Tech

Criminal probe launched into LinkedIn over secret browser extension scanning

Since 2017, the social network has encrypted and injected data on thousands of installed extensions into user requests without consent, prompting a formal criminal investigation

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Hacker News · original
Tech
No image available
Bavarian authorities investigate platform for alleged Digital Markets Act breaches following revelations of covert data collection practices

A criminal investigation has been opened by the Bavarian Central Cybercrime Prosecution Office in Bamberg into LinkedIn's data collection practices. The probe focuses on allegations that the platform failed to comply with the European Union's Digital Markets Act through covert tracking mechanisms.

Investigative findings reveal that LinkedIn has been scanning for browser extensions since at least 2017. As of April 2026, the system tracks 6,278 specific extensions, a significant increase from the 38 entries recorded at the start of the decade. This data is encrypted and injected into every API request made by a user during their session.

The practice is part of an internal system known as APFC, or Anti-fraud Platform Features Collection. This infrastructure links a user's software inventory directly to their verified professional identity, including their name, employer, and job title. The scanning occurs without explicit consent or mention in the platform's privacy policies.

According to records documented by browsergate.eu, the scanning mechanism uses automated tooling to crawl the Chrome Web Store. It fires requests to specific files within extensions; a successful response indicates the software is installed, while a blocked request logs a failure.

Detected extension IDs are encrypted with an RSA public key and transmitted to LinkedIn's tracking endpoint. A second detection system, dubbed Spectroscopy, independently walks the DOM tree to catch extensions interacting with the page even if they are not on the hardcoded list.

Milinda Lakkam confirmed under oath that LinkedIn has taken enforcement action against users who had specific extensions installed. The platform's ability to infer details about personal lives and employer environments from this data has raised significant privacy concerns.

The Bavarian authorities have confirmed that the investigation is underway, moving beyond a simple regulatory compliance dispute into the realm of criminal law. Legal outcomes remain uncertain as the case proceeds through the judicial system.

Continue reading

More from Tech

Read next: The Walrus warns of collapsing digital memory as AI erodes search reliability
Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers