Pull to refresh
Logo
LinkedIn wins permanent court order blocking ProAPIs from scraping user data

LinkedIn wins permanent court order blocking ProAPIs from scraping user data

Rule Changes

Two data-broker firms must delete millions of scraped profiles and stop selling access to them.

7 days ago: Federal judge finalizes consent judgment

Overview

Updated 1 hour ago

If you have a LinkedIn profile, a data broker may hold a copy of it. Two California firms scraped millions of profiles with fake accounts, then sold access to that data for up to $15,000 a month — until a federal judge ordered them to stop and destroy what they took.

The Sept. 17 order settles LinkedIn's October 2025 lawsuit against ProAPIs, its partner Netswift, and co-founder Rehmat Alam. It's a negotiated consent judgment, not a merits ruling, so it binds only these defendants. LinkedIn has now removed two scrapers in five months, but the next data broker is already selling subscriptions.

Why it matters

This ruling limits which companies can profit from copying LinkedIn profiles without permission — your data included.

Questions about this story

Free account needed to ask — your question is kept and asked for you right after sign-up. Answers are public.

No questions yet — be the first to ask.

Key Indicators

$15,000
Monthly top-tier subscription for scraped data
ProAPIs sold access to LinkedIn data via an iScraper API, with premium tiers reaching $15,000 a month.
13 million
Daily profile requests at the premium tier
The top subscription allowed 150 requests per second, roughly 13 million profile pulls a day.
95 million
Automated scraping attempts LinkedIn blocks daily
LinkedIn reported blocking roughly 95 million automated scraping attempts every day.
2
Scraping operations removed in five months
LinkedIn removed ProAPIs and earlier persuaded data broker Proxycurl to stop scraping.

Voices

Curated perspectives — historical figures and your fellow readers.

Ever wondered what historical figures would say about today's headlines?

Sign up to generate historical perspectives on this story.

People Involved

Organizations Involved

Timeline

October 2025 September 2026

3 events Latest: 7 days ago

Scenarios

1

LinkedIn sues the next ProAPIs

Likely Resolves by Q2 2027

Discussed by: gblock analysis and The Record note LinkedIn has removed two scraping operations in five months, pointing to an active enforcement program.

LinkedIn takes the consent judgment as a template and files a new federal suit against another data broker selling scraped profile data. The judgment established no legal precedent, so each new case must be fought on its own contract and user-agreement grounds.

2

ProAPIs ban holds, case closes quietly

Likely Resolves by Q2 2027

Discussed by: Bloomberg Law and Law360 report the defendants consented to the judgment; The Record notes ProAPIs posted that it will never scrape LinkedIn again.

ProAPIs, Netswift, and Alam comply: they delete the scraped archive, stop selling data, and file no appeals. The docket goes quiet apart from a final compliance filing.

3

ProAPIs violates the ban, faces contempt

Unlikely Resolves by Q2 2027

Discussed by: gblock analysis questions whether the deletion obligation will be audited or “merely promised.”

A former customer or LinkedIn discovers ProAPIs still holding or selling LinkedIn data, or still running fake accounts. LinkedIn moves for contempt, asking the court to enforce the judgment with sanctions.

Historical Context

2 moments from history that rhyme with this story — and how they unfolded.

November 2013 – May 2015

Craigslist v. 3Taps (2013–2015)

Craigslist sent scraper 3Taps a cease-and-desist letter and blocked its IP addresses. 3Taps and its partner PadMapper kept scraping by moving to different hosting and circumventing the blocks.

Then

The Northern District of California found that circumventing technical barriers after a cease-and-desist constituted unauthorized access under CFAA and entered a permanent injunction.

Now

The case established that bypassing technological gates, unlike merely scraping open pages, creates clear liability.

Why this matters now

ProAPIs' use of millions of fake accounts to dodge LinkedIn's blocks mirrors the 3Taps pattern of circumventing technical barriers, the liability theory that won in court.

June 2017 – April 2022

hiQ Labs v. LinkedIn (2017–2022)

Data analytics firm hiQ Labs scraped LinkedIn member profiles that were publicly visible. LinkedIn sent cease-and-desist letters and blocked hiQ's crawlers; hiQ sued, seeking an injunction to keep scraping.

Then

In 2019 the Ninth Circuit ruled scraping publicly available data does not violate the Computer Fraud and Abuse Act, and reaffirmed in 2022 after the Supreme Court's Van Buren decision.

Now

hiQ ultimately lost on contract-based claims and paid LinkedIn $500,000. Companies posting terms of service retained contract and trespass-to-chattels claims even where CFAA fails.

Why this matters now

It explains why LinkedIn sued ProAPIs for breach of contract and fraud rather than relying only on CFAA, and why this consent judgment, built on user-agreement violations, stuck.

Sources

(9)