Last updated:

What is coordinated inauthentic behavior? Troll farms, paid posters and bots explained

A wave of uniformly worded comments appears on social media. Some call it a troll farm, others say paid posters, and others say it is just bots. For brands, financial institutions and government agencies, not being able to tell these terms apart makes it hard to decide whether to respond and what to report to the platform. This article starts from the platform term coordinated inauthentic behavior (CIB) and explains its two core features, the differences between six account types, what the Chinese colloquial terms mean, and how Meta, X, YouTube and TikTok each regulate it.

Infographic for Coordinated Inauthentic Behavior: Bots, Sockpuppets, Troll Farms, illustrating key concepts from AI Knowledge Hub

Quick answer: what is coordinated inauthentic behavior

Coordinated inauthentic behavior (CIB) is a policy term coined by Meta. Broadly, it describes multiple accounts that conceal their true identities or relationships and work together to mislead others. Meta's current definition is narrower, limited to particularly sophisticated inauthentic behavior in which fake identities are central to the operation and adversarial techniques are used to evade detection or appear authentic. The key to understanding it is concealment and coordination, not whether the content is true: Meta's Community Standards state that this enforcement is independent of content or ideology, so a network of accounts telling the truth can still constitute CIB. Conversely, X's policy explicitly permits collective voices that do not deceive others or break platform rules. Troll farms, paid posters and bots may be part of CIB, but none of them is the same thing as CIB.

Who this is for

  • Brand and PR teams: telling genuine customer complaints from coordinated negative reviews
  • Financial institution risk teams: spotting impersonation accounts and traffic-diversion accounts that appear in clusters
  • E-commerce and platform operators: understanding the account patterns behind fake reviews and review manipulation
  • Government agencies and researchers: using terms such as CIB, troll farm and paid posters correctly

What problems it solves

  • You are not sure what "troll farm", "paid posters", "bots" and "sockpuppets" each mean
  • You want to know when coordinated posting actually breaks platform rules
  • You are not sure which policy to cite when reporting to a platform

The definition of CIB and its two core features

The term "coordinated inauthentic behavior" comes from Meta (then Facebook). Meta was already using it in a public announcement no later than July 31, 2018, explaining that it does not allow people or organizations to create networks of accounts that mislead others about who they are and what they are doing. On December 6 of the same year, Meta's head of cybersecurity policy released a video explaining the term in detail.

Broken down, it has two core features: coordination and inauthenticity. Both need to be present before CIB is worth suspecting, and whether something constitutes CIB under a platform's policy depends on meeting that platform's full definition.

The first feature is coordination. Multiple accounts or pages are controlled by the same person or group, or act according to a shared plan, for example posting similar content at similar times or sharing and liking each other's posts. Coordination by itself is not a violation: a social media manager running several brand accounts, or fans rallying to comment together, are both forms of coordination.

The second feature is inauthenticity, in other words concealment. Accounts mislead others about their identity, their relationships with one another or their purpose, for example by using fake identities, making accounts controlled by one person look like strangers, or hiding who is funding them. Concealment without coordination cannot be treated as CIB, and any other violations need to be verified separately. Genuine coordination that does not deceive anyone and complies with platform rules should not be treated as inauthentic behavior simply because people speak up together. Posting under a real name also does not mean nothing is concealed: funding or organizational ties may still be undisclosed.

Meta has revised its definition, and the bar is higher than the features above. According to its 2020 CIB report, CIB is coordinated efforts to manipulate public debate for a strategic goal, where fake accounts are central to the operation. Meta's current Community Standards (accessed October 2026) define it as particularly sophisticated inauthentic behavior in which fake identities are central to the operation and the operators use adversarial techniques to evade detection or pose as authentic accounts; where the operators and the target audience are in different countries, it is classified separately as foreign interference. The standards also state that this enforcement is independent of content or ideology. In other words, concealment and coordination are only clues, not sufficient conditions for a platform finding.

"Independent of content" also cuts the other way: however extreme the content, if the accounts are genuine and conceal nothing, it is not CIB, and it is handled under other rules such as those on hate speech or disinformation. CIB should therefore not be treated as a synonym for spreading fake news.

Six account types compared

CIB describes an entire network of behavior, and the accounts in that network may be any of the types below, or a mix of them. The table summarizes what each type is, its observable features, what it might be mistaken for, and how it relates to CIB. The features in the table are only clues: no single feature is enough to conclude that an account is inauthentic or that CIB is taking place, and each must be cross-checked against other evidence.

