On September 21, 2026, the federal court for the Northern District of California approved a settlement in the case LinkedIn Corporation v. ProAPIs Inc. (No. 5:25-cv-08393). ProAPIs, which sold LinkedIn data through an API, along with its partner Netswift and co-founder Rehmat Alam, are permanently barred from accessing the platform and are required to delete the collected archive. Two weeks earlier, on September 8, the same court dismissed two class action lawsuits against LinkedIn regarding a script that scans visitors' browsers for over 6000 extensions. Together, these rulings illustrate how LinkedIn will continue to combat scraping and who should reconsider their data collection practices.
What Exactly Did the Court Decide Regarding ProAPIs
LinkedIn filed the lawsuit in October 2025. According to the plaintiff, ProAPIs operated like a factory: creating hundreds, if not thousands, of fake accounts per day, totaling over a million. Each account managed to extract hundreds of profiles before being caught by security measures. To access premium features, the complaint alleges that invalid credit cards were used.
They collected everything indiscriminately: participant profiles, company and educational institution pages, posts, comments, and reactions. The data was sold via subscription. The top tier cost up to $15,000 per month and allowed for 150 requests per second. This amounts to about 13 million profile requests per day.
The decision was a settlement, meaning the defendants did not contest it until the end. Under its terms, they:
- are prohibited from accessing LinkedIn through fake accounts, bots, or any automation;
- cannot sell or transfer previously collected data;
- are required to delete the entire accumulated archive.
LinkedIn's litigation lead, Sarah White, articulated the company's position as follows: the profile belongs to the participant, not to a third-party firm that collects their data without consent.
This is Already a Series, Not an Isolated Case
ProAPIs is not the first such defendant. In January 2025, LinkedIn filed a lawsuit against Nubela (the Proxycurl service, case No. 3:25-cv-00828). The case ended in a settlement, and Proxycurl, one of the most well-known API wrappers over LinkedIn data, according to its creators, no longer works with LinkedIn. According to The Record, about five months before the ruling on ProAPIs, LinkedIn achieved a similar result against a company distributing unauthorized browser extensions.
The scheme is the same everywhere. LinkedIn does not attempt to prove that collecting public pages constitutes hacking. Instead, the company targets what is easier to prove:
- violation of the user agreement, which everyone accepts when creating an account;
- fake accounts and bypassing paid access;
- commercial resale of participant data.
What About hiQ?
Many still refer to the case hiQ Labs v. LinkedIn as evidence that scraping LinkedIn is legal. This is only partially true. In 2022, the Ninth Circuit Court of Appeals ruled that collecting public pages likely does not violate the U.S. Computer Fraud and Abuse Act (CFAA). However, the dispute did not end there. Ultimately, hiQ paid LinkedIn $500,000 and agreed to a court injunction, including the destruction of algorithms built on the collected data.
The founder of Proxycurl, who was also sued by LinkedIn, stated after his case: public scraping may not fall under one specific article of the law, but that does not mean the company is protected from LinkedIn. The main risk for businesses is a civil lawsuit for breach of contract, not a criminal case.
The Second Ruling: The Extension Scanner Stood Firm
In April 2026, the German organization Fairlinked e.V. published a report titled BrowserGate. It was revealed that when loading any LinkedIn page in Chrome or another Chromium-based browser, such as Edge, the site runs a script that checks which extensions are installed on the visitor's browser. The check is done using known extension IDs: the script attempts to load their static files, and if the file responds, the extension is found.
The scale grew rapidly:
- in 2025, researchers on GitHub counted about 2000 extensions on the list;
- by early 2026, around 3000;
- by April 2026, 6236.
The list included competing sales tools (Apollo, Lusha, ZoomInfo), as well as grammar assistants and tax consultant utilities. Along with the list of extensions, the script, according to BleepingComputer, collects device data: number of CPU cores, memory size, screen resolution, time zone, language, battery status, audio settings, and storage parameters. All this combines into a fingerprint that can identify the session.
