Between January 2025 and mid-2026, LinkedIn went from tolerating a gray-zone tool ecosystem to systematically dismantling it. A scraping API was sued out of existence, two of the biggest names in sales intelligence lost platform access, a much-loved analytics product closed, and a founder was personally banned. Each event produced a news cycle; nobody kept the record in one place.

This page is that record — every enforcement action, dated, with what happened and what it signaled. It exists to be cited. At the end there's a short section on what the pattern means if you're buying LinkedIn tooling today.

January 2025 — LinkedIn sues Proxycurl

LinkedIn filed suit against Proxycurl, an API business selling scraped LinkedIn profile data to other software companies. The case settled under a permanent injunction — Proxycurl agreed to delete its data and ceased operating, shutting down entirely by July 2025. It was the opening move of the wave, and it targeted the supply chain: many tools that "enriched" LinkedIn data never scraped anything themselves, they bought from Proxycurl.

March 2025 — Apollo.io and Seamless.ai lose platform access

LinkedIn cut platform access for Apollo.io and Seamless.ai and deleted both companies' LinkedIn pages. These were not fringe products — both are major sales-intelligence platforms with large customer bases. The signal was that scale is not protection; enforcement was no longer limited to small scraping shops.

2025 — the cookie-extension enforcement wave

Through 2025, enforcement widened from scraping infrastructure to distribution — Chrome extensions that work by borrowing the user's logged-in LinkedIn session cookie. An extension built this way acts as the member without being the member, which makes it both a policy violation for the vendor and an account risk for the user whose session it rides. A related pattern, coordinated engagement pods, was already being detected and demoted on-platform (the Lempod story is the canonical example).

May 18, 2026 — Shield Analytics shuts down

Shield Analytics, a widely liked LinkedIn analytics product, announced its shutdown on May 18, 2026. Its site, shieldapp.ai, is now a wind-down notice stating that Google and LinkedIn made clear the product could not continue as it was built — LinkedIn enforced its platform policies while the Chrome Web Store pulled Shield's extension. Shield matters as a data point because it was not a scraper or an automation tool; it was analytics, delivered through a session-riding extension, and the architecture alone was enough. Within days, competitors published migration pages (ours is here).

2026 — HeyReach's company page removed, founder banned

LinkedIn permanently removed the company page of HeyReach, a LinkedIn outreach-automation platform, and banned its founder, Nikola Velkovski, from the platform. HeyReach continues to operate as a business — the enforcement struck its presence on LinkedIn itself. The escalation is notable: enforcement now reaches the people behind the tools, not just the tools.

March 2026 — the Transparency Report quantifies the wave

LinkedIn's March 2026 Transparency Report put numbers on the machinery behind these actions — 78.2 million fake accounts blocked and 23.5 million automated sessions flagged in a single quarter. Numbers at that scale mean detection is automated, continuous infrastructure, not manual case-by-case policing. Every automated session a tool creates is a data point in that system.

What this means for buyers

Compliance is now a primary buying criterion for LinkedIn tooling — on par with features and price — because the enforcement record shows the downside is total. Shield's customers didn't lose a feature in May 2026; they lost the product, on weeks of notice. Proxycurl's downstream customers lost their data supply mid-contract. When a vendor is built on a non-compliant architecture, its roadmap is hostage to a policy decision it doesn't control.

Four questions to ask any LinkedIn tool vendor before buying:

  • How do you access LinkedIn — the official API with OAuth consent, or my session cookie via a browser extension?
  • Does anything happen on my account without my explicit approval — posts, comments, invites, data pulls?
  • Has LinkedIn ever taken action against you — page removal, access cutoff, cease-and-desist, litigation?
  • If you were forced to shut down tomorrow, what happens to my data — and can I export it today?

A vendor on the right side of these answers them happily. Evasiveness is itself the answer.

Which architectures survive — and which get banned

The pattern across every event above is architectural, not commercial. What gets removed: session-cookie extensions, scraping and scraped-data supply chains, and automated sessions — the exact behaviors the Transparency Report counts in the tens of millions. What keeps operating: tools built on LinkedIn's official API with OAuth consent, where a human owner approves what happens on their own account.

Full disclosure — GTM Brigade, our product, sits on the OAuth-and-owner-approval side of that line; that positioning lives on our Shield Analytics alternative page, not here. This page's job is to stay a neutral, dated record either side can cite.

This timeline is updated as enforcement events occur. Last reviewed August 6, 2026.