LinkedIn Wins Permanent Injunction in Fake-Account Scraping Suit
Independently fact-checked against primary sources (last audited October 6, 2026). · 4 primary sources cited on this page. How we verify our legal content

A federal judge in San Jose entered a permanent injunction against a Pakistan-based scraping operation that LinkedIn says ran millions of fake accounts to harvest member profile data and resell access to it for up to $15,000 a month.
Information last verified on September 19, 2026.
Status: Final Judgment on Consent entered September 16, 2026. The judgment resolves the case by the parties' stipulation; it contains no merits ruling on whether the conduct violated any statute.
Jurisdiction scope: This is a federal civil judgment from the U.S. District Court for the Northern District of California. It has no direct effect outside that case and does not change any state's or country's criminal or civil scraping laws. General discussion of the Computer Fraud and Abuse Act below describes federal law, which applies nationwide, but the judgment itself was entered against three named defendants only.
What Happened
On October 2, 2025, LinkedIn Corporation filed a complaint against ProAPIs Inc., a Delaware corporation based in Middletown, Delaware; Netswift (SMC-Private) Limited, a company incorporated in Pakistan in 2022; and Rehmat Alam, identified in the complaint as cofounder and Chief Technology Officer of both companies and a Pakistan resident. The case was docketed as LinkedIn Corp. v. ProAPIs Inc., Case No. 5:25-cv-08393, in the U.S. District Court for the Northern District of California.
LinkedIn's complaint alleged that the defendants "operate a vast network of continuously-created fake accounts, numbering in the millions, that they use to log into LinkedIn and scrape LinkedIn member, company, and school data, as well as member posts, reactions, and comments." The complaint alleged that LinkedIn's technical defenses "regularly detect and restrict Defendants' fake accounts within hours of their creation," but that each fake account "can sometimes scrape hundreds of profiles, if not more" before it is caught, and that the defendants "persist in registering hundreds if not thousands of new accounts per day."
The complaint further alleged that the defendants marketed the product built from this scraping, describing it in their own materials as offering "real-time, detailed data for individual and company LinkedIn profiles" that is "comprehensive" and "up-to-the-second," and that they rented access to customers for "up to $15,000 per month."
The defendants returned an executed waiver of service on October 15, 2025, and did not file an answer contesting the specific factual allegations. The parties instead negotiated a resolution, and on September 15, 2026, both sides' counsel, Munger, Tolles & Olson LLP for LinkedIn and Quinn Emanuel Urquhart & Sullivan LLP for the defendants, signed a stipulated Final Judgment on Consent asking the court to enter it. Judge Pitts signed the judgment on September 16, 2026. The court's docket lists the case as terminated that same date.
What the Judgment Requires
The judgment's operative language, drawn from the document as entered, permanently restrains and bars the defendants, along with their officers, directors, agents, servants, employees, and anyone acting in concert with them, from:
- Accessing or attempting to access LinkedIn's website, computers, computer systems, computer networks, or computer programs, or data stored in them, "through impersonation, fake accounts, scraping, crawling, and/or the use of bots or other automated technologies, or otherwise in violation of LinkedIn's User Agreement";
- Marketing, advertising, or making any statement to anyone about the scraping, inclusion, or availability of LinkedIn data on any website or service the defendants offer;
- Circumventing any technological measure that controls access to LinkedIn's servers;
- Offering, selling, or using any third-party product or service, including software, that provides LinkedIn data, creates or operates LinkedIn accounts for others, accesses LinkedIn's servers in an automated manner, or circumvents LinkedIn's access controls;
- Encouraging or assisting any third party in doing the same;
- Offering, selling, or transferring, including for free, LinkedIn data or information derived from it to any third party, or developing any product that third parties could use to access LinkedIn's servers in an automated manner; and
- Displaying LinkedIn's trademarks or otherwise suggesting an association with LinkedIn that does not exist.
Beyond the injunction, the defendants represented and certified in writing, under penalty of perjury, that they had provided LinkedIn with all documents and information required under the settlement agreement; permanently deleted all LinkedIn data they had obtained by any means; destroyed any reports or analyses built from that data; destroyed all software code used to scrape LinkedIn's platform; destroyed all software code, "including, without limitation, SDKs and APIs," used to deliver LinkedIn data to anyone; and removed any materials referring to their scraping of LinkedIn data or using LinkedIn's marks.
The judgment states that a violation of any of its provisions exposes the defendants "and all other persons bound by this Final Judgment on Consent to all applicable penalties, including contempt of Court." It resolves all claims and defenses in the case, is final, and by its own terms "may not be appealed by any party." The court retained continuing jurisdiction to enforce the judgment, including the underlying settlement agreement and the document-production obligations it describes.
