How to spot fake accounts: four layers of signals and common false positives
Scam accounts impersonating banks or celebrities, clusters of negative reviews, inflated positive reviews and coordinated posting on public issues may all be backed by batches of inauthentic accounts. Financial risk teams, brand PR, e-commerce platforms and the public sector all need to tell the difference: are these accounts participating naturally, mobilizing openly, or running a coordinated operation that conceals their identities or their relationships? This article covers four levels of signals, the ways each level can misidentify real people, the current state of research tools, and how to write a verification record.
Quick answer: how to spot fake accounts
Fake accounts can be identified by cross-checking four levels of signals: account attributes, posting behavior, content similarity and interaction networks. Account attributes cover creation date and naming and profile-photo patterns; posting behavior covers timing, intervals and the share of original posts; content similarity covers near-duplicate text and identical links; and interaction networks show which accounts always reshare, like or appear together. Any single signal can misidentify a real person — a new account, high posting volume or late-night posting cannot serve as evidence on its own. How suspicious a group is depends on whether signals from different levels point to the same accounts, after ruling out natural causes, followed by human verification. These methods find behavioral signs; the signals alone cannot confirm who is behind an account.
Who it is for
- Risk and fraud-prevention teams at financial institutions: spotting accounts impersonating the institution, its executives or celebrities, as well as coordinated posting about individual stocks or financial products
- PR teams in brands and consumer industries: telling coordinated negative reviews and narrative steering apart from genuine customer complaints
- E-commerce and platform operations teams: determining whether review sections contain inflated positive reviews or review-farming accounts
- Public sector and research organizations: observing whether groups of accounts are spreading content in a coordinated way on public issues
What problems it solves
- You see a batch of similarly worded comments and are unsure whether it is coincidence or an operation
- You are unsure which records to keep for suspicious leads so that legal or a platform can re-check them
Personal checks and system detection are two different things
When ordinary users assess a single account, they can look at a few surface signs: whether the profile photo looks like stock imagery, whether the account was just created, whether it has very few followers, and whether its name is a string of digits. When an account messages you recommending investments or claiming to be customer service, these signs can remind you to check official channels before responding.
But these signs are unreliable for judging whether an account is real. A real person who just joined a platform also has a new account, and people who prefer not to show their face may use a landscape as their profile photo. Conversely, a planned operator can age accounts, fill in profiles and mix in everyday posts so that each account looks perfectly normal.
What sets system detection apart is scale and relationships. Manual one-by-one comparison is limited by time and data volume; a system can compare large numbers of accounts at once across timing, content and interactions, surfacing synchronization and duplication that a single account would never reveal — but what it produces is still leads to be verified.
Four signal levels: what to look at, what they catch, and what they may misjudge
Based on public research and platform reports, this article organizes observable cues into four levels: account attributes, posting behavior, content, and interactions between accounts. This is our own editorial framework, not a unified industry standard. The table below summarizes the key points, followed by an explanation of each level.
| Signal level | What to look at | What it catches | Possible misjudgments |
|---|---|---|---|
| Account attributes | Creation date, naming and profile-photo patterns, profile completeness | Groups of accounts created in bulk in the same period with similar naming conventions | Real people who have just joined, and privacy-conscious users who fill in little profile information |
| Posting behavior | Time-of-day distribution, posting intervals, ratio of reshares to original posts | Accounts that post at fixed intervals, only reshare without original content, or keep implausible hours | Organizations using scheduling tools, shift workers, users in other time zones |
| Content similarity | Near-duplicate text, identical links, identical images | Coordinated comments that are copy-pasted or lightly reworded, and traffic funneled to the same URL | Users joining a campaign, discussions citing the same news story |
| Interaction network | Co-resharing, mutual likes, synchronized appearances | Groups of accounts that always act together and boost one another | Natural interaction among fan communities, coworkers or club members |
Level 1: Account attributes
What to look at: Account creation date, patterns in display names and handles, the source of the profile photo, completeness of the bio and profile fields, and any history of name or profile-photo changes.
What it catches: A single account’s attributes can offer leads, while the distribution of attributes across a group adds evidence of links between accounts. For example, a batch of accounts created in the same week, all named with a personal name plus a string of digits and sharing a consistent profile-photo style, is worth digging into. Be careful with profile photos too: they may be AI-generated and look like real photos, so appearance alone cannot tell you whether an account is genuine.
Possible misjudgments: Newly registered real people, and privacy-conscious users who post no photo or fill in little information, may share the same traits. Platforms also expose different fields — some show the join date on the profile page and some do not — so the attributes you can compare vary by platform. Another blind spot is old accounts that were bought or hijacked: they may keep complete profiles, so looking only at creation date and profile completeness may reveal nothing unusual.
