What this page carries that others in this category do not: the full citation chain for one statistic, each page quoted with its URL and fetch date, then checked against LinkedIn's own help pages and the federal court record. All fetches 5 September 2026 unless stated otherwise.

1. The claim

If you have read anything about LinkedIn automation in the last few months, you have probably met this number. It turns up in vendor blog posts, in comparison articles, in "is this tool safe" explainers, and, as of our check, in at least one search engine's AI-generated answer. In its original form the sentence reads:

"LinkedIn's enforcement against automation tools got serious in Q1 2026. The number that matters: roughly 40% of accounts using non-compliant automation tools received some form of restriction between January and March 2026."

It is a good sentence. It is specific, it is bounded by dates, it carries a percentage, and it reads like the output of a measurement. We wanted to cite it. That is why we went looking for the study behind it.

What follows is what we found, in order. We are not making a case about anybody's motives, and we do not know them. Every step below is a statement about text that you can open and read for yourself.

2. The origin

The earliest version of the sentence we could find sits on northlight.ai/blog/linkedin-automation-without-getting-banned. That is the wording quoted above, verbatim, captured on 5 September 2026.

Four things about that page:

  • There is no hyperlink on or near the claim. Nothing to click through to.
  • There is no citation, no sample size and no methodology. No population, no measurement window beyond the months named, and no description of how an outside party could observe restrictions on accounts it does not own.
  • The words study, survey, sample, methodology and dataset appear nowhere on the page. We checked that programmatically against the page text rather than by reading it, so it is a property of the document and not an impression.
  • The sentence names no tools. Not one. It refers to "non-compliant automation tools" as a category and stops there. Hold on to this detail, because it is the one the next page in the chain changes.

Two contextual facts, stated neutrally. Northlight sells a LinkedIn automation product, a macOS desktop app that runs through the user's own browser session, priced from a free tier up to $80 a month and in open beta as of 5 September 2026. And the paragraph containing the claim sits directly above the page's own pitch. Both are observable from the page. Neither of them tells you whether the number is right.

One caveat we will raise ourselves, because it cuts against a tidy story. Two separate fetches of that post returned different content: one carried the sentence twice, a later one did not carry it at all. The page may have been edited between them. We quote the version we captured, and we note that this changes nothing downstream, because the republications quote it, are dated, and are still live.

The same page carries a second uncited assertion that we come back to below: "the 2026 LinkedIn Transparency Report showed a massive increase in automated account removals".

3. Step one: four tool names appear

The next link in the chain is joinvalley.co/blog/linkedin-automation-safety-2026, published 11 May 2026 and updated 31 August 2026. It restates the claim like this:

"Northlight.ai's Q1 2026 analysis quantified this pattern: roughly 40% of accounts using non-compliant automation tools - explicitly naming HeyReach, Expandi, Dripify, and Waalaxy - received some form of restriction between January and March 2026."

Put the two sentences side by side and the change is visible without interpretation.

 What the origin saysWhat the republication says it says
Tools namedNoneHeyReach, Expandi, Dripify, Waalaxy
AttributionStated by the author"explicitly naming"
Described as"The number that matters""Q1 2026 analysis quantified"
Source offeredNoneNorthlight

The attribution is false. That is a checkable statement about two documents rather than a claim about anyone's intentions: the Northlight page names none of those four tools, so it cannot be explicitly naming them. Four companies are now attached to an enforcement statistic by a sentence that never mentioned them.

Valley also sells a LinkedIn tool, priced at $199 and $499 per seat per month as of 5 September 2026. The same post carries its own uncited safety claim, "Valley has managed 1,000+ LinkedIn accounts across its customer base over 2+ years of operation. Zero documented account restrictions from LinkedIn enforcement." We record that as an unverifiable vendor claim, exactly as we would record one of ours.

4. Step two: an assertion becomes an analysis

Further down the chain, anybiz.io restates the figure as coming from "A first-quarter analysis by Northlight".

