Last updated:

What to do when a brand is targeted by narrative-steering attacks: identifying coordinated negative reviews and the response process

When a wave of negative reviews suddenly hits a brand on social media, forums and review platforms, the first question is not how to fight back but whether these voices are real customers or a group of accounts coordinating to steer the narrative. This article covers the signs of coordinated negative reviews, how to tell them apart from genuine complaints, the response process, evidence preservation and legal considerations. It applies to brands, consumer goods, food and beverage, retail and e-commerce.

Infographic for Brand Astroturfing and Coordinated Attacks: How to Respond, illustrating key concepts from Use Cases

What narrative steering and coordinated negative reviews are

Astroturfing means dressing up organized, orchestrated messaging as a spontaneous grassroots voice; the Chinese terms 帶風向 (steering the narrative), 網軍 (troll farms) and 水軍 (paid posters) describe similar phenomena. When it targets a brand, it can take the form of one-star reviews posted by the same group of people running multiple accounts, boycott posts that all repeat the same talking points, or a single genuine complaint reposted again and again to amplify it.

Each platform has its own policies on fake engagement, inauthentic accounts and manipulation. Meta's Community Standards (December 2025 update) classify networks of inauthentic assets controlled by the same person or group with the intent to deceive Meta or the community, or to evade enforcement of the Community Standards, as inauthentic behavior, and call complex inauthentic behavior carried out by adversarial actors using fake identities coordinated inauthentic behavior (CIB). Google Maps' user-contributed content policy prohibits content not based on a genuine experience, paid reviews, and content posted from multiple accounts by or at the request of the same person, and also prohibits posting content on a competitor's business listing to harm its reputation. X's Authenticity policy prohibits artificially influencing conversations through coordinated inauthentic activity, and also prohibits operating multiple accounts to inflate the visibility of content or accounts. YouTube prohibits artificially inflating metrics such as views, likes and comments through automated systems or other means. Conversely, a cluster of negative reviews, a call for a boycott or mass reposting is not by itself enough to establish a violation, and spontaneous collective criticism from real customers is legitimate expression. For a full definition of coordinated inauthentic behavior, see What is coordinated inauthentic behavior (CIB)?.

This article does not cover ordinary negative volume. Criticism driven by products, service or pricing falls under brand reputation management and crisis handling; see brand reputation management and PR crisis monitoring. This article focuses on a different situation: negative reviews that appear to be driven by coordinated, inauthentic accounts.

Signs of coordinated negative reviews: situations worth verifying further

Below are situations a brand team can check first against its own operations. They do not prove coordination on their own, nor are they platforms' criteria for a violation; real customers can exhibit any of them too. Their only purpose is to flag that a particular batch of negative reviews is worth spending a little more time verifying.

  • Negative reviews cluster, but no plausible cause can be found internally : no product issue, shipping delay, price change or news event in the same period explains the reaction.
  • Details do not match the facts : reviews mention products the brand does not sell, stores that do not exist or plans that have not launched yet.
  • Negative reviews steer readers to the same destination : the point of the content is not to describe a customer experience but to direct readers to a particular competitor, group or link.

Account- and content-level assessment methods — account attributes, posting behavior, content similarity and interaction networks — along with their limitations, are covered in How to spot fake accounts; this article does not go into them.

Telling coordinated negative reviews apart from genuine complaints

The starting point is verifiable facts, not tone. A real customer's complaint can be scathing, and content from coordinated accounts can be perfectly polite. The table below lists questions to ask first when verifying, and the limits of each:

Question to ask first If it checks out If it does not, keep in mind
Can the orders, dates and stores mentioned in the review be found in internal records? Handle it through the normal complaint process Internal records may be incomplete, and the customer may have bought under someone else's name or through a reseller; not finding a record does not mean there was no genuine experience
Did anything happen in the same period that could have caused dissatisfaction? The cluster of negative reviews can be explained by the event; deal with the event itself first It may be a problem the brand has not noticed yet; widen the scope of the internal review first
Do the products, stores and plans described in the review actually exist? Respond and improve based on the content The customer may have misremembered or confused brands, or the content may be false; log it as evidence and respond with facts

Three further cautions. First, not asking for a refund, declining to message privately and simply voicing a boycott are all consumers' prerogatives, and none of them justifies presuming an account is inauthentic. Second, a real event can also cause customers to post negative reviews all at once; clustering by itself does not prove coordination. Third, a single genuine complaint may be picked up and amplified by a batch of accounts. In that case, handle the complaint through the normal process and collect evidence on the amplification separately — the fact that someone amplified it is no reason to deny the original problem.

