"The reaction coming out of this breach is ... change your password on any sites where you've used the same password," deSouza said.
LinkedIn, based in California, said last week that 6.5 million user passwords were posted on a hacker site and the United States Federal Bureau of Investigation was working with the company on the security breach.
LinkedIn said that it hadn't received any verified reports of unauthorised access to member accounts. The company also said it disabled any passwords it found were potentially compromised.
Customers of CBS's Last.fm music site and EHarmony's dating site also had passwords stolen last week. Both companies suggested that users change their passwords immediately.
One way criminals have taken advantage of job sites such as LinkedIn is by creating fake accounts and linking them to hacked accounts.
Then they wait. The connection lets the perpetrator monitor the breached accounts for news that someone is changing jobs. Once that happens, the hacker might send an email pretending to be a new colleague or someone from human resources. If the unsuspecting user clicks on a malicious link in the message, the hacker can take control of the victim's computer.
LinkedIn said on its blog that many of the stolen passwords posted on a hacker site were "hashed", or encoded to be unreadable by outsiders. Still, some were decoded and published, the company said.
- Bloomberg