The Lead Gold Rush Is Selling Shovels
You'll have seen the ads — on Instagram between the holiday photos, in your feed under a stranger's confident smile. Paste in your website address and the tool does the rest: it reads your site, writes hundreds of SEO articles a day, and sweeps LinkedIn for thousands of ready-to-buy prospects while you sleep. Every gold rush produces this figure, and it was never the prospector. The dependable money was always in selling shovels to the hopeful.
We build marketing software, so these ads are aimed at the people we serve, and we get asked about them: is this real, is it allowed, and why does our own tool keep declining to do things theirs apparently do all day? Those are three different questions with one underlying answer — the rules being trampled here were never unclear, and when they bite, they bite the customer rather than the toolmaker.
The rules were never blurry
Take the LinkedIn sweep first. LinkedIn's user agreement bans automated collection outright — no bots, no scrapers, no "any other means" of harvesting profile data — and the official developer APIs, the ones tools like ours are built on, offer no endpoint that returns a thousand strangers as prospects. A tool promising that harvest has left the sanctioned road before it starts, and the platform's terms say so in plain words rather than small print.
The best-known court fight over this ran for years. A company called hiQ Labs scraped public LinkedIn profiles at scale, and American courts did decide that reading a public page is not criminal hacking. hiQ still lost — on the contract, in 2022 — and the litigation finished the company. So the accurate summary is not that scraping is a crime; it's that scraping breaks a promise every account holder made, the platform wins those fights, and any tool built on it lives one enforcement wave from disappearing.
In the UK and Europe there's a second layer with real teeth. A scraped profile is personal data about a named person, and data-protection law applies to it however publicly it was posted — regulators, including the ICO, have said in terms that "it was public" is not a lawful basis for harvesting people into a marketing database. Tools aimed at the American market tend to ignore this entirely. Their British customers don't get to.
How a thousand-lead sweep really works
Since no official door exists, the tools use one of three unofficial ones. Some run fleets of rented or disposable LinkedIn accounts, driven by browser automation dressed up to look like a person clicking. Some connect to your own LinkedIn login and drive it for you, which puts your account — the one holding your customers and your history — on the line for every automated action taken in your name. And some never touch LinkedIn live at all: they resell databases scraped months or years earlier, freshened with a search box and marketed as a sweep.
Notice where the risk sits in each version. The restricted account is yours or a burner you paid for; the burnt sending domain is yours; the name on the unwanted email, and on the complaint it generates, is yours. The toolmaker's exposure rounds to a cancelled subscription. Shovel-sellers came out of every gold rush on record ahead of the diggers, and this is the mechanism.
Hundreds of articles a day, meet Google's spam team
The other half of the pitch — paste in a URL, receive a torrent of SEO articles — collides with a different rulebook. Google's spam policies name the practice: scaled content abuse, meaning pages mass-produced to manipulate rankings rather than to help a reader, whoever or whatever wrote them. Since the March 2024 update, Google has removed entire sites from its results under that policy, including sites that had been earning real traffic until the volume switch was flipped.
Volume itself is not the offence; publishing faster than anyone could be checking usefulness is. A hundred pieces a day means nobody read them before your name went on them, and both the ranking systems and the people who land on the pages can tell. If you want the version of content that survives contact with a search engine, our guide on How to Rank Higher on Google, Without the Snake Oil lays it out.
The invented crowd
Then there's the strangest exhibit in the case: advertising fronted by AI-generated "customers" — synthetic faces delivering scripted testimonials for products no one in the video has used, because no one in the video exists. Whatever you make of it aesthetically, the law has already dealt with it. In the UK, fake reviews are banned under the Digital Markets, Competition and Consumers Act, with the CMA enforcing since April 2025; in the US, the FTC finalised a rule in August 2024 covering fake and AI-generated testimonials by name. A model posing as a happy customer is a fake review however it was manufactured, and both regulators have said so.
