LinkedIn optimization · 7 min read

LinkedIn Account Restricted or Hacked: How to Get Back In

You open LinkedIn and instead of the feed there is a grey box telling you your account has been restricted. Or your login stops working and the recovery email goes to an address you no longer control. Either way, if you are in the middle of a job search, the profile that half your applications point back to has just gone dark.

The first thing to get right is which problem you actually have. Three very different situations produce the same symptom, and the fix for one of them will waste a week on the other two.

Work out which of the three you are in

A restriction comes from LinkedIn itself. Something tripped an automated rule and the platform has put your account on hold pending review. The tell is the wording on screen: it will reference the user agreement or the community policies and point you toward a route to appeal.

An account takeover is someone else. The tells are different. Your login no longer works although you never changed it, or it still works but there are messages in your sent folder you never wrote, invitations you never sent, a headline that is not yours.

A lockout is neither of those. The account is fine. You just cannot prove you are you, usually because the email on the account belongs to an employer you left, or because your authenticator app lived on a phone that is now at the bottom of a lake.

Read the actual message on the screen before you fill in anything. Almost every wasted week in this process comes from somebody appealing a restriction when they were hacked, or resetting a password when the account was restricted.

If LinkedIn restricted your account

What usually triggers it

Automated enforcement is blunt on purpose. The patterns that get caught most often involve volume and automation: sending connection requests faster than a human plausibly could, running a browser extension that visits hundreds of profiles or fires messages on a schedule, scraping profile data with a tool, or signing in from a cloud server address because the automation runs somewhere other than your laptop.

Then there is the real-name rule. LinkedIn expects the name field to hold the name you go by in professional life, and nothing else. Accounts get flagged for job titles stuffed into the surname field, for emoji, for "open to work" typed into the name, for strings of credentials. Plenty of people did that for a decade and got away with it, then hit one review and lost the account overnight.

What an appeal actually needs

The appeal route is normally linked from the restriction message itself, or reachable through the help section. Expect a short form rather than a conversation. A few things make a real difference:

  • Write it yourself, in plain language, and keep it short. Say what you think triggered the flag and what you have changed.
  • If automation was involved, say so and confirm you have uninstalled it. Denying something their logs already show is not a strong opening move.
  • Do not send five appeals. Duplicate submissions tend to push you back in the queue rather than forward.
  • Fix the underlying problem before you appeal, not after. An appeal that arrives while the name field still reads "Sarah Chen, Data Scientist, Hiring" argues against itself.

How identity verification works

For a large share of restrictions, the resolution path is proving that a real person sits behind the account. In broad terms you upload an image of a government identity document, and in many cases you also record a live selfie through the camera so it can be matched against the document.

Two practical notes. The name on the document needs to match the name on the profile: if you go by a shortened first name or a maiden name professionally, that mismatch is itself a source of delay. And image quality matters more than people expect. Whole document in frame, no glare, no photograph of a photocopy.

If someone else is in your account

Order matters here, because doing step three before step one hands the intruder your new credentials.

  1. Secure your email account first. If the attacker controls your inbox, every LinkedIn reset you trigger lands in their hands. Email is the root of the tree. Change that password, then check its forwarding rules, because a quiet forward to an unknown address is the classic way access gets kept.
  2. Reset your LinkedIn password. If you can still sign in, do it from account settings. If you cannot, use the standard forgotten-password flow against the email address you still control.
  3. Sign out of every other session. LinkedIn keeps a list of devices and browsers currently signed in, with approximate locations, in the sign-in and security part of settings. Review it and end everything that is not the device in your hand. A password change on its own does not always kill a live session.
  4. Turn on two-step verification. An authenticator app beats SMS here, since a phone number can be moved by anyone who talks a mobile carrier into it.
  5. Audit what changed. Look at the email addresses and phone numbers attached to the account. Attackers routinely add one of their own so they can walk back in later. Then read your sent messages and anything posted while you were away.

If messages went out to your network, tell people. A short note saying the account was compromised on a given day costs you nothing and protects contacts who would otherwise click.

If you are simply locked out

This is the least alarming case and often the slowest. The common version: the account is tied to a work address at a company you left eighteen months ago, and you never added a personal one.

If you still have the password and a recognised device, add a second email address right now, before you do anything else. If you do not have either, you are back to identity verification, which is the same document-and-selfie process described above. It works. Treat it as days rather than minutes.

Lost the authenticator? Recovery codes solve this instantly, assuming you saved them. Nobody saves them. Which is why five minutes spent storing them somewhere durable is worth more than most of the productivity advice you will read this year.

Be honest about the damage and then be pragmatic. Applications you already sent elsewhere are unaffected. What breaks is the discovery layer. Recruiters running searches cannot find you, anyone clicking the profile link on your CV hits an error page, and live conversations go silent from the other side's point of view.

Recovery timelines vary enormously and anyone quoting you a fixed number is guessing. A straightforward password reset can be same-day. Identity verification usually takes longer. Contested restrictions involving automation can drag, and a minority of them do not end the way the account holder wanted.

So run the parallel track from hour one. If a recruiter is mid-conversation and you have an email or a number from an earlier exchange, contact them directly. One line saying your LinkedIn access is temporarily disrupted, here is your email, here is your phone. Almost nobody will care. Silence is what kills those conversations, not the outage.

This is also the argument for refusing to let LinkedIn hold the only copy of your professional history. A current CV file on your own drive, plus a saved list of the recruiters you are talking to and their contact details off-platform, turns a lockout from a crisis into an inconvenience. Tools like Postulit exist partly because a career history that lives only on somebody else's server is a single point of failure.

The tools that cause this in the first place

Most restrictions I have seen among job seekers trace back to something the person installed on purpose. Connection automators promising five hundred invitations a week. Messaging sequencers that run drip campaigns from your account while you sleep. Profile-view bots. Scrapers that pull contact data out of member pages into a spreadsheet. Auto-endorsers.

The pitch never changes: the job search is a numbers game, so automate the numbers. It works right up until the account disappears.

If you want volume without the risk, the boring methods still function. Saved searches with alerts. Invitations sent by hand with a line of context, which convert better anyway. Two-step verification on permanently.

Do this before anything goes wrong, because it takes about fifteen minutes. Open settings, switch on two-step verification, read the list of signed-in devices and end the ones you do not recognise, make sure there is a personal email on the account that you will still control in ten years, and download your data archive. That is the only part of this you can act on while you still have access.

Try Postulit

Now tailor your résumé in 30 seconds.

Build my resume — free
◆ The Postulit Brief

Stay connected!

Receive the latest articles directly in your inbox

No spam · Unsubscribe anytime