Account type What it is Observable features Situations that do not imply harm
Bot An account that posts or interacts automatically through software Regular posting times, round-the-clock activity, fixed content formats Clearly labeled automated accounts for news alerts, weather or earthquake notifications
Cyborg account A human operator using automation tools, or an automated account that a human steps into from time to time Scheduled automatic posts interspersed with human replies Ordinary creators or social media managers using scheduling tools
Sockpuppet Another account controlled by the same person; whether it amounts to manipulation depends on whether it is used to deceive others or to echo other accounts and inflate volume Several accounts echo one another in the same thread and share similar phrasing habits Openly run work and personal accounts, or different users in the same household or office
Hijacked or purchased account An originally genuine account that has been hijacked or resold and is now operated by someone else When the name, profile picture or posting content suddenly changes, check whether the original user made the change; the change alone does not prove the account has changed hands A real person who has changed interests or revived an old account
Covert paid posters (水軍) People paid to post, comment or leave reviews on someone's behalf who do not disclose the arrangement and pose as independent voices Concentrated reviews of the same product or topic within a short period, with no disclosure of a paid relationship Sponsored content or endorsements with the partnership disclosed, spontaneous fans, or customers who genuinely recommend a product
Organized account groups (網軍, troll farms) A group of accounts dividing up work toward a shared goal, possibly mixing any of the types above Multiple accounts appearing in sync, telling a consistent narrative and amplifying one another Synchronized reactions that arise naturally to the same news event

A few of these types need more explanation. Automation in itself does not mean harm: research by Chu et al. at ACSAC 2010 distinguished legitimate bots that post news and status updates from bots that spread spam or malicious content, and used "cyborg" to describe bot-assisted humans or human-assisted bots. Whether an automated account is a problem still depends on its content, behavior and the platform's rules.

In everyday use, a sockpuppet is an alternate account used to pretend to be a different person, but the research definition is broader. Kumar et al., analyzing nine discussion communities at WWW 2017, counted all multiple accounts controlled by the same person as sockpuppets. They found that pairs of accounts controlled by the same person were more likely than pairs of ordinary users to appear in the same discussion at the same time. The study also noted that these accounts do not necessarily pretend to be different people, nor are they all malicious. Running several accounts is therefore not manipulation in itself; what matters is whether they are used to mislead others.

A purchased account may keep its original creation date and posting history after changing hands, so account age or past posts alone cannot confirm who is operating it now. X's authenticity policy explicitly prohibits buying, selling or transferring accounts.

Chinese colloquial terms: troll farms (網軍), paid posters (水軍) and side-wing accounts (側翼) are not the same as CIB

These colloquial Chinese terms are everyday vocabulary with no unified definition from platforms or regulators, and their boundaries are fuzzier than CIB. The following explains only what the words mean and is not used to refer to any specific party.

Paid posters (水軍, literally “water army”): a term from the Chinese-language internet for writers who are paid to post, comment or leave reviews on someone’s behalf without disclosing that relationship. A 2011 study by Chen et al. called them the “Internet water army,” describing them as writers hired to post in online communities with hidden purposes, such as shaping others’ views of social events or commercial markets. The defining features are payment and non-disclosure; sponsored content that discloses the partnership does not fall into this category. In commercial settings, inflated positive reviews, review bombing and review manipulation may be carried out by such writers, or by automated programs or other manipulation methods.

Troll farm (網軍, literally “internet army”): Chinese-language media use this word for two different things — groups engaged in hacking and cyberattacks, and organized groups of accounts that post online to steer the narrative. When reading a report, first check which one is meant. The two usages call for different analysis: the former leans toward cybersecurity, while the latter is closer to discussions of CIB. Both can also appear in the same operation, for example when hijacked accounts are then used for coordinated posting, and each needs to be verified separately. Even in the latter case, if the accounts do not conceal their identities or relationships, it does not constitute CIB.

Loosely affiliated supporter accounts (側翼, literally “flanks”): the dictionary meaning is the two wings of an army, and in political discussion the word is borrowed as an informal label that lets the speaker convey their belief that certain fan pages or communities support a particular political position. The label itself proves no organizational identity, chain of command or inauthentic behavior; whether accounts are directed by someone or conceal their relationships cannot be inferred from their stance and requires behavioral evidence.

Applying these labels to specific accounts may lead readers to infer a commissioned, organized or hidden relationship behind them, but synchronized posting or shared positions alone cannot confirm such relationships. Staff must check further evidence and, where necessary, obtain platform data or leave it to competent authorities to investigate. Confirm the evidence before using these labels publicly. A safer approach is to describe the observed behavior — for example, “a batch of accounts published similar content within ten minutes” — rather than attaching a label.

How platforms handle it: differences in terminology across Meta, X, YouTube and TikTok

Every platform deals with coordination and fake accounts, but their terminology and categories differ. When filing reports or writing up findings, citing the platform’s own policy names makes communication easier. The following is based on current policy pages consulted in October 2026.