Nothing new has been measured between step one and step two. What changed is the grammar of authority. A sentence written on a marketing page has become "an analysis", a word that implies a method, inputs and an analyst. AnyBiz also sells a competing product. As before, that does not make the sentence wrong. It is simply the third page in a row where the party carrying the number also sells against the tools the number is used to describe.

5. Step three: into AI search results

The last step is the one that matters most for anyone deciding what to believe in 2026. Asked about LinkedIn enforcement, a search engine's own AI summary returned the figure as coming from "A Northlight.ai study on Q1 2026".

Follow the escalation across the four documents:

  1. Origin: an unsourced sentence, naming no tools.
  2. Step one: the same sentence, now "explicitly naming" four tools it does not name.
  3. Step two: the same sentence, now "an analysis".
  4. Step three: the same sentence, now "a study", delivered by a search engine as an answer.

No new evidence enters at any point. Each step adds a word the previous step did not support, and the final step strips out the chain entirely and presents the result as a finding. This is the practical failure mode of generative search in a category where almost every publisher is also a vendor: repetition across many domains reads like corroboration, and here the domains are not independent of each other. They are quoting each other.

6. The primary-source check

Only one party in the world can count restrictions on LinkedIn accounts, and that is LinkedIn. So the question is narrow: does LinkedIn publish a number the figure could be derived from?

It does not. LinkedIn's Transparency Center reports fake accounts, spam and scams, content violations, copyright removals and government requests. Its Community Report covering July to December 2025 publishes fake-account volumes and its own proactive-detection rate for fake accounts. It publishes no statistics on account restrictions tied to third-party automation tools, and no per-tool enforcement rates. Checked 5 September 2026.

That absence is not a gap in an otherwise complete picture. LinkedIn reports in real detail on the categories it does report on. This category is simply not one of them, which means no outside party can derive an enforcement rate from LinkedIn's publications, because both the numerator and the denominator live inside LinkedIn.

The Transparency Report claim, separately

The origin page's second assertion, that "the 2026 LinkedIn Transparency Report showed a massive increase in automated account removals", is worth separating out, because it conflates two different populations:

  • Fake accounts removed. LinkedIn does report these. They are accounts that should not exist, created in bulk, and improvements in detection move that number.
  • Restrictions applied to real members who use automation. LinkedIn does not report these at all.

A change in the first is not evidence about the second. Different people, measured differently, and only one of the two is published.

What LinkedIn does say

LinkedIn's prohibited software policy bans "any third party software, including 'crawlers', bots, browser plug-ins, or browser extensions that scrape, modify the appearance of, or automate activity on LinkedIn's website", and says members "risk having their accounts restricted or shut down". It names no tool and gives no statistic. A separate help article on invitation limits adds: "If you send an excessive number of invitations and we suspect the use of an automation tool, we may suspend or restrict your account." And on why you cannot reverse-engineer the rules from your own experience: "LinkedIn Support cannot disclose the type or reason for the restriction."

That is the published record in full: a prohibition, a warning, and an explicit refusal to explain individual cases. Any percentage attached to it came from somewhere else.

7. What is actually on the record

A fact check that only takes things away is less useful than one that leaves you with the verified version. Here is what we could confirm from federal dockets through CourtListener, checked 3 to 5 September 2026.

LinkedIn has filed exactly two scraping lawsuits since mid-2024, and both are against data-API companies rather than outreach automation tools.

DateCaseStatus
24 January 2025LinkedIn Corp. v. Nubela Pte. Ltd., Proxycurl LLC, Steven Goh, Bach Le, No. 3:25-cv-00828 (N.D. Cal.)Six claims, including breach of contract, fraud, CFAA, trademark and misappropriation
4 July 2025ProxycurlShut down. Its founder wrote that "there is no winning in fighting this"
25 July 2025LinkedIn Corp. v. NubelaJudgment entered. We read the docket entry rather than the document itself, so we state the fact and the date and no terms
2 October 2025LinkedIn Corp. v. ProAPIs Inc., No. 5:25-cv-08393 (N.D. Cal.)Eight counts. The complaint alleges more than a million fake accounts and an API sold at up to $15,000 a month
9 February 2026LinkedIn Corp. v. ProAPIsAgreement in principle, terms undisclosed. As of 3 September 2026, no settlement, injunction or judgment had been entered

