Account Forensics
MinutesBefore taking an online account's word, or taking a crowd of accounts as public opinion, spend a minute on the profile itself: its age, history, posting rhythm, network, and photo, which together show whether you are looking at a person, a persona, or a coordinated operation.
How to do it
- 1Check the creation date against the behaviour. A week-old account, or an old account that was silent for years and then began posting heavily on one topic, deserves suspicion.
- 2Scroll back. Look for abrupt changes of language, subject, or identity, and for deleted history; repurposed and purchased accounts often show a seam.
- 3Look at the rhythm. Dozens of posts an hour, activity around the clock with no sleep gap, or bursts that coincide to the minute with other accounts are signs of automation or scheduling.
- 4Look at originality. A feed made almost entirely of reposts, or of replies pasted word for word under many different posts, is amplification rather than conversation. Search a distinctive sentence in quotation marks to see who else posted it.
- 5Check the identity markers: reverse-search the profile photo, read the handle (a name followed by a string of digits is a default), and treat a paid verification badge as proof of payment, not of identity.
- 6Judge the pattern across accounts. One odd sign means little; many accounts sharing creation dates, wording, timing, and targets is the signature of coordination.
What to say
- “Before I answer this account: it was created last month, posts every few minutes, and has never said anything that was not a reply.”
- “Are all these replies from different people? Six of them use the same sentence.”
When to use it
- •A sudden wave of replies, reviews, or comments all pushing the same line.
- •An account claiming to be an insider, a local resident, a veteran, a nurse, or a member of a group in order to lend a claim authority.
- •A stranger who messages you with an opportunity, a romance, or an urgent problem.
- •Deciding whether a trending topic reflects real public feeling.
Counters
Evidence and how strong it is
Ferrara et al. (2016) review how social bots operate and the features (account age, timing, network structure, content originality) that distinguish them, and Varol et al. (2017) estimated from such features that roughly 9 to 15 percent of active Twitter accounts at the time showed bot-like behaviour. The Atlantic Council's Digital Forensic Research Lab published a practitioner checklist of twelve indicators (Nimmo 2017) that closely matches the steps above. Evidence strength: observational and practitioner. The indicators are probabilistic, not diagnostic. Rauchfleisch & Kaiser (2020) showed that a widely used automated bot detector produced many false positives and false negatives and gave inconsistent scores over time, and coordinated campaigns increasingly use real people and aged accounts that pass simple checks.
- Do not call individuals bots in public. Real people post obsessively, use default handles, join late, and write in a second language. A false accusation is insulting, derails the discussion, and is itself a common way to dismiss critics.
- Inauthentic accounts can spread true claims and authentic accounts can spread false ones. Forensics tells you how much weight the apparent crowd deserves, not whether the claim is correct.
- Platform changes have removed or hidden much of the data these checks rely on, and paid verification has inverted what a badge means. Expect the checks to get harder, not easier.
- If an account is harassing or threatening you, do not investigate the person yourself. Document, block, report to the platform, and involve police if there are threats.
- Ferrara, E., Varol, O., Davis, C., Menczer, F., & Flammini, A. (2016). The Rise of Social Bots. Communications of the ACM, 59(7), 96-104Review of social-bot behaviour and the account features used to distinguish automated from human accounts.
- Varol, O., Ferrara, E., Davis, C. A., Menczer, F., & Flammini, A. (2017). Online Human-Bot Interactions: Detection, Estimation, and Characterization. Proceedings of the Eleventh International AAAI Conference on Web and Social Media (ICWSM), 280-289Feature-based estimate that roughly 9 to 15 percent of active Twitter accounts were bot-like at the time of study.
- Nimmo, B. (2017). #BotSpot: Twelve Ways to Spot a Bot. Atlantic Council Digital Forensic Research Lab (DFRLab)Practitioner checklist of activity, anonymity, and amplification indicators for automated and inauthentic accounts.
- Rauchfleisch, A., & Kaiser, J. (2020). The False Positive Problem of Automatic Bot Detection in Social Science Research. PLOS ONE, 15(10), e0241045Evidence that automated bot detection misclassifies many accounts, the basis for the caution against labelling individuals.