Scammers use LinkedIn to find new employees and people who work in finance, payroll and IT, because those are the people who can be persuaded to move money or reset access.
A new-job post gives them a name and a role. A job advert reveals which software the practice uses. Project updates disclose client names, suppliers and travel plans. Put together, that's enough to write a convincing message from "the director" to the new finance assistant.
Sensible guidance for staff
Don't post screenshots of internal systems, staff badges, unannounced client names, supplier changes, or travel plans before or during a trip. Celebrating a project win once it's public is fine; announcing a tender you're chasing isn't.
Do the search yourself
Search for your company's name and look at what employees, job adverts and public posts reveal, as an attacker would. Then tighten what needs tightening.
If you'd like help writing a short social media guideline for the practice, or want to pair it with phishing awareness training, ask us.
Want a hand with this? Talk to us.