Both defendants were selling programmatic access to LinkedIn data at scale, and the ProAPIs complaint describes fake-account infrastructure as the mechanism. Neither is a tool a salesperson installs to send connection requests. Our sweep of federal filings found no litigation involving PhantomBuster, Dux-Soup, Expandi, Dripify, Waalaxy, Meet Alfred, Closely, Octopus CRM, Salesflow, Skylead or Linked Helper.

The one documented cease-and-desist

On 5 August 2025, a developer posting as jpctan on Hacker News (item 44796306) wrote that he had built a LinkedIn engagement assistant used by around 100,000 people across more than 150 countries, then received a cease-and-desist from LinkedIn Legal and shut it down immediately. His own reflection: "I naively thought they would go after all the full automation tools that spam their users, while we always put humans in the loop."

That is a first-person account from the person who received the letter, which makes it the best-sourced enforcement event against a tool builder that we have. By contrast, the far more widely repeated claim that LinkedIn issued HeyReach a cease-and-desist is unverified: it appears on blogs published by competing vendors, we found no primary source for it, and LinkedIn does not comment on individual enforcement. We are not saying it did not happen. We are saying nobody has shown that it did.

8. Why this keeps happening

The structural reason is simple, and it does not require anyone to act in bad faith. Every vendor in this category benefits from the belief that a rival's architecture is dangerous, so architecture-risk claims get written, and almost nobody in the category is positioned to check them.

You can see the result by lining up what different vendors publish about the same question:

PublisherWhat it says is riskyWhat it sells
NorthlightCloud proxy infrastructureA desktop app running in your own browser session
ValleyShared cloud proxy infrastructureCloud, with a dedicated IP per account
LinkedInsiderCloud infrastructureMarketing site for another tool
CleverlyBrowser extensionsCloud
LinkedNavBrowser extensionsCloud
SyncGTMBrowser extensionsCloud

Three publishers say cloud infrastructure is the exposure. Three say browser extensions are. In every case, the architecture described as safe is the one the publisher sells. Northlight's version, uncited and on the same page as the 40% sentence, reads "Most platforms use cloud proxy infrastructure, which is why their users keep getting banned", and its own architecture is described as "a proprietary browser integration that operates through your real browser session. LinkedIn sees your session because it is your session."

The most honest sentence we found in the entire genre comes from LinkedInsider, and it appears immediately before that site goes on to cite its own uncited statistics:

"anyone citing a precise 'X percent of accounts got banned in 2026' is almost certainly fabricating the number."

Two concessions, since we are the ones handing out scrutiny. First, the underlying advice on several of these pages is reasonable: pacing your activity, not running many accounts from one address, and treating LinkedIn's published warnings as real are all sensible whatever you use. Valley's stated design, "dedicated IP addresses per account (not shared), enforces LinkedIn's published daily limits as hard caps (not user-configurable)", is a better answer to the shared-infrastructure question than most of this category offers, and caps a user cannot raise are a discipline we would like to see more often. Second, we are not exempt. An earlier draft of our own internal guidance repeated the neighbouring claim that a "compliant API" alternative exists, until we checked Microsoft's developer documentation and found that no official LinkedIn API sends connection requests, sends member messages or performs people search. The Compliance API, the one usually gestured at, is documented as being for "monitoring, archiving, and management of communications for enterprises in regulated industries". We had believed a claim that the primary source contradicts.

9. How to check a statistic yourself

This takes about five minutes and works on any number in this category.

1. Follow the link. If there is no link, the page is the source

Click the number. If nothing is clickable, you have reached the origin, whatever the page implies about where it came from. Then search the page for the words study, survey, sample, methodology, dataset. Real measurements almost always say how they were made, because saying so is the entire point of publishing one.

