Fake CISO Profiles on LinkedIn Target Fortune 500s
2022-09-29 • Krebsonsecurity •
https://krebsonsecurity.com/2022/09/fake-ciso-profiles-on-linkedin-target-fortune-500s/
A network of fake LinkedIn profiles impersonated CISO roles at major companies including Chevron, ExxonMobil and Biogen, causing search engines and downstream data brokers to surface fabricated security-leadership identities as if they were real. The report does not identify who created the fake CISO profiles, but it highlights the security risk of professional-network data being copied into external sources without verification. It separately notes Mandiant's report that North Korean government hackers had copied resumes and profiles from LinkedIn and Indeed as part of attempts to obtain jobs at cryptocurrency firms. The case matters for CTI because profile fraud and scraped identity data can support social engineering, trust abuse and targeting of security or cryptocurrency-sector organizations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | apollo.io | 2022-09-29 | 2022-09-29 |