Level 2: Posting behavior
What to look at: How posts are distributed across the day, the interval between consecutive posts, the ratio of reshares to original posts, short-term changes in posting volume, and sudden activity after long dormancy.
What it catches: Automated programs may post at fixed intervals or reshare heavily in a short period; manually operated account groups may come online together and go quiet together. If an account barely posts most of the time but posts intensively when a particular issue emerges, then falls silent again afterward, that pattern is worth noting.
Possible misjudgments: Corporate or media accounts that schedule posts at fixed intervals can also show regular posting gaps; shift workers, overseas users and night owls may post late at night; and people in a discussion may post more during major events. Posting behavior can only show that an account keeps unusual hours, not that it is fake.
Level 3: Content similarity
What to look at: Whether posts or comments from different accounts are identical or highly similar, whether they repeatedly post the same URL or image, and whether they share the same typos, punctuation habits or hashtag combinations.
What it catches: Coordinated comments that are copy-pasted or change only a few words, posts that funnel people to the same investment group or shopping URL, and identical negative reviews appearing on multiple fan pages at once. Shared typos or unusual word pairings can serve as leads for verifying whether text came from the same source.
Possible misjudgments: Users joining a campaign may paste the same copy, and people resharing the same news story may attach the same link — both are natural similarity. Generative AI may also weaken this level: every account can produce text that says the same thing in different words, and matching only verbatim duplicates will miss it. Matching can be extended to the narrative level, but sharing a position or narrative is not in itself evidence of inauthentic behavior — real people can hold the same views — and it cannot justify publicly naming accounts. For how narrative matching works, see “Fake news detection methods”, in the section on generative AI.
Level 4: Interaction network
What to look at: Which accounts always reshare the same batch of posts, like and comment on each other, or appear almost simultaneously under the same post, and how these relationships change over time.
What it catches: The core of a coordinated operation is multiple accounts acting together, and the interaction network fills in links that a single account cannot show. A study presented by an Indiana University research team at ICWSM 2021 used behavioral traces shared between accounts — such as retweeting the same posts, identical hashtag sequences, identical images or close posting times — to build coordination networks and identify suspected coordinated account groups across multiple cases. Because such methods look at behavioral links rather than whether content is true, they can in principle also be used to observe operations that selectively amplify accurate information.
Possible misjudgments: Fan communities, coworkers or club members may also like each other’s posts and reshare together, and such interactions alone do not prove inauthentic activity. Once you see an account group, you still need to determine whether it is open, organized mobilization or an operation that conceals its members’ relationships. Under the current version of Meta’s Community Standards (last updated December 2025), inauthentic behavior is deception carried out through inauthentic assets — such as accounts, Pages or Groups — controlled by the same person or group, intended to mislead the platform or users, or to evade enforcement of the Community Standards. The key test is concealment and deception, not a group of people sharing the same opinion. For the full definition of coordinated inauthentic behavior, see “What is coordinated inauthentic behavior” and “Meta’s original Inauthentic Behavior policy”.
Why “new account,” “posts a lot” and “posts late at night” can’t serve as evidence on their own
Relying on these three signs alone to label accounts as a troll farm (網軍) can misidentify real people.
New accounts: real people also sign up to join a particular debate. A sudden rise in new accounts may mean someone is creating them in bulk, or simply that the topic is drawing in new users. You need to check whether these accounts are linked in other ways.
High posting volume: people passionate about current affairs, social media managers, journalists and opinion leaders may all post heavily. Volume only reflects how active an account is. What matters is whether changes in it move in sync with other accounts, and whether the content is heavily duplicated.
Late-night posting: late night locally may be daytime in another time zone, and overseas users, shift workers and students can all be active late at night. Whether a schedule is abnormal should be judged against the same account's past activity and against other accounts on the same topic.
Conversely, a single normal-looking signal does not mean an account is genuine; a planned operation can make each account look normal at any single level. A more robust approach is to cross-check signals across levels: when a group of accounts was created in the same week, leaves comments in similar wording and always reshares together, signals from three levels point to the same group, and that group deserves priority verification. Also watch whether these signals are just repeated expressions of one phenomenon — for example, a single public event driving sign-ups, comments and reshares at the same time — so you do not double-count how suspicious it is. Clear impersonation cues, such as an account misusing an organization’s name and logo, are worth verifying even when only one signal is present.