2. Find the earliest copy of the sentence

Take a distinctive fragment, ten or twelve words, and search it inside quotation marks. Sort by date. The oldest page carrying the phrase is usually the origin, and the newer ones very often contain detail the origin does not. That gap between versions is where invention happens, and spotting it requires no judgement call at all.

3. Ask who could even measure it

A restriction rate needs two numbers: how many accounts used a given tool, and how many of them were restricted. Only the platform can see the second. Only the vendor can see the first. If neither publishes it, no third party can compute it, so the figure cannot have a legitimate derivation regardless of who is repeating it.

4. Read who sells what, on the page carrying the number

Scroll down to the pitch. Then ask whether the architecture the statistic condemns happens to be the one the publisher does not sell. This proves nothing on its own, and plenty of true things get published by interested parties. But when it holds for every page in a chain, you are looking at a marketing position rather than a finding.

10. Where we stand

We build Leadsforlinked, which competes with several of the companies named on this page, so we carry the same incentive everyone else here does. That is exactly why we will not put an enforcement percentage on our own site, in either direction. We publish none, because none exist: LinkedIn does not release restriction rates for third-party tools, we cannot compute one, and any figure we invented would be worth no more than the one we have just spent this page tracing. What LinkedIn does publish is a prohibition, a warning that accounts can be restricted or shut down, and a refusal to explain individual cases. We would rather hand you that, plus the method above, than a number that sounds decisive and rests on nothing.

If you want to see what our tool actually produces before deciding anything, the free tier exists for that: 100 leads on signup, no card. Open the CSV and count the rows you would genuinely contact. That number is measurable, which is more than can be said for most of what this category publishes.

Found an error on this page, or a document that changes one of these findings? Tell us, and we will correct it and date the correction. That is the only thing that makes a page like this worth anything.

Frequently asked questions

Where does the 40 percent LinkedIn restriction figure come from?

From a single vendor blog post at northlight.ai, captured on 5 September 2026, which states it with no hyperlink, no sample size and no methodology. Every later version we found quotes or paraphrases that page rather than any underlying data. The three republications we traced each added detail the original does not contain: four tool names, then the word analysis, then the word study.

Does LinkedIn publish account restriction statistics for automation tools?

No. LinkedIn's Transparency Center reports fake accounts, spam and scams, content violations, copyright removals and government requests. It publishes no statistics on restrictions of real accounts tied to third-party automation tools, and no per-tool enforcement rates. Checked 5 September 2026.

Did the 2026 LinkedIn Transparency Report show a rise in automated account removals?

That claim conflates two different things. LinkedIn does report fake accounts it removes, which are accounts that should not exist. It does not report restrictions applied to real members who use automation. A change in the first is not evidence about the second.

Has LinkedIn sued any LinkedIn automation tool?

Not on the federal record since mid-2024. A sweep of federal filings through CourtListener returns exactly two cases with LinkedIn as plaintiff in that period, both against data-API companies rather than outreach tools: LinkedIn Corp. v. Nubela Pte. Ltd. and Proxycurl, No. 3:25-cv-00828 in the Northern District of California, filed 24 January 2025, judgment entered 25 July 2025; and LinkedIn Corp. v. ProAPIs Inc., No. 5:25-cv-08393, filed 2 October 2025, with an agreement in principle reported on 9 February 2026 and no judgment entered as of 3 September 2026.

Did LinkedIn send HeyReach a cease-and-desist?

We could not verify it. The claim appears on blogs published by competing vendors and we found no primary source for it, so we record it as unverified rather than as either true or false. LinkedIn does not comment on individual enforcement. The one cease-and-desist against a tool builder we could document comes from the builder's own first-person post on Hacker News dated 5 August 2025.

What does LinkedIn actually say about automation tools?

Its prohibited software policy bans third party software including crawlers, bots, browser plug-ins and browser extensions that scrape, modify the appearance of, or automate activity on LinkedIn's website, and says members risk having their accounts restricted or shut down. It names no tool and gives no statistic. A separate help article adds that if you send an excessive number of invitations and LinkedIn suspects the use of an automation tool, it may suspend or restrict your account.