Why there's an unsubscribe link on a business email
Against all this, the unsubscribe link at the bottom of a plain business email can look like bureaucratic fuss — one firm writing to another, so who is being protected? The rules are more sensible than they first appear. UK law does treat email to a limited company differently from email to a named individual: the strict consent requirement exists to protect individuals, sole traders and partnerships rather than corporate inboxes. But every route, corporate or not, requires the sender to say plainly who they are and to give the recipient a working way out — and the person reading a company inbox is still a person, whose details are still personal data.
There's also a plainer reason to keep the link. Spam filters and recipients alike read a missing opt-out as the signature of a sender with something to hide, because it usually is. The link costs you a click from someone who was never going to buy; leaving it off costs you deliverability today and a far more awkward conversation if a complaint ever reaches the regulator. Our own campaign emails carry a one-click opt-out and a postal address on every send, and a suppressed address stays suppressed.
The version still standing when the dust settles
None of this argues against using software for marketing — we'd be in the wrong trade. It argues for a distinction the gold-rush ads work hard to erase: between automating the labour and automating away the rules. The durable version of this work runs on official APIs and accounts you actually own, finds prospects on the open web where businesses publish themselves, keeps a human on the final call about who gets contacted, and treats an opt-out as permanent. That version cannot promise you a thousand leads before breakfast. It can promise that everything sent under your name would survive being read aloud to the person it reached — and it will still be operating, accounts intact and domain unburnt, after the sweep-sellers have rebranded twice.
If you're weighing tools in this territory, our guides on Cold Email Marketing: The Honest Guide for Small Businesses, Outreach Software: What to Actually Look For and The AI Outreach Tool Built Around Judgement, Not Just Automation set out what the properly-built version looks like from the inside. And the usual caveat applies to everything above: we're a software company describing rules we operate under, not a law firm advising on your case.
Common questions
Is scraping LinkedIn for leads illegal?
It violates LinkedIn's user agreement, which prohibits automated data collection in plain terms, so at minimum it's a breach of contract that can cost every account involved. In the best-known case, courts found that scraping public pages wasn't criminal hacking, but the scraper still lost on the contract in 2022 and was wound down. In the UK and EU there's a further layer: scraped profiles are personal data, and using them for marketing without a lawful basis engages data-protection law no matter how public the profile was.
Why does a business email need an unsubscribe link?
UK rules require every marketing email to identify the sender and offer a valid way to opt out, whoever it's addressed to; the stricter consent rule additionally protects individuals, sole traders and partnerships. Beyond the law, a missing opt-out reads as a red flag to spam filters and recipients alike. The link costs almost nothing to include, and honouring it is what keeps a sending domain trusted.
Are the "thousands of leads in one sweep" tools illegal to use?
For a customer the risk is usually contractual and regulatory rather than criminal — restricted accounts, burnt sending domains, and responsibility under data-protection law for whatever scraped personal data you go on to use, since that responsibility follows the person using the data, not only whoever collected it. The tool's name appears nowhere on that list, which is worth noticing before paying for one.
Does Google penalise AI-written articles published at scale?
Google's spam policies target scaled content abuse — mass-produced pages designed to manipulate rankings, whoever or whatever wrote them — and it has removed whole sites from its results under that policy since the March 2024 update. The offence is publishing faster than usefulness can be checked, not the use of AI as such; a smaller number of pieces someone stands behind remains both safe and effective.
Are AI-generated testimonials legal?
In the UK, fake reviews are banned under the Digital Markets, Competition and Consumers Act, enforced by the CMA since April 2025; in the US, the FTC finalised a rule in August 2024 that covers fake and AI-generated testimonials explicitly. A synthetic person presented as a real customer is a fake review in both regimes, however it was made.
If you'd rather build something that lasts
Prospecting with judgement, and a paper trail you'd show anyone
Paul researches markets from the open web, reads each business before it reaches your list, tells you straight which ones deserve your own words, and leaves the final call with you. Sends go out paced, from your own verified domain, with an opt-out on every campaign email. No scraped accounts, no rented identities, nothing you'd need to explain later.
Open the app →