A whereas clause in the judgment also records that the defendants "have not filed an answer in this matter, but deny liability for the actions alleged in the Complaint." The judgment resolves the case on stipulation; it does not include any factual finding or legal conclusion that the defendants' alleged conduct actually violated the statutes LinkedIn pleaded.
What the Law Actually Says
LinkedIn's complaint pleaded eight causes of action: breach of contract; fraud and deceit under California Civil Code sections 1572 and 1710; breach of the Computer Fraud and Abuse Act, 18 U.S.C. § 1030; breach of the California Comprehensive Computer Data Access and Fraud Act, California Penal Code § 502; unlawful, unfair or fraudulent business practices under California's Unfair Competition Law, Business and Professions Code § 17200 et seq.; trademark dilution under the Lanham Act, 15 U.S.C. § 1125(c); misappropriation; and trespass to chattels. None of those claims was adjudicated. The consent judgment resolves the case without a ruling on which, if any, of the eight theories the defendants' conduct actually satisfied.
That distinction matters because the underlying legal question, whether scraping data from a website violates the CFAA, is unsettled in a way this case does not touch. In a separate, long-running dispute, hiQ Labs, Inc. v. LinkedIn Corp., LinkedIn sought to block a data-analytics company, hiQ, from scraping LinkedIn member profiles that were visible to the public without logging in. The Ninth Circuit, ruling on an appeal of a preliminary injunction and applying the "serious questions on the merits" standard that governs preliminary relief rather than a final judgment on the merits, held that hiQ had raised a serious question as to whether the CFAA's "without authorization" language applies at all "where access is open to the general public." The court reasoned that where "the default is free access without authorization, in ordinary parlance one would characterize selective denial of access as a ban, not as a lack of 'authorization.'" That 2022 decision, 31 F.4th 1180, came on remand after the U.S. Supreme Court vacated the Ninth Circuit's earlier ruling in the same case and directed it to reconsider in light of Van Buren v. United States. It affirmed a preliminary injunction requiring LinkedIn to continue allowing hiQ's access while the underlying suit proceeded; it did not decide the case on the merits.
The ProAPIs judgment does not turn on that question, and its terms should not be read as extending or narrowing hiQ's reasoning. The distinction the defendants agreed to here, using fake, unauthorized accounts and automated tools to reach data that is not generally open to the public, including information "only available behind LinkedIn's password wall," as the complaint put it, is a different fact pattern from scraping data a site makes visible to any visitor. Readers researching where their own state's privacy protections sit relative to scraping, biometric data collection, or profile information generally can find background in the site's coverage of state-by-state data privacy laws, biometric privacy statutes, and California's data privacy framework.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
A consent judgment is not a court ruling on the law, and it is worth being precise about why that limits its value as precedent. No judge weighed evidence, no jury returned a verdict, and no opinion explains which of LinkedIn's eight theories, if any, a court found the facts actually supported. The defendants expressly preserved their denial of liability even as they agreed to be bound. Other companies scraping LinkedIn, or scraping other platforms under different facts, cannot point to this judgment as authority that a court found their own conduct illegal, because no court made that finding here.
What the judgment does supply is a detailed, court-enforceable template of what LinkedIn considers unacceptable conduct, and a real operational cost for defendants who cross that line: destruction of the scraping software itself, destruction of the delivery infrastructure including SDKs and APIs, and a standing contempt exposure if they resume. For a company whose product was the scraped data, an order to delete it and to destroy the tools that produced it is close to an operational shutdown, backed by a federal court's continuing jurisdiction rather than by a one-time settlement payment.
The scale alleged in the complaint, millions of fake accounts, hundreds of profiles scraped per account before detection, and paying customers charged up to $15,000 a month, illustrates a broader dynamic in how personal information that people post voluntarily on a professional network can end up resold into other databases they never see and cannot correct. A LinkedIn profile is not a static document; people update job history, delete old roles, and change how much is visible to the public. Once that data is copied into a third party's database, the platform's own privacy controls, including a member's ability to delete information and have it actually removed, no longer reach the copies.
How This Affects You
This judgment does not give an individual LinkedIn member any new personal right of action, and readers should not treat it as a template for their own disputes. It is worth separating what a member can and cannot control about scraping in general terms.
A member can control what appears on their public profile, including limiting visibility to logged-in users only or removing a profile from public search engine results, and can delete their account. What a member generally cannot control is data that has already been copied off the platform by a third party before deletion, or data that a scraper obtained through a fake account logged in to view content available to any LinkedIn user, not only the public internet. Neither of those situations is something an individual member can undo unilaterally; enforcement against the scraper, as happened here, depends on the platform pursuing legal action.
Readers concerned generally about how their information circulates once it leaves a platform's direct control, including through background-check services that aggregate public and semi-public profile data, may find the site's overview of background check laws and its explanation of data access request rights useful starting points, though neither addresses this case specifically.
