rather than a handful of scripts: a network of bogus accounts numbering in the millions, scraping continuously, with hundreds or thousands of new accounts created daily. LinkedIn says it found and blocked the accounts within hours, and that the window was still enough to pull hundreds of profiles each time. The targeted data covered members, companies and schools, plus reactions, comments and posts. ProAPIs, which describes itself as a data pipeline platform, posted that it "does not offer tools to scrape LinkedIn" and has agreed never to do so in future.

A court order ends a scraping ring built on fake LinkedIn accounts
A court order ends a scraping ring built on fake LinkedIn accounts — Dev News Daily

What it means

The interesting detail is the arithmetic of the defence. LinkedIn was winning every individual round - accounts detected and killed within hours - and losing the campaign, because the attacker's cost of creating an account was lower than the platform's cost of finding it. Detection speed measured in hours is a good number that turns out not to be the number that matters.

That is why this ended in a courtroom rather than in an anti-abuse team. When per-unit defence is cheaper for the attacker than for the defender, the only lever that changes the slope is one that raises the cost of the operation itself, and a consent judgment with a deletion obligation does that in a way no rate limit can.

Written by Victoria Shinder.