LinkedIn's Legal Battles Over Terms of Service Violations
I've been digging into LinkedIn's legal battles over data scraping and Terms of Service violations. Specifically, how courts have interpreted the Computer Fraud and Abuse Act (CFAA) when it comes to web scraping.
Key Findings
hiQ Labs v. LinkedIn (2022) set the key precedent here:
- Scraping publicly accessible data doesn't violate the CFAA
- "Without authorization" applies to technical access restrictions, not just ToS violations
- Website terms alone can't criminalize access to public information
- Note: hiQ did use some fake accounts to access password-protected data, leading to partial CFAA liability in settlement
LinkedIn v. ProxyCurl (2025) - a more recent case:
- LinkedIn sued ProxyCurl for unauthorized scraping, fraud, and trademark misuse
- ProxyCurl ran a $10M revenue business providing LinkedIn profile scraping APIs
- LinkedIn alleged Proxycurl gathered data only available to logged-in members (implying possible use of fake logins or other techniques)
- Court entered a permanent injunction requiring data deletion and blocking future access
- ProxyCurl shut down in July 2025 rather than fight LinkedIn's "unlimited war chest"
- Shows that platforms can still enforce through contract, fraud, and IP claims even when CFAA might not apply
LinkedIn v. ProAPIs (2025) - the latest case:
- Filed in Northern California against ProAPIs and CEO Rahmat Alam
- Alleges use of millions of fake accounts to access password-protected content
- Unlike hiQ (which scraped public profiles), ProAPIs allegedly went after data behind LinkedIn's login wall
- ProAPIs allegedly charges customers up to $15,000/month for this non-public data
- LinkedIn detects scraping within hours, but ProAPIs reportedly spins up hundreds or thousands of fake accounts daily to get around it
- Also alleges trademark abuse
- Using fake accounts to bypass authentication significantly strengthens LinkedIn's legal position
What this means:
- Scraping public data doesn't violate CFAA, even when it violates ToS (hiQ precedent)
- Bypassing technical access controls (passwords, fake accounts) likely does violate CFAA
- Cease-and-desist notices can turn authorized access into unauthorized access
- Commercial scraping of public data faces challenges but has legal precedent
- Platforms can still go after you with contract and trademark claims even when CFAA doesn't apply
Read the Full Research
For detailed analysis of the legal cases, court holdings, practical implications, and best practices:
Download the full PDF report
The complete report covers:
- Detailed case analysis (hiQ Labs, Power Ventures, ProxyCurl)
- Legal principles and CFAA scope
- Best practices for scrapers and platforms
- State laws and international considerations
- Practical guidance for businesses
Additional Reading:
This research was prepared with AI assistance and is for informational purposes only. It does not constitute legal advice. Consult with qualified legal counsel for specific legal questions.