What Happens Next
The judgment is final and, by its own terms, is not subject to appeal by either party. The court retains continuing jurisdiction to enforce it, meaning LinkedIn can return to Judge Pitts to seek contempt sanctions if it believes the defendants have resumed the conduct described above or failed to complete the document-production and settlement obligations the judgment references. The order binds ProAPIs Inc., Netswift (SMC-Private) Limited, and Rehmat Alam individually, along with anyone acting in active concert with them; it does not bind other scraping operations, and LinkedIn would need to bring a separate action against any other party engaged in similar conduct. Nothing in the public record reviewed for this article indicates further proceedings are scheduled.
This article is for general informational purposes only and does not constitute legal advice. It summarizes a specific federal court judgment entered on the parties' consent; it does not evaluate the legality of any reader's own data collection or use of a website, and readers with specific questions about scraping, data privacy, or platform terms of service should consult a licensed attorney.
Related articles
- Data access requests: what they cover and how to file one
- Biometric privacy laws by state
- US state privacy laws comparison
- California data privacy laws
- Background check laws
Last updated: 2026-09-19. This is a developing story; details verified as of 2026-09-19.
Frequently Asked Questions
Did a court rule that scraping LinkedIn violates the law?
No. This is a Final Judgment on Consent, meaning the defendants agreed to the terms and the court entered them without a trial or a ruling on the merits of LinkedIn's claims. The defendants expressly denied liability even while agreeing to be bound by the injunction.
What case is this and who decided it?
LinkedIn Corporation v. ProAPIs Inc., Netswift (SMC-Private) Limited, and Rehmat Alam, Case No. 5:25-cv-08393-PCP, in the U.S. District Court for the Northern District of California, San Jose division. U.S. District Judge P. Casey Pitts signed the Final Judgment on Consent on September 16, 2026.
What are the defendants now barred from doing?
The judgment permanently bars them from accessing LinkedIn's systems through fake accounts, scraping, or automated tools; from selling or offering any product that scrapes or delivers LinkedIn data; from helping others do so; and from using LinkedIn's trademarks to suggest an association that does not exist.
Did the defendants have to delete the data they collected?
Yes. The defendants certified in writing, under penalty of perjury, that they permanently deleted all LinkedIn data they had obtained, destroyed any reports built from it, and destroyed the software, including SDKs and APIs, used to scrape and deliver it.
What did LinkedIn originally allege in its complaint?
LinkedIn's October 2, 2025 complaint alleged the defendants ran a network of fake accounts, described as numbering in the millions, to log into LinkedIn and scrape member, company, and school profile data, then rented access to that data to paying customers for up to $15,000 per month. These were allegations; the consent judgment does not adjudicate whether they were true.
Does this judgment mean all web scraping is illegal?
No. It resolves a dispute between LinkedIn and three specific defendants over fake-account access and data resale. Separate litigation, including hiQ Labs, Inc. v. LinkedIn Corp., has addressed whether scraping data that is visible to the public without logging in raises different issues under the Computer Fraud and Abuse Act; that question was not part of this case.
Can the defendants appeal this judgment?
No. The judgment states it is final and may not be appealed by any party, consistent with its entry on the parties' own stipulation.
What happens if the defendants violate the judgment?
The judgment states that a violation exposes the defendants and anyone bound by the order to all applicable penalties, including contempt of court. The district court retained continuing jurisdiction specifically to enforce the judgment and the underlying settlement agreement.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- Final Judgment on Consent, LinkedIn Corp. v. ProAPIs Inc. et al., No. 5:25-cv-08393-PCP (N.D. Cal. entered Sept. 16, 2026), ECF No. 36(storage.courtlistener.com)
- Stipulated Final Judgment on Consent as filed by the parties, ECF No. 35 (Sept. 15, 2026)(storage.courtlistener.com)
- Complaint, LinkedIn Corp. v. ProAPIs Inc. et al., No. 3:25-cv-8393 (N.D. Cal. filed Oct. 2, 2025), ECF No. 1(storage.courtlistener.com)
- CourtListener docket, LinkedIn Corp. v. ProAPIs Inc., No. 5:25-cv-08393 (N.D. Cal.)(courtlistener.com)
- hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180 (9th Cir. 2022) (on remand from the Supreme Court)(courtlistener.com)
- 18 U.S.C. § 1030, Computer Fraud and Abuse Act(govinfo.gov).gov
- California Penal Code § 502, Comprehensive Computer Data Access and Fraud Act(leginfo.legislature.ca.gov).gov
- California Business and Professions Code § 17200, Unfair Competition Law(leginfo.legislature.ca.gov).gov
- 15 U.S.C. § 1125(c), Lanham Act trademark dilution provision(govinfo.gov).gov