LinkedIn has initiated legal action against ProAPIs Inc., a Delaware-based company, and its founder and CEO, Rahmat Alam, for orchestrating a massive data scraping operation using millions of fake accounts. The lawsuit alleges that ProAPIs created and maintained a vast network of fraudulent LinkedIn profiles to automate the extraction of member, company, and school data, as well as posts, reactions, and comments. LinkedIn claims that ProAPIs offered real-time access to this scraped data through a tool called iScrap, charging clients up to $15,000 per month for the service. The operation involved the continuous creation of hundreds or thousands of new fake accounts daily, which were used to bypass LinkedIn’s technical defenses and harvest data before being detected and restricted, often within hours. Despite LinkedIn’s efforts to block these accounts, the persistent activity allowed each fake account to scrape hundreds of profiles, contributing to a significant volume of unauthorized data collection. The lawsuit also names a Pakistan-based technical enabler, Netswift, as a party responsible for supporting the scraping activities. LinkedIn asserts that ProAPIs’ actions constitute a clear violation of its terms of service and misuse of its trademarks, as the defendants allegedly implied endorsement by LinkedIn. The company is seeking a permanent injunction to halt the scraping, deletion of all unlawfully obtained data, and monetary damages. LinkedIn emphasizes its ongoing investment in advanced technology and dedicated teams to combat unauthorized scraping and protect the integrity of its platform. The company has a history of taking aggressive legal action against scrapers, with previous lawsuits resulting in judgments prohibiting such activities. LinkedIn’s technical and human resources are regularly deployed to detect and block fake accounts, aiming to ensure that the platform remains a trusted space for professional networking. The scraping operation not only compromised user privacy but also placed additional load on LinkedIn’s servers, potentially impacting service performance. Official investigations clarified that the data involved in recent leaks originated from scraping rather than a direct security breach. LinkedIn’s legal action underscores the broader challenge faced by social networks in protecting user data from automated harvesting and the lengths to which some actors will go to circumvent platform defenses. The outcome of this lawsuit may set further precedent for how professional networks address large-scale scraping and the misuse of their services.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
LinkedIn sued ProAPIs, alleging the company used roughly 1 million fake accounts to scrape LinkedIn user data at scale as part of a paid scraping scheme reportedly worth about $15,000 per month. Multiple reports on October 6, 2025 describe the same legal action and allegations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.