An open laptop beside a staff badge on a lanyard drawn in blue binary digits on a dark background, beside the headline LinkedIn Hacked? Take It Back.

LinkedIn Hacked and Email Changed: How to Get Back In

LinkedIn hacked and the email changed? Use Forgot password, then "Can't access this email?" to add a new email and verify your ID. Steps for Malaysia.

11 min read
Short answer

The reset now goes to the attacker's email, so use LinkedIn's lost email route. Choose Forgot password, then Can't access this email, then Don't have access to any of these, and enter a new email only you control. LinkedIn then asks for a photo of a government ID. Secure your own email first and report the takeover.

Summary
  • If someone changed the email on your LinkedIn, the password reset now goes to them, so you need LinkedIn's route for members who cannot reach their email.
  • On the sign in screen choose Forgot password, then Can't access this email, then Don't have access to any of these, and enter a new email you control.
  • LinkedIn then asks for a photo of a valid government ID through its verification partner Persona, and sometimes a selfie, before it restores access.
  • Secure your own email account first and use the Report Unauthorized Account Access or Changes form from LinkedIn's compromised account page.
  • LinkedIn has no phone support and never asks for your password, so ignore anyone offering to recover the account for payment or asking for a code.
  • LinkedIn makes the final decision and some cases take time; once you are back in, remove the attacker's details and turn on two-factor authentication, ideally with an authenticator app.
Table of contents14 sections
  1. 01What Do You Do When Your LinkedIn Is Hacked and the Email Is Changed?
  2. 02Which Situation Are You In?
  3. 03If You Can Still Sign In: Lock the Attacker Out
  4. 04If You Are Locked Out: The Lost Email Route
  5. 05How LinkedIn's ID Verification Works
  6. 06Evidence Checklist Before You Verify
  7. 07Why Your Verification Code Is Not Arriving
  8. 08Secure Your Email Before Anything Else
  9. 09After You Get Back In: Clean Up
  10. 10Fake LinkedIn Emails and Appeal Messages
  11. 11If Money Was Lost or Your Profile Scammed Others in Malaysia
  12. 12Mistakes That Slow a LinkedIn Recovery
  13. 13When Expert Recovery Help Makes Sense
  14. 14Frequently Asked Questions

You try to sign in to LinkedIn and your password no longer works. You tap Forgot password, and the code goes to an email address you have never seen. Or you still have access, but LinkedIn has emailed you about a sign in from a new device, and your headline now advertises something you did not post.

You can usually still get back in. LinkedIn has a route for members who cannot reach the email on their account: you give it a new email address and prove who you are with a government ID. At the same time, report the takeover to LinkedIn and lock down your own email so it cannot happen twice.

This guide covers both situations, the ID check, missing codes, and what to do in Malaysia if the attacker used your profile to scam others.

Last checked: 29 September 2026.

#What Do You Do When Your LinkedIn Is Hacked and the Email Is Changed?

Go to the LinkedIn sign in page, choose "Forgot password", enter your old email or phone, and when LinkedIn asks for the code, choose "Can't access this email?" and then "Don't have access to any of these?". Enter a new email address that only you control, then verify your identity with a photo of a valid government ID. LinkedIn's page on having no access to your email address lists these steps and says LinkedIn will process your information and contact you. Report the takeover through the form on LinkedIn's compromised account page as well, and include your profile URL if you have it.

#Which Situation Are You In?

Find the row that matches your screen, then follow the matching section below. Wording can vary by app version and region.

LinkedIn takeover symptoms and the route for each, at the time of writing.
What you seeWhat it usually meansYour route
A security email about a sign in from a new device or browser that was not youSomeone has your password and is trying the second step, or has already passed itReset the password now, sign out other sessions, report it
You can sign in, but posts, messages or profile details changed without youSomeone else is inside the account right nowChange the password, end sessions, check emails and phones, submit the report form
Your password stopped working, but the reset code still reaches your email or phoneThe attacker changed the password but not your contact detailsReset the password with the code, then secure the account straight away
The reset code goes to an email or phone you do not recogniseThe attacker replaced your contact detailsForgot password, "Can't access this email?", "Don't have access to any of these?", then ID verification
The two-factor code never arrives, or your authenticator no longer worksThe attacker may have changed 2FA, or your own phone or app changedSee the section on missing codes below

#If You Can Still Sign In: Lock the Attacker Out

Act while your session still works. LinkedIn's compromised account page asks you to submit the Report Unauthorized Account Access or Changes form, then take these steps immediately:

  1. Change your password to one you use nowhere else, not even on your email.
  2. Turn on two-factor authentication.
  3. Review your active sessions and sign out of anything you do not recognise.
  4. Check every email address and phone number on the account, and remove any that are not yours.
  5. Secure the personal email accounts tied to LinkedIn, including resetting their passwords.