Confirm before responding: the risk of misjudging genuine complaints

Under pressure, a brand may be tempted to announce publicly that it is under attack by a troll farm. If the reviewers later prove to be real customers, a complaint that could have been handled may turn into a second PR crisis — one about accusing consumers. Legally, publicly asserting that specific people are fake accounts or paid smear writers can also give rise to defamation-related disputes. In the United States, the Federal Trade Commission (FTC) Rule on the Use of Consumer Reviews and Testimonials (16 CFR Part 465), effective October 21, 2024, makes it an unfair or deceptive practice under § 465.7 to use public false accusations, made with knowledge or reckless disregard of their falsity, to prevent or remove consumer reviews.

We therefore recommend this sequence:

  1. Check internally first : have customer service, stores, logistics and product teams check the facts the negative reviews mention, and confirm whether any real event recently could have caused dissatisfaction.
  2. Triage : reviews that map to a concrete problem go through normal complaint handling; for those that do not, and that also show the situations worth verifying described above, keep responding as usual while collecting evidence separately — without jumping to conclusions.
  3. Respond to the facts, not the accounts : keep public statements focused on verifiable facts, such as product specifications, store opening status and return or exchange channels, and invite customers with a genuine purchase experience to message you privately. Do not accuse any account in public replies of being fake or of taking part in a coordinated campaign.
  4. Keep your assessment flexible : record the preliminary assessment internally, noting what it is based on and what remains unconfirmed. That way it can be revised whenever new evidence emerges, instead of locking in a position from the outset.

For how to divide responsibilities, align messaging and sequence public statements during a crisis, see Crisis communication SOP.

What InfoMiner does in this process

InfoMiner continuously collects content published publicly on social media and forums, provides real-time intelligence assessment, and produces leads on suspicious accounts and account clusters for brand teams and consultants to verify manually. Observable coverage depends on the plan and licensing and is limited by data availability; gaps may occur when platforms change or restrict access.

There are two limitations in use. First, what the system produces are suspicious leads, not determinations. Whether those accounts are real people, who is behind them and whether anything illegal occurred must be verified by people, and where legal liability is involved, the determination rests with the competent authorities. Second, the system does not perform identity resolution: it does not determine the individuals or organizations behind accounts, nor does it map identities across platforms.

Companies that need AI inference on their internal network can evaluate on-premise deployment of RAGi; the actual configuration has to be confirmed separately.

For the overall anomalous account detection solution and deployment options, see Anomalous account detection solution.

Preserving evidence and reporting to platforms

Preserve evidence before you report, so that nothing is lost if the platform removes the content or disables the account. We recommend saving:

  • The URLs of the content and profile at the time, the account name, and any publicly available platform identifiers. Accounts may be renamed, posts deleted or accounts suspended, breaking those URLs, so save screenshots or web archives as well.
  • Complete, timestamped screenshots or web archives that clearly show the platform, account, content and posting time, along with a record of the capture date and who captured it.
  • An overall timeline: when the negative reviews began, when they peaked, the order in which they appeared across platforms, and any events found internally during the same period.
  • Internal review records: which negative reviews match orders or customer service records, which do not, and the basis for that assessment.

Limit evidence collection to what is necessary to handle the incident at hand. In Taiwan, Article 19, Paragraph 1 of the Personal Data Protection Act requires non-government agencies collecting or processing personal data to have a specific purpose and to meet one of the conditions listed in that paragraph; even content the person made public themselves cannot be filed and used without limit. Where evidence is at risk of being lost or becoming difficult to use, Article 368 of the Code of Civil Procedure also provides a route to petition the court to preserve evidence.

