Security ·
Profile deepfakes: when someone else's LinkedIn is a synthetic version of you
In 2026 it no longer takes much imagination to clone someone else's LinkedIn profile. With an image model trained on a few public photos, a text generator and a free afternoon, anybody can put together a profile using your face slightly altered, a name almost identical to yours and a biography that sounds like something you might have written. The victim usually finds out by chance, when a contact asks whether they "also have an account with the middle name in front".
This guide explains how profile deepfakes work, how to spot one quickly if a colleague warns you, how to report it so LinkedIn takes it down in under 48 hours, and what preventive measures you can take today to make impersonating you cost considerably more than it is worth to whoever tries.
By Sheena de PunkVoice · Edited by Mario Pérez

What a profile deepfake exactly is
A profile deepfake is an account created to pass itself off as a real person, resting on three pieces generated or manipulated with AI: a photo (often your real one, slightly retouched to get past duplicate image detectors), a name almost identical to yours (with a middle name added, an initial instead of the first name, an invisible Unicode character) and a biography written in roughly your tone from the one you already have public.
The purpose varies. The most common in 2026 is romance fraud or commercial fraud: the impostor connects with your contacts, starts a conversation in private messages and at some point proposes a financial transaction (an investment, a loan, consultancy paid up front). Other uses: reputation damage (publishing content in your name to harm you), phishing aimed at your employer, or inflating follower counts by buying already active profiles.
The profiles usually have between 200 and 800 connections by the time you discover them. That is enough to pass the visual check most of your contacts make, and well below your real network, which also serves as a clue.
How to spot a profile deepfake in under a minute
When a contact tells you "there is another account of yours" or you find a suspicious one yourself, the first minute decides whether you are looking at a real namesake or an impersonation. These are the six quick checks that resolve 90% of cases.
- Compare the name character by character. Impersonators use subtle variations: an "i" replaced by an "í", an "a" with a Cyrillic accent, a non-breaking space between first and last name, an almost invisible underscore.
- Run the suspicious profile's photo through Google Images. If it appears on several profiles on other networks under different names, it is a bank of stolen photos.
- Look at mutual connections. If you have zero mutual connections but the profile claims to have worked at your company for three years, it is impersonation.
- Check the account's age. A profile created less than six months ago with a very polished biography and a professional photo is usually suspicious; real profiles leave a trail of historical activity AI cannot fabricate.
- Read three of the suspicious profile's posts out loud, one after another. If they sound like AI with no human editing (the five tells from the accent guide), that adds to the impersonation signal.
- Look at the About section. An impostor usually reproduces yours with slight linguistic variations: the verbs change, the sentence order shifts, but the concrete examples and proper names disappear or get replaced with generics.
How to report it so LinkedIn takes it down
LinkedIn has a specific procedure for identity impersonation, separate from the generic spam report. It is slower but far more effective, and since 2025 it lets you attach documentary evidence. These are the steps in the order that works in 2026.
One: go into the suspicious profile, tap the "More" menu and choose "Report or block", then "Report this profile", then "Impersonation". Two: fill in the request with the URL of your real profile and a photo of yourself with your ID document visible (LinkedIn keeps it encrypted and does not publish it). Three: block the impersonating account from the same menu to cut off its access to your profile.
Four: send a message to the support team by tapping "Help" on your own profile and describing the case with all three URLs (your real profile, the impersonator, any other related one). Five: warn your contacts with a short post on your own wall. There is no need to show the fake URL (which would still send traffic to it), it is enough to explain that an impersonating account exists, that they should not interact and that they should report it. Six: if the impersonation involves completed or attempted financial fraud, report it in parallel to the police cybercrime unit and, in Spain, to INCIBE.
In 2026 the average takedown time after a report accompanied by an ID document is 24 to 48 hours. Without a document, it can take weeks or never happen.
What to do while the fake profile is still live
Even with the report under way, the fake profile can keep operating for 24 or 48 hours. In that time three concrete actions reduce the damage: containing your network, leaving a public record that you know it exists, and documenting. Containing means your most exposed contacts (your team, active clients, family) hear through a channel other than LinkedIn that there is an impersonating account. A short message by email or WhatsApp is enough.
Leaving a public record means publishing a short, dated post on your real profile noting the fake account's existence and asking people to report it. If the impostor later gets something out of a third party, that post protects you legally (and helps LinkedIn's internal process accelerate the takedown). Documenting means taking screenshots of the fake profile, of its three or four posts and of any message it sent to your contacts, saving the date and the URL. If it ends in a criminal report or litigation, those screenshots are the evidence.
How to make impersonation harder before it happens
No profile is 100% immune, but some measures raise the cost of impersonating you a lot. All of them take a couple of hours to implement and last for years.
- Complete LinkedIn's Verified process if you are eligible (employees of companies with a verified domain, government, universities). It is the badge an impostor cannot replicate.
- Publish regularly. A profile with a consistent editorial cadence leaves a trail AI cannot fabricate in a few weeks.
- Customise your short URL (linkedin.com/in/yourname) and share it in your email signature, on your website and on your cards. It is the one people share when they are unsure between two profiles.
- Use a profile photo that is hard to recycle: looking at the camera with a specific expression and a background recognisably yours, rather than the typical studio shot anyone can regenerate.
- Write an About section with specific anecdotes: proper names, dates, figures. It is material an AI can rephrase but cannot invent without obvious errors.
- Turn on two-factor authentication, review active sessions monthly and change your password twice a year. Half of impersonations start with unauthorised access to the real account.
Identity is protected by acting, not by trusting the platform
LinkedIn has got serious about impersonation over the last two years, but its capacity to act is reactive: it only moves when somebody reports. While the report is processed, containment is on you. A profile with a consistent presence, a recognisable photo, active contacts and its own URL shared across every channel turns a possible impersonation into an unprofitable fraud for whoever attempts it.
The other half of the work is cultural: helping your contacts normalise doubt when a second account with your name appears. A simple "if you get a second request from me, verify it through another channel before accepting", said occasionally in your own posts, counts for more than any technical measure.