Not surprising really. A few years back Hotmail/Outlook were returning people's Twitter/LinkedIn handles for emails sent/received. It had been noticed you could scrape that fairly easily at scale. With one email account you could check up to 30000 email addresses before being flagged by Outlook. Slightly longer ago you could simply iterate 1...n on LinkedIn URLs to find someone's profile, by converting the number to…
> He claims the data was obtained by exploiting the LinkedIn API to harvest information that people upload to the site.
> our initial analysis indicates that the dataset includes information scraped from LinkedIn as well as information obtained from other sources. This was not a LinkedIn data breach and our investigation has determined that no private LinkedIn member data was exposed.
If the attacker is telling the truth, Then somehow the attacker has gained access to privileged API of LinkedIn which gives out more fields than those listed in the official LinkedIn API doc[1].
If LinkedIn is telling the truth, Then the source of breach is most likely one of the many data brokers who have been breached several times in the past[2].
[1] https://docs.microsoft.com/en-us/linkedin/shared/references/...