Sessions live under the Me icon, then "Settings & Privacy", then "Sign in & security", then "Where you're signed in". LinkedIn's page on seeing where you're signed in says each session shows the device, browser, IP address and an approximate city. Choose "Sign out of all these sessions" on desktop or "End these sessions" in the app, then confirm with your password. Check connected third party apps under "Partners & services" too.

#If You Are Locked Out: The Lost Email Route

Use this when every reset lands in the attacker's inbox. LinkedIn's no access to email page gives these steps:

  1. On the sign in screen, select "Forgot password".
  2. Enter the email or phone on the account (try your old email first) and select "Next".
  3. When asked for the verification code, select "Can't access this email?".
  4. If LinkedIn offers a list of emails or phone numbers, and none are yours any more, select "Don't have access to any of these?".
  5. On a desktop, scan the QR code on screen with your phone. This step does not appear if you started on mobile.
  6. Enter the new email address you want on the account. You can also add your profile link, which is optional but helps.
  7. Verify your identity with an image of a valid government issued ID. LinkedIn then processes it and contacts you.

Why not just use the report form? At the time of writing, LinkedIn's help forms usually send a logged out visitor to the sign in page, which is exactly where you are stuck. The lost email route starts from the sign in screen, so start there and file the report once you are back in.

#How LinkedIn's ID Verification Works

LinkedIn uses Persona, an outside identity verification provider, to confirm you are the rightful owner. Its page on verifying your identity to recover access says Persona asks for a digital ID or a clear photo of a valid government issued ID card, driving licence or passport, and in some cases a photo of yourself to match your face to the ID portrait. Accepted documents vary by country, and library or school cards are not accepted. For most Malaysians that means a MyKad, a driving licence or a passport, but choose from the list Persona shows for Malaysia.

You need a smartphone to take the photo. LinkedIn says Persona shares data only after you tap "Yes, share", that LinkedIn gets a redacted copy of the ID showing just your name and face, not your ID number or biometric data, and that the data is generally deleted within 14 days.

#Evidence Checklist Before You Verify

A rejected photo or a mismatched name costs days. Prepare these before you start the flow:

  • A valid, unexpired ID, photographed flat in good light with all four corners visible and no glare over the text.
  • The name on your LinkedIn profile, written down exactly as it appeared before the hack, so you can explain any difference from your ID.
  • Your profile URL, from an old email signature, CV or a colleague's browser.
  • Every email address and phone number you ever used on LinkedIn.
  • Dated screenshots of LinkedIn security emails you received.
  • A short note of what happened: when you noticed, what changed, what the attacker sent.

#Why Your Verification Code Is Not Arriving

Missing codes are often the first sign of a takeover, and sometimes just a changed phone. LinkedIn's page on two-factor authentication says codes arrive by text message or authenticator app, and that a signed in phone may get a sign in prompt instead. Work through the likely causes:

  • The code goes to an email or phone the attacker added. Use the lost email route above rather than requesting more codes.
  • You replaced or reset your phone. LinkedIn's authenticator app page says the authenticator link is tied to each device and app install. From any device still signed in, turn 2FA off and on again with the new app. With no active session, contact LinkedIn support.
  • You got a security email but did not sign in. LinkedIn's page on two-factor notification emails says it sends one for each sign in from a new device or browser, and if it was not you, reset your password right away.

A Malaysian check worth doing: if your phone suddenly shows no service around the time of the hack, call your carrier from another phone and ask whether a replacement SIM was issued on your number. Text message codes follow the SIM. That is one reason LinkedIn recommends an authenticator app as the preferred 2FA method.

#Secure Your Email Before Anything Else

Your inbox is the master key. LinkedIn's compromised account page lists the ways accounts are usually taken: a login left open on a shared or public computer, an old email or phone on the account that was recycled or compromised, or a password reused on another site that was phished. Change your email password, sign out its other sessions, delete forwarding rules or filters you did not create, and turn on two-factor authentication there too. Our guide to securing your social media accounts in Malaysia walks through that inbox check for Gmail and Outlook.