LinkedIn explained that it is looking for extensions that collect data without participants' consent or violate service terms. On April 7-8, California residents Jeff Ganan and Nicholas Farrell filed two class action lawsuits. On September 8, Judge Vince Chhabria dismissed both: the plaintiffs failed to demonstrate specific harm, without which the federal court does not consider the case on its merits. The court did not rule on the legality of the scanning itself. However, in practice, the script continues to operate, and there are currently no grounds for LinkedIn to remove it.
Timeline: How LinkedIn Tightened the Screws
- 2022 — Ninth Circuit Court of Appeals in the hiQ case: collecting public pages likely does not violate the CFAA. Later, hiQ pays $500,000 and agrees to an injunction.
- 2025 — researchers find a list of about 2000 tracked extensions in LinkedIn's code.
- January 2025 — lawsuit against Nubela (Proxycurl), later a settlement.
- October 2025 — lawsuit against ProAPIs and Netswift.
- April 2026 — BrowserGate report: the list now has 6236 extensions. A few days later, two class action lawsuits are filed.
- September 8, 2026 — Judge Chhabria dismisses both lawsuits.
- September 21, 2026 — settlement ruling on ProAPIs: access ban and archive deletion.
What This Means in Practice
The two rulings combine to form a clear picture. LinkedIn sees how you access (extensions and device fingerprint) and can sue those who access under someone else's name (fake accounts) for resale. Below are conclusions for different tasks.
If You Sell LinkedIn Data or Build a Product Based on It
- The model "army of fake accounts → API for sale" has now lost in court twice: Proxycurl has backed away from LinkedIn, and ProAPIs is banned. The court's decision requires the deletion of the database, which nullifies the entire product.
- If the data is needed for a B2B product, seek licensed sources or work with data that users provide themselves (for example, through OAuth and the official API).
If You Work with Your Own Accounts: Recruiting, Sales, SMM
- Do not keep "spy" extensions in a profile where LinkedIn is open. Sales extensions that extract contacts are directly visible to the site, and this is grounds for account restrictions. It's better to keep a work profile for LinkedIn clean.
- The fingerprint must be plausible. The script collects cores, memory, screen, time zone, and language. If the browser's time zone does not match the IP, and the "laptop" shows 64 cores, that is noticeable. Check your profile before working with checkers that we compared in our analysis CreepJS, Pixelscan, Iphey, and BrowserScan.
- One account — one stable IP. A real account needs a constant address from the same country where the profile "lives." The best options are residential proxies with sticky sessions or mobile proxies: they have the reputation of home and cellular networks, not hosting.
- Maintain a human pace. According to the case materials, each new ProAPIs account opened hundreds of profiles within a few hours. Such behavior is abnormal in itself, and changing the IP does not mask it.
If You Collect Public Data
- The difference between logging in and not logging in is important. Collecting public pages without logging into an account is exactly the case discussed in hiQ. Once you log into an account, you operate under the user agreement.
- Collect only what is necessary for the task, and do not store personal data longer than necessary. Reselling profiles is the riskiest scenario.
- For more on setting up collection and limits, see our guide on proxies for LinkedIn.
What Proxies Do Not Solve
Honestly about the limits. Proxies change the network address and help avoid looking like a thousand requests from one server. But they do not create a real person behind the account, do not hide installed extensions, and do not negate the user agreement. The ProAPIs case shows that at the scale of a million fake accounts, the solution lies with a lawyer, not an IP address.
Conclusion
September 2026 solidified LinkedIn's strategy: technically monitoring what is installed on visitors' devices while legally targeting factories of fake accounts and data resellers. Courts are currently siding with the platform in both directions. For those working with their own accounts, the takeaway is simple: a clean browser profile, a plausible fingerprint, a stable IP from the required country, and a human pace. For those who built a business on reselling profiles, the window seems to have closed.