Platform Main terms and policies Key points Points to note
Meta (Facebook, Instagram, Threads) The Inauthentic Behavior section of the Community Standards, subdivided into coordinated inauthentic behavior and foreign interference Especially sophisticated inauthentic behavior: fake identities are central to the operation, and adversarial techniques are used to evade detection or appear authentic States explicitly that enforcement is independent of content or ideology
X Authenticity policy (April 2025 version), covering multiple accounts and coordination, fake identities, impersonation, engagement inflation and more Prohibits coordinated inauthentic activity that artificially influences conversations, such as using multiple accounts to inflate the same content or posting identical content across accounts; content localized into other languages is exempt Explicitly allows genuine coordination to express support or opposition in non-violating ways, and allows running multiple accounts for distinct, non-overlapping purposes within account limits
YouTube The spam policy, fake engagement policy and impersonation policy in the Community Guidelines Prohibits deliberately inflating view and engagement metrics through automated systems and similar means; prohibits impersonating others to mislead viewers, and fan channels must make this clear in their name or handle Google discloses the coordinated influence operations it has terminated on its platforms in quarterly bulletins
TikTok Deceptive behavior and fake engagement rules in the Community Guidelines (version effective 24 September 2026), covering covert influence operations, impersonation, spam and fake reviews Networks of accounts that coordinate to mislead people or the platform’s systems in an attempt to strategically influence public discussion, such as elections or social issues Allows multiple accounts, but they may not be used to deceive others or evade the rules

There are two differences. First, among the four platforms, Meta uses CIB as a formal policy name; X uses "coordinated inauthentic activity" in its multiple-accounts-and-coordination section, TikTok uses "covert influence operations", and YouTube spreads the behavior across policies on fake engagement, impersonation and spam. Second, the thresholds differ from section to section: Meta's CIB requires fake identities to be central to the operation, and cases that fall short of that threshold may instead be handled under its general inauthentic behavior rules, while X's multiple-accounts-and-coordination section directly covers simpler cases such as multiple accounts inflating the same content.

As a result, the same set of accounts may fall under different rules on different platforms. When reporting, rather than accusing someone of being a troll farm, describe the behavior in the terms of the policy: for example, misuse of a brand name and trademark, multiple accounts posting substantially identical content, or buying and selling accounts. Attach the links and screenshots you have preserved.

CIB is a platform enforcement term that looks at account behavior. Cognitive warfare, information manipulation and foreign information manipulation and interference (FIMI) are analytical frameworks that look at the intent, methods and impact of an operation. An information manipulation campaign may use a CIB network to amplify its message, but it may also rely solely on public accounts, media outlets or genuine people sharing content, with no CIB involved at all. For how organizations can monitor and respond to these operations, see Fake News Detection and Cognitive Warfare Monitoring System; for the origins of each term and how they compare, see What is cognitive warfare? How it differs from fake news, information manipulation and FIMI.

CIB is not limited to public affairs. Businesses encounter similar account behavior in other settings: accounts impersonating banks, celebrities or customer service that lure people into fake investment groups; a batch of accounts leaving similar negative reviews of a brand within the same time window; and undisclosed paid reviews inflating ratings on e-commerce pages. These situations do not necessarily meet a platform's definition of CIB, but the way to assess them is the same: first ask whether something is being concealed, then whether the accounts are coordinated.

Keep in mind that account-level signs can only indicate suspicion; they cannot prove identity or intent. Whether a real person is behind an account, and who is operating it, must be established by people checking further evidence, obtaining platform data where necessary; whether anything is illegal is for the competent authorities to determine. For how to identify suspicious accounts from account attributes, posting behavior, content similarity and interaction networks, and where each layer of signals tends to produce false positives, see How to spot fake accounts: four layers of signals and common false positives.

FAQ

Fake news is about whether content is true; coordinated inauthentic behavior is about how accounts behave. Meta's current definition is limited to particularly sophisticated inauthentic behavior in which fake identities are central to the operation and adversarial techniques are used to evade detection or appear authentic. Meta states that this enforcement is independent of content or ideology, so a network spreading true information can still constitute CIB, while a single genuine account posting false content is handled under other rules.
Paid posters (水軍, "water army") are writers paid to post, comment or leave reviews on someone's behalf; the defining features are payment and non-disclosure. In Chinese-language media, 網軍 (literally "cyber army") is used in two ways: for hacker groups conducting cyberattacks, and for organized groups of accounts that steer the narrative. Both are colloquial terms with no agreed definition, and neither is the same as what platforms call coordinated inauthentic behavior.
Not necessarily. Fans answering a call to action, marketing campaigns or major news events can all lead many genuine accounts to post similar content at the same time, and X's policy also permits authentic coordination that does not break its rules. Whether it constitutes CIB depends on whether the accounts conceal their identities or relationships and meet the platform's full definition, which requires more behavioral evidence and human verification.
No. News alerts and weather or earthquake notifications may all be sent by bots, and automation in itself does not mean harm. Academic research likewise distinguishes legitimate bots that post news and updates from bots that spread spam or malicious content. What matters is the content, the behavior and the platform's rules, such as whether the bot is being used to artificially inflate volume or mislead people.
No, and it does not try to. InfoMiner collects public social media content, assesses suspicious accounts and account clusters in real time, and produces leads for staff to verify. It looks for behavioral signs; it does not perform identity resolution or cross-platform identity matching. Whether an account is a real person, and whether anything is illegal, is established through human verification and determined by the competent authorities.

Want visibility into suspicious account clusters on social media?

Contact the LargitData team to learn the scope and limits of anomalous account detection and assess whether it fits your needs.

Contact Us Explore the anomalous account detection solution