UA RU EN

Fraudsters may identify your friends from the reviews you post online

Зловмисники можуть дізнатися про ваших знайомих завдяки відгукам, які ви залишаєте в Інтернеті. Photo: НВ — Техно

What posting reviews can cost you

Leaving online reviews may quietly expose both users and the people around them to targeted phishing. Public feedback appears harmless, but researchers at the McCombs School of Business at the University of Texas at Austin found that attackers can reconstruct a user’s list of friends with striking accuracy using only that public content. In a 2020 analysis of 4,299 Yelp users in Louisiana and Pennsylvania, review texts and star ratings allowed correct identification of up to 49% of social connections with minimal errors. When a higher error margin was accepted, identification accuracy reached 63%.

The strongest signal turned out to be the length of a user’s written reviews. The more relationships an attacker can uncover, the more likely phishing campaigns are to succeed; depending on campaign scope, estimated success rates rise by 109% to 1,098%. In targeted phishing, criminals impersonate people the victim trusts, making the deception much harder to spot.

How widespread phishing has become

Between 2021 and 2023, the FBI’s Internet Crime Complaint Center received almost one million complaints about phishing schemes, with reported losses exceeding $305 million. Although most review platforms do not publish users’ contact lists, that does not stop attackers from gathering information through other means.

Led by associate professor Yan Leng, the research group suggests deploying algorithms that add artificial information noise, adjusting review lengths without altering the actual content. Simulations indicate this technique could entirely remove the financial incentive behind such cyberattacks. Notably, the European Union’s GDPR does not cover the indirect information sources used in this study.

This work is a reminder to think carefully about the personal details we post online, especially on review sites.

From an attacker’s perspective, more publicly available data means a greater chance of success. Privacy-protecting technologies, such as noise-based algorithms, could become a valuable defense, but they still require further research and testing. At the same time, users need greater awareness of these threats and of practical ways to safeguard personal information online.