Corporate honeypot: the fake woman on LinkedIn
How fake LinkedIn profiles get close to executives to extract strategic information.
Audience: Companies and Operations · Risk level: ATTENTION
Blindfy Intelligence Unit · Technical review by Blindfy
Scenario
A director gets a message from an "international headhunter" on LinkedIn who, after weeks of conversation, starts asking precise questions about roadmap, M&A and partners.
How the scam works
Attackers build polished profiles with AI-generated photos and fabricated histories, pick targets with strategic access and cultivate the relationship for weeks before asking for "an opinion" on something confidential.
Common mistake
Trusting LinkedIn as a filtered environment without applying basic OSINT to relevant new connections.
Impact
Competitive intelligence leaks, compromise of ongoing M&A and reputational exposure for the executive.
What works
OSINT on new strategic connections, executive training and a clear protocol on what never to discuss outside official channels.
Protection checklist
- Validate new connections' history with OSINT
- Run reverse image searches on profile photos
- Train executives on long-game social engineering
- Define topics forbidden outside the office
- Monitor the C-level's strategic exposure
- Report suspicious profiles to LinkedIn
- Audit exchanged messages during incidents
Editorial sources
- CERT.br / NIC.br — Cartilha de Segurança para Internet
- ENCCLA / Ministério da Justiça — Enfrentamento a golpes digitais
LinkedIn is the spy's new front door. Treat every connection as a risk asset.