LinkedIn Scraping Court Order: What Outbound Must Change
Summarize with AI
A California federal court has ordered two data operators to stop mass-scraping LinkedIn, stop selling what they collected, stop using fake accounts, and delete the data. If your prospecting list came from a vendor whose access path you cannot describe, that is now the question to answer this week. Every tool touching LinkedIn should be able to show you a permitted way in, under a real account, with a stated purpose. Anything that cannot is a supply you are about to lose.
What the Order Actually Requires
The Record reported on 21 September 2026 that a California federal court finalized a consent judgment against ProAPIs and Netswift, along with their CEO. The judgment requires them to stop mass scraping of user data, cease selling and transferring scraped data, stop accessing LinkedIn through fake accounts, and delete all previously scraped data.
LinkedIn alleged the operators "created a massive network of bogus accounts, numbering in the millions, that scraped the data on a constant basis." The targeted information covered member profiles, company and school information, reactions, comments, and posts. According to the complaint, the defendants stood up "hundreds or even thousands of new accounts daily," which let them scrape "hundreds of profiles" within hours of account creation, faster than LinkedIn could block them.
Sarah Wight, LinkedIn's litigation and enforcement lead, framed the principle: "Your profile is yours. What you choose to share on LinkedIn is meant for the professional community you're building, not for an outside company to scrape and use in ways you never agreed to."
This Enforces Existing Terms, Not a New Rule
Nothing in the judgment invents an obligation. LinkedIn's User Agreement already prohibits all three behaviors named in the order.
Section 8.2.2 bans members from "develop, support or use software, devices, scripts, robots or any other means or processes (such as crawlers, browser plugins and add-ons or any other technology) to scrape or copy the Services, including profiles and other data from the Services."
Section 8.2.13 bans members from "use bots or other unauthorized automated methods to access the Services, add or download contacts, send or redirect messages, create, comment on, like, share, or re-share posts, or otherwise drive inauthentic engagement."
Section 8.2.1 bans members from "create a false identity on LinkedIn, misrepresent your identity, create a Member profile for anyone other than yourself (a real person), or use or attempt to use another's account (such as sharing log-in credentials or copying cookies)."
Our view: the meaningful change here is enforcement appetite, not policy. Teams that read the terms and assumed nobody would act on them have now watched a court order deletion and a halt on data sales. That moves scraped-data dependence from a background risk to a supply risk you can lose overnight.
Separate the Three Things People Call "LinkedIn Data"
Most outbound stacks blur categories that carry very different exposure. Pull them apart before you judge any single tool.
| Access pattern | What it looks like | Standing after the judgment |
|---|---|---|
| Person-to-person outreach | You, on your own account, viewing profiles and sending connection notes or messages by hand | Unaffected. This is ordinary use of the product. |
| Authorized integration | A vendor using an official LinkedIn API or a licensed data agreement, or a member exporting their own data | Depends on the agreement. Ask for it in writing. |
| Unauthorized automated access | Headless browsers, cookie-sharing plugins, account farms, bulk profile extraction sold as an enrichment feed | Directly in scope. The judgment describes exactly this behavior. |
Automation by itself is not the issue. Sequencing, CRM sync, and enrichment against other sources never touch LinkedIn's systems, and none of them are affected by this judgment.
Run the Access Inventory
For every tool, extension, scraper, enrichment provider, and data vendor that touches LinkedIn, record six fields:
- The tool name and who inside your company owns the relationship.
- What LinkedIn data it reads or writes, stated specifically rather than as "profile data."
- Whose account it operates under, including any shared logins or cookies.
- The access path the vendor claims, in the vendor's own words, in writing.
- Whether that path is an official API, a licensed feed, a member's own export, or unauthorized collection.
- Your decision: keep, replace, or remove.
Browser extensions deserve extra attention because they run inside a logged-in session under a real employee's identity. A seller who installs a bulk extractor is doing the scraping personally, with their own account carrying the restriction risk.
Ask vendors a direct question rather than a legal one: "Which LinkedIn interface does this data come from, and under what agreement?" A vendor with an authorized path answers in a sentence. A vendor without one talks about encryption, compliance certifications, or how everyone in the industry does it.
What to Do With the Data You Already Bought
A list sourced from a scraping vendor does not become clean because you paid for it. Two decisions follow.
First, stop treating that vendor as a renewing supply. If the judgment's remedies become the pattern, a supplier can be ordered to delete its corpus and your pipeline of new records stops with it. Build the replacement now, while you have time to test alternatives, rather than after a notice arrives.
Second, keep the business facts you can verify independently and drop the rest. Company name, domain, and a contact you have confirmed through a source you control are things you can stand behind. Scraped reaction histories, comment archives, and inferred relationship graphs are not worth defending.
What Still Works
Outbound on LinkedIn does not require any of this. A seller researching named accounts on their own account, sending a relevant connection request, and following up in the seller's own words is ordinary use of the platform, and it was ordinary use before this judgment.
The teams caught out are the ones that replaced judgment with volume and bought reach from someone who was manufacturing millions of accounts to supply it. The judgment removes that supplier and sets the pattern for the next one.
Start the inventory with the tool your team installed most recently and work backwards. Newer extensions are the least documented and the most likely to be running under an individual seller's login without anyone else knowing.
If you want a second pair of eyes on your ICP, your data sources, and whether your current campaign is built on infrastructure you own, book a free ICP and campaign-fit discovery call →.
Frequently Asked Questions
Hiring an in-house SDR costs $5,500+/month in salary alone, before tools ($3K–5K/month), training, and management. Agencies typically charge $3,000–8,000/month. A managed outbound system like LeadHaste starts at $2,500/month, with infrastructure the client owns and month-to-month engagement after the first three months.
With a properly built system, most clients see their first qualified replies within 2–3 days of campaign launch (after the 2–3 week warm-up period). The real power shows in month 2–3 as domain reputation strengthens, sequences optimize from real data, and targeting sharpens.
In-house works if you have a dedicated ops person, 6+ months of runway for ramping, and budget for 20+ tool subscriptions. Outsourcing makes sense when you want speed-to-pipeline, can't justify a full-time hire, or need multi-channel orchestration (email + LinkedIn + intent data) that requires specialized tooling.
Inbound attracts leads through content, SEO, and ads. Prospects come to you. Outbound proactively reaches prospects through targeted email, LinkedIn, and calls. Inbound scales slowly but compounds over time. Outbound delivers faster results but requires ongoing execution. The best B2B companies run both.
A compound outbound system is an orchestrated set of 20–30 tools (enrichment, sending, warm-up, analytics) that improves automatically over time. Month 2 outperforms month 1 because domain reputation strengthens, AI sequences learn from engagement data, and targeting tightens from real conversion patterns. It's the opposite of starting fresh every month.

Dimitar Petkov
Co-Founder of LeadHaste. Builds outbound systems that compound. 4x founder, Smartlead Certified Partner, Clay Solutions Partner.