#After You Get Back In: Clean Up

LinkedIn can undo some of what the attacker did. Its page on compromised account cleanup says that once you regain access, a request form lets you ask it to move the attacker's messages to recipients' spam or label them with a warning, withdraw invitations not yet accepted, and remove posts or comments shared during the takeover. The email notification of an invitation cannot be withdrawn.

Then review recent connections, follows and posts, as LinkedIn suggests. Attackers often send fake job offers or investment links to your network, so warn contacts from another channel not to click anything "you" sent. Our guide to a hacked account messaging your contacts has wording you can adapt.

#Fake LinkedIn Emails and Appeal Messages

Attackers often get in with a fake LinkedIn email, then keep going with fake "policy violation" comments. LinkedIn's page on phishing content names three sender addresses that are genuine: [email protected], [email protected] and [email protected]. It also shows fake comments urging you to appeal to avoid permanent suspension. Real LinkedIn emails carry a security footer with your name and headline. When in doubt, open LinkedIn directly instead of clicking, and forward suspicious emails to [email protected].

LinkedIn's page on recognising scams also warns about job offers that ask for ID photos early or push you to WhatsApp or Telegram. In Malaysia these often arrive in English, Malay or Chinese as "work from home" offers.

#If Money Was Lost or Your Profile Scammed Others in Malaysia

If you or your contacts sent money, or shared banking details on a fake page, call the National Scam Response Centre on 997. The government's NSRC page asks victims to call within 24 hours of discovering the scam so accounts and transactions can be blocked, then contact the bank and lodge a police report. Keep your screenshots and LinkedIn emails for that report.

To report the phishing site or the incident itself, CyberSecurity Malaysia runs Cyber999, the national point of contact for computer security incidents, which accepts reports by online form, email, phone and mobile app.

#Mistakes That Slow a LinkedIn Recovery

  • Requesting code after code to an address the attacker now controls, instead of choosing "Can't access this email?".
  • Using your old, possibly compromised inbox as the new recovery email.
  • Uploading a blurred, cropped or expired ID photo.
  • Opening a new LinkedIn account while you wait, which splits your history and can confuse the case.
  • Paying a stranger who promises to get the account back faster.
  • Getting back in but leaving the attacker's email, phone or connected app on the account.

If LinkedIn restricted the account rather than handing it to someone else, the route is different; see our guide to a restricted LinkedIn account appeal. For the same problem on other platforms, our social media account recovery guide for Malaysia covers Facebook, Instagram and TikTok.

#When Expert Recovery Help Makes Sense

If you have used the lost email route, submitted your ID and filed the report, you have done what LinkedIn asks. A second opinion helps when the ID check keeps failing or the account is taken again after recovery. SocialSafe by AwareXone is AwareXone's recovery and account security service, and we are based in Malaysia. We review your situation first and use only LinkedIn's own processes. Our account security service explains what the review covers, and our Trust Center sets out what we will never ask you for.

#Frequently Asked Questions

Will LinkedIn delete the messages the hacker sent from my account?
It may. Once you are back in, LinkedIn's cleanup request form lets it move the attacker's messages to spam or label them with a warning, withdraw unaccepted invitations and remove posts or comments from the takeover.
How long does LinkedIn take to restore a hacked account?
LinkedIn does not publish a fixed time. A working reset code is fastest; the ID route depends on LinkedIn processing your documents and contacting you.
Is it safe to send my IC to LinkedIn?
Only through LinkedIn's own verification flow, where Persona handles the photo. Never send your IC to someone who contacts you offering help.
Can I call LinkedIn to recover my account?
No. LinkedIn says it does not offer phone support, so any number advertised as LinkedIn support is not LinkedIn.
Why did I get a LinkedIn security email when I did not sign in?
If you use two-factor authentication, LinkedIn emails you whenever someone signs in from a new device or browser. If it was not you, reset your password straight away.
Can AwareXone get my LinkedIn back for me?
No. Only LinkedIn can restore an account. We can review your case and help you prepare a clear request through LinkedIn's own forms.

Official sources

Need help with your account?

Tell us the platform and what you have already tried. We review the case first, work only through official platform processes, and never ask for your password, OTP or backup codes. The platform makes the final decision. Related service: Account security.