In late March 2026, LinkedIn moved against HeyReach, one of the most widely used cloud automation platforms for outbound sales. LinkedIn removed the vendor’s company page and its founders’ profiles, and within weeks HeyReach cut its LinkedIn functionality and repositioned around email.
The tool had a reported user base in the tens of thousands, and many of those teams watched their LinkedIn sequences go quiet.
The action did not happen in isolation. A first-quarter analysis by Northlight estimated that close to 40% of accounts running non-compliant automation tools, including HeyReach, Expandi, Dripify, and Waalaxy, picked up some form of restriction between January and March.
For a sales team, a single restriction can take offline the exact account the pipeline depends on.
Most of the panic has focused on the wrong number. LinkedIn’s weekly limit of roughly 100 connection requests has been the working ceiling since 2022, and it is not the reason enforcement reached the headlines this year.
The change is in how LinkedIn now decides which accounts to act against, and that shift quietly rewards teams that already run outbound with discipline.
What actually happened in early 2026
The HeyReach case is the clearest marker of the shift, because the enforcement landed on the vendor rather than on individual users.
The HeyReach action and the email pivot
Reporting from across the outbound tooling space agrees on the outline of events. LinkedIn took action against HeyReach at the company level in March 2026, and the product moved away from LinkedIn automation soon after. The accounts differ on the mechanics.
Some describe a cease-and-desist that ended LinkedIn functionality for users, while LinkedCamp reports that LinkedIn removed HeyReach’s public company page and founder profiles without disabling the software itself.
Neither LinkedIn nor HeyReach has published a detailed public breakdown, so the safest read is that this was vendor-level enforcement rather than a mass suspension of end users.
The wider enforcement pattern
The vendor takedown sat on top of a broader tightening. According to Northlight, the restriction rate for accounts on flagged tools sat near 40% in the first quarter, and it named the same cloud and browser-extension platforms that dominate the category.
As LinkedCamp notes, industry observers expect further vendor-level actions through the middle of 2026 rather than a one-time event.
The pattern points to enforcement that is continuous and infrastructure-aware, not a single ban wave that passes and leaves the old playbook intact.
Enforcement in 2026 landed on the vendor, then rippled down to the accounts running on it.
Why this should worry every outbound team
If your pipeline runs through LinkedIn, the question is whether your activity looks like a person.
The account you lose is the channel your pipeline runs on
For most B2B sales teams, the LinkedIn account is not a growth experiment. It is the identity that holds the network, the conversation history, and the social proof that makes outreach work at all.
A restriction on that account does not slow a campaign. It removes the channel and everything built inside it.
That is why the HeyReach episode registered as more than tooling news. Teams that had wired their entire motion through a single cloud platform discovered how much operational risk sat in one dependency.
“We stayed under the limit” is no longer a defense
A recurring theme in 2026 guidance is that accounts can be flagged even while operating inside the numeric caps.
LinkedIn’s systems score behavior, so bulk activity clustered at identical times, low acceptance rates, and sessions that originate from data centers can all trigger a review regardless of daily counts.
Staying under 100 invitations a week is table stakes, and it does nothing on its own to make an account look human.
What changed under the hood, and it is not the cap
The connection cap is a convenient scapegoat because it is a visible number. The mechanism that actually decides account fate is less visible and more important.
Session origin and behavioral detection
LinkedIn’s defenses evaluate where an action comes from and whether it resembles genuine human use.
When many client accounts run from the same IP address, the shared infrastructure reads as an automation service, and a flag on one account can degrade the reputation of others on that IP.
Also, cloud sessions and browser extensions that inject scripts into the page produce signals that do not match a logged-in person, which is the profile that draws enforcement. Volume matters, but origin and timing patterns matter more.
The connection cap in context
The weekly ceiling of about 100 invitations has been the observed norm since roughly 2022, and it applies across free, Premium, and Sales Navigator tiers.
LinkedIn does not publish the figure as a fixed rule, and the effective limit shifts with account age, acceptance rate, and overall standing.
Treating that number as the whole story is what leaves teams exposed, because it says nothing about the behavioral signals that trigger most restrictions.
The cap tells you how many invites you can send. It says nothing about whether LinkedIn believes a human sent them.
What LinkedIn’s policies actually prohibit
For a sales leader deciding how to run outbound, the policy language and the case law both matter, because they set the boundary that enforcement operates inside.
The rules in plain language
LinkedIn’s User Agreement, in Section 8.2, prohibits using bots or other automated methods to access the service, add or download contacts, or send and redirect messages.
A separate Help Center policy on prohibited software states that LinkedIn does not permit third-party crawlers, bots, browser plug-ins, or extensions that scrape, modify, or automate activity on the site, and it warns that members using such tools risk having accounts restricted or shut down.
Why the policy holds up
The enforceability question was settled in the long-running hiQ Labs dispute.
According to the Ninth Circuit’s 2022 ruling, scraping publicly available data does not, on its own, violate the federal Computer Fraud and Abuse Act. LinkedIn still prevailed, because a district court held in November 2022 that user-agreement provisions barring scraping and fake profiles are enforceable as a matter of contract.
