Article
How to Spot Fake LinkedIn Sales Bots
LinkedIn is now a primary channel for business fraud, and the fake profiles have got good. Here is how to tell a real prospect from a bot working an angle.

LinkedIn occupies a strange position in most people security thinking: it is the one platform where receiving unsolicited messages from strangers is completely normal. Someone you have never met asks to connect, opens with a pitch, and nobody blinks. That is an enormous advantage if your goal is fraud.
The result is that LinkedIn has become a serious channel for business attacks — not just tedious sales spam, but reconnaissance, credential theft and the groundwork for invoice fraud.
What they are actually after
Understanding the objective makes the tells easier to read, because different goals produce different behaviour.
Reconnaissance. The most common and least obvious. Connecting gives an attacker your full profile, your connection list, your role and your colleagues. That is the raw material for a convincing impersonation email later: they now know your finance manager name, who reports to whom, and who is on leave because someone posted about it.
Credential theft. A link to a "shared document" or a "proposal" that leads to a fake Microsoft 365 login page. The LinkedIn conversation exists purely to make the link feel expected.
Malware. Most commonly disguised as a job description or a candidate CV, which is why recruiters and hiring managers are targeted disproportionately.
Long-game fraud. A relationship built over weeks that ends in an investment opportunity or a payment. Patient, and expensive when it works.
The profile tells
Fake profiles have improved considerably. AI-generated headshots no longer have obvious artefacts, and the bios read fluently. Look at structure rather than polish.
- A thin history with a senior title. A VP with two years of listed experience and no earlier roles is a fabrication, because real careers leave a trail.
- Very few connections, or thousands with no engagement. Both are wrong in different ways. Real professionals accumulate connections gradually and their posts get responses from actual humans.
- No mutual connections in an industry where you would expect some. If someone claims fifteen years in Australian managed services and shares nobody with you, that is worth a pause.
- A headshot that is too good. Studio-quality, perfectly centred, neutral background, slightly uncanny symmetry. Reverse image search takes ten seconds.
- An employer that cannot be verified. Check whether the company page has real employees, real posts and a real website, or whether it was created last month.
- Location and language mismatch. A profile claiming Sydney with phrasing and spelling conventions from elsewhere.
The message tells
Behaviour gives it away faster than the profile does.
The pitch arrives instantly. Connection accepted at 9:01, sales message at 9:02. Automation, at best.
It does not match your business. Generic flattery that would apply to anyone, or an offer aimed at an industry you are not in. Real salespeople at least read the profile.
Urgency in a context that cannot justify it. A stranger on LinkedIn has no legitimate reason for a deadline today.
An early push to move platforms. "Message me on WhatsApp" or "here is my personal email" within the first few exchanges is the single strongest signal. LinkedIn logs conversations and can ban accounts; a private channel does neither.
A link or attachment with no established relationship. No legitimate first contact requires you to open a document to understand the offer.
Why this matters more than the nuisance suggests
The connection itself is the payload for the most expensive attack in Australian business fraud: business email compromise.
The pattern runs like this. An attacker maps your organisation through LinkedIn — who approves payments, who the directors are, who handles supplier accounts. They then send an email that references real people, real projects and real reporting lines, because they researched all of it legitimately from profiles people published on purpose.
The email asks accounts to update a supplier bank account, or the "director" asks for an urgent transfer while travelling. It succeeds because it is specific, and it is specific because of LinkedIn. We covered the voice-cloning evolution of this in our piece on the deepfake CEO scam, and the reconnaissance stage is identical.
Practical hygiene
- Be selective about connections. Your connection list is an org chart you are publishing.
- Review your public profile. Detailed descriptions of internal systems and processes help attackers more than recruiters.
- Think before posting operational detail. Announcing that the finance team is away at a conference is useful information to the wrong reader.
- Report and block rather than just ignoring. Reporting removes the profile for everyone.
- Verify out of band. If someone claims to be from a supplier, ring the supplier on a number you already have.
The control that actually stops the loss
Training helps, but the reliable defence against LinkedIn-sourced fraud is a payment process that does not depend on anyone spotting the fake.
Any change to supplier bank details gets verified by phone, on a number from your existing records, never one supplied in the request. Payments over a threshold require two approvers. Both rules are unglamorous, and together they defeat the entire attack chain regardless of how convincing the impersonation was.
Add user awareness training that includes social platforms rather than email alone, and managed detection and response to catch the mailbox rules and unusual sign-ins that follow a successful lure.
Local IT and cyber security support across NSW
Chewing IT runs managed IT and cyber security for small and mid-sized businesses from our Wyong and Hornsby offices, covering the Central Coast, Newcastle, Lake Macquarie and Hornsby.
Worried someone in your team would act on a convincing request? Ask us about payment verification controls and awareness training that covers more than email.