Public research tools and their limits
Among public research tools, Botometer, developed by Indiana University’s Observatory on Social Media (OSoMe), is one example. It used to estimate in real time how likely a Twitter account was to be run by software, and it was adopted by many academic studies. Its current state illustrates two limits.
The first limit is data access. After Twitter (now X) stopped offering researchers free data access, the original Botometer website was shut down. In February 2024 OSoMe launched Botometer X, which only offers scores precomputed from historical data collected before June 2023; accounts created after 31 May 2023 cannot be looked up, and accounts created earlier do not necessarily have a record either. OSoMe later also opened batch queries of these historical scores via an API. OSoMe also explains that the Botometer X model was trained before generative AI tools became widespread and cannot identify AI-enhanced bots. In other words, Botometer X is an archival tool and cannot assess the current state of X accounts. OSoMe also launched Botometer Blue, which analyzes Bluesky accounts using data from the Bluesky API and assesses whether recent posts look AI-generated. Neither covers other platforms.
The second limit is that accuracy varies with language and over time. A 2020 study by Rauchfleisch and Kaiser in PLOS ONE tested the then-current Botometer v3 between March and June 2019 on English and German accounts known to be bots and known to be human. It found that the scores were imprecise for estimating bots, more so on the German data tested, and that the same threshold produced different results at different times, with both false positives and false negatives. The researchers cautioned that counting bots with a fixed threshold can classify real people as bots and also miss bots. The study tested an older version of the tool, so its results cannot be taken as directly representing how the current Botometer X or Botometer Blue performs; the threshold instability it identified is, however, a useful caution when using any score-based tool.
The study only tested English and German, so its findings cannot be directly extended to Chinese. When applied to platforms such as PTT, Dcard and LINE groups, any method needs separate validation on local data. In his 2020 review of a decade of social bot detection research, Cresci also noted that bots mimic humans and that detection and evasion techniques keep adapting to each other, so tools need continual updating and validation.
Generative AI is also changing things. In its Q1 2024 Adversarial Threat Report, Meta documented removed influence operations using GAN-generated profile photos, as well as images and comments likely produced with generative AI. As of that report, Meta said it had not yet seen novel generative AI tactics that would impede its ability to disrupt the related account networks. This was one platform’s observation at the time and cannot be treated as a guarantee for every platform.
From a suspicious account group to a verification record
If suspicious leads are going to legal, a platform or a regulator, the record must let someone who was not part of the analysis re-check it. We recommend keeping the following.
- Original content: URLs, screenshots and capture times for posts and comments, plus the public information on account pages. Accounts may be deleted or renamed, so preserve these as early as possible.
- Observed signals: the concrete facts for each signal level — for example, which accounts were created on which day and which comments are identical — rather than simply writing “suspected troll farm.”
- Alternative explanations: list natural causes that could produce the same pattern, such as concurrent news, marketing campaigns or fan mobilization, and the reasons each was ruled out or could not be ruled out.
- Assessment level and limits: state whether the judgment is highly suspicious, under observation or possibly natural, and which data you could not see, such as private groups or deleted content.
- Actions and follow-up: when reports were filed with the platform and their outcomes, any public statements, and whether monitoring continues.
The record should avoid drawing conclusions about the people behind the accounts. Behavioral analysis can show that a group of accounts behaves in a highly coordinated way, but behavioral signals are not enough to confirm who is operating them or on whose behalf; identity and commissioning relationships need separate verification, and where legal liability is involved, they are handled by the competent authorities through due process. Writing “what coordination signs this group of accounts shows” stays closer to what the behavioral evidence can support than writing “this is so-and-so’s troll farm.”
References
- Meta Transparency Center: Inauthentic Behavior
- OSoMe: Introducing Botometer X (2024)
- Botometer: About and FAQ
- Rauchfleisch & Kaiser, The False Positive Problem of Automatic Bot Detection in Social Science Research, PLOS ONE (2020)
- Pacheco et al., Uncovering Coordinated Networks on Social Media: Methods and Case Studies, ICWSM (2021)
- Cresci, A Decade of Social Bot Detection, Communications of the ACM (2020)
- Meta Adversarial Threat Reports
Further Reading
- What is coordinated inauthentic behavior? Troll farms, paid posters and bots explained
- How can financial institutions monitor impersonation and scam accounts?
- What should a brand do when hit by a narrative-steering attack?
- How does AI detect fake news? Five methods and their limits
- Fake News Detection and Cognitive Warfare Monitoring System
FAQ
Ask about product capabilities and limits
To learn about InfoMiner's suspicious-lead analysis capabilities, data availability and limits, and the human verification effort involved, contact the LargitData team.
Contact Us Learn about anomalous account detection