When reporting to a platform, point to the specific policy you believe was violated and attach your evidence. Taking Google Business Profile as an example, businesses can report policy-violating reviews on their profile or flag them through the review management tool. Google says reviews usually take several days, that status can be checked in the tool, and that for a review found not to violate policy, one appeal can be filed via the tool's options. Meta, X and YouTube also all have reporting channels for fake accounts and manipulation. Whether and how quickly action is taken is up to the platform under its own policies, so evidence collection cannot wait for the outcome of a report.

We recommend involving legal counsel as early as possible in the situations below. This section only lists relevant provisions for discussion and does not constitute legal advice. Whether an offense is made out, who can bring a claim and what can be claimed all depend on the specific facts, and the current text on the Laws & Regulations Database of the Republic of China (Taiwan) is authoritative.

  • There are signs pointing to a competitor : Article 24 of the Fair Trade Act provides that no enterprise may, for the purpose of competition, make or disseminate any false statement that is injurious to the business reputation of another.
  • The content appears to be a false statement rather than an opinion : Article 313 of the Criminal Code punishes anyone who damages another's credit by spreading rumors or by fraudulent means, and Paragraph 2 provides that the punishment may be increased by up to one half when the offense is committed through the internet or other means of mass communication. On the civil side, have a lawyer assess provisions such as Articles 184 and 195 of the Civil Code. Note also that under Article 311 of the Criminal Code, a person who expresses an opinion in good faith or makes fair comment on a matter open to public scrutiny is not punishable — negative opinions are not unlawful in themselves.
  • Considering filing a criminal complaint : under Article 314 of the Criminal Code, offenses in the chapter on offenses against reputation and credit are prosecuted only on complaint. Article 237, Paragraph 1 of the Code of Criminal Procedure requires the complaint to be filed within six months from the time the person entitled to file it learns who the offender is. This is the complaint period; have a lawyer confirm exactly when it starts to run.
  • Preparing a public response or asking a platform to remove content : if a public statement involves accusing others, have legal confirm the wording first so the brand does not end up in a defamation dispute of its own.

One last caution: do not fight fire with fire. If a brand hires people to write positive reviews or pad its ratings to offset negative ones, in Taiwan this may amount to a false or misleading representation under Article 21 of the Fair Trade Act, or a deceptive act able to affect trading order under Article 25. In the United States, the FTC rule mentioned above prohibits businesses from writing, creating or selling fake consumer reviews; prohibits buying reviews about their own business, products or services when they know or should know the review materially misrepresents whether the reviewer exists, whether the reviewer actually used the product, or the reviewer's actual experience; and prohibits offering compensation or incentives in exchange for reviews expressing a particular positive or negative sentiment. Countering coordinated behavior with coordinated behavior can turn a brand from the victim into the party being reported.

FAQ

Not necessarily. When a product defect or service outage occurs, real customers posting at the same time will also produce a cluster of negative reviews. Start by having customer service, store and product teams check the facts the reviews mention against recent events. Even if no cause turns up, that only means the reviews deserve further verification — it is not grounds for concluding there is a coordinated campaign.
Not before you have verified it. If the reviewers later turn out to be real customers, the brand has added a second controversy — accusing its own consumers — and may also face defamation-related legal issues. Keep public responses focused on verifiable facts and on how customers can get help, and have legal review any wording that accuses others before it goes out.
Not necessarily. Whether content is removed, and how quickly, is decided by the platform under its own policies; the brand cannot guarantee the outcome. When reporting, point to the specific policy you believe was violated — for example, Google Maps' prohibition on content posted from multiple accounts by or at the request of the same person. Save screenshots and URLs before you report, so you do not lose the evidence if the content is taken down.
No, and it does not perform identity resolution. InfoMiner continuously collects public social media content, assesses suspicious accounts and account clusters in real time, and produces leads for people to verify. Whether an account is a real person, who is behind it and whether anything illegal occurred require human verification, and where legal liability is involved, the determination rests with the competent authorities.

InfoMiner Social Listening

InfoMiner produces leads on suspicious accounts for human verification. Features, data coverage and deployment options depend on the plan; contact us to learn about its capabilities and limitations.

Contact Us InfoMiner Social Listening