As the law firm Morgan Lewis summarized, the case ended in a consent judgment with a $500,000 award against hiQ, a permanent injunction, and the company shutting down.
The scale LinkedIn is defending against
The aggressive posture makes more sense against LinkedIn’s own numbers. LinkedIn’s Community Report states that 99.7% of the fake accounts it removed in a recent period were caught proactively, before any member reported them, and its transparency reporting puts fake-account removals at roughly 86 million in the first half of 2024.
When a platform is filtering fake accounts at that scale, anything that behaves like automated, non-human activity sits squarely in the blast radius.
How to build outbound that survives the crackdown
The takeaway is not to abandon outbound. It is to run it in a way that leaves a human-shaped footprint and does not concentrate risk in one place.
Spread the load across channels
Maxing out a single LinkedIn account is the pattern most exposed to a restriction. Distributing outreach across LinkedIn, email, and other touchpoints lowers the volume any one channel has to carry and keeps a lead from going cold when one channel throttles.
A multichannel motion also mirrors how buyers actually move between inboxes and feeds.
Volume discipline over raw send count
Acceptance rate is the signal that protects an account, so quality of targeting beats quantity of sends.
A short, disciplined checklist for staying inside safe behavior:
- Keep new accounts well below the ceiling and ramp gradually rather than starting at full volume.
- Spread activity through the day instead of firing every invitation in one burst.
- Withdraw stale pending invitations so the pending ratio stays healthy.
- Prioritize personalized, relevant requests to keep acceptance rates high.
- Watch for warning notices and pause immediately when one appears.
Human-in-the-loop steering
The most durable setups keep a person in control of judgment while software handles repetitive work, rather than handing the whole motion to an unattended agent. That means reviewing targeting, approving messaging, and monitoring account health, so the activity pattern stays consistent with a real operator.
Human oversight is exactly the profile LinkedIn’s behavioral detection is least likely to flag.
Want to see what human-steered outbound looks like in practice? Book a demo.
Mistakes that get accounts flagged in 2026
Most restrictions trace back to a handful of avoidable patterns. Steer clear of these:
- Running high volume through shared-IP cloud tools that read as automation infrastructure.
- Using browser extensions that inject scripts into LinkedIn pages.
- Sending at identical times every day, which reads as scripted behavior.
- Letting acceptance rates stay low while pushing near the weekly cap.
- Skipping the warm-up ramp on a new or reactivated account.
- Treating a numeric limit as proof of safety while ignoring behavioral signals.
Where to take your outbound next
The 2026 crackdown did not close the door on outbound. It raised the cost of doing it carelessly and rewarded teams that operate like the humans they represent.
The safer path forward runs across multiple channels, stays inside both the letter and the spirit of LinkedIn’s rules, and keeps a person steering the parts that require judgment.
AnyBiz is built for that model. It runs multichannel outbound from one place, with human oversight where it matters, so your pipeline keeps moving while brute-force tools keep drawing enforcement.
See how AnyBiz runs a compliant, multichannel outbound that keeps sending while high-risk tools get flagged. Book a demo today!
Analysts already expect the next vendor-level action in the middle of 2026. Moving your pipeline onto infrastructure built to outlast the next wave is easier to do now than after the account you rely on goes dark.
FAQ
Is LinkedIn automation against the rules in 2026?
LinkedIn’s User Agreement (Section 8.2) prohibits bots and other automated methods for accessing the platform, adding contacts, or sending messages, and a separate Help Center policy bars third-party tools that scrape or automate activity. I
t is not a criminal matter on its own, but the hiQ Labs case confirmed that these terms are enforceable as a contract, so routing around them carries real exposure beyond an account restriction.
What is the LinkedIn weekly connection request limit in 2026?
The working ceiling is roughly 100 invitations per week, and it applies across free, Premium, and Sales Navigator accounts. LinkedIn does not publish the number as a fixed rule, and the effective limit shifts with account age, acceptance rate, and overall standing.
It has been the observed norm since around 2022, so it is not the change that drove enforcement this year.
Did LinkedIn ban HeyReach?
LinkedIn took action against HeyReach at the company level in March 2026, and the product moved away from LinkedIn automation soon after. Industry reports differ on the mechanics, with some describing a cease-and-desist that ended functionality and others describing the removal of HeyReach’s company page and founder profiles.
Neither company published a detailed breakdown, so the accurate read is vendor-level enforcement rather than a mass suspension of individual users.
Why did my LinkedIn account get restricted if I stayed under the limit?
LinkedIn scores behavior, not just volume, so an account can be flagged while operating inside the caps. Activity clustered at identical times, low acceptance rates, and sessions that originate from data centers or shared IPs all read as non-human.
Staying under 100 invitations a week is a baseline that does nothing on its own to make the activity look like a real person.
How can I run LinkedIn outreach safely in 2026?
Spread outreach across channels rather than maxing out one account, ramp new accounts gradually, and prioritize personalized requests to keep acceptance rates high.
Avoid shared-IP cloud tools and browser extensions that inject scripts, since those produce the signals enforcement targets.
Keeping a person in control of targeting and messaging, with software handling the repetitive work, is the profile least likely to be flagged.
