In the quiet act of writing a restaurant review, millions of people unknowingly sketch a map of their social world — one that scammers have learned to read. Research from the University of Texas at Austin reveals that the length and pattern of public online reviews can expose who knows whom, giving spear phishers the intelligence they need to impersonate trusted contacts with devastating precision. The finding reframes a familiar question about digital privacy: it is not only what we choose to share, but what others can deduce from the shape of our sharing, that places us at risk.
Study reveals how review patterns expose users to spear phishing attacks
Platforms need to protect not only what users disclose, but also what others can infer.
So the study is saying that just by looking at how long someone's reviews are, you can figure out who their friends are?
Not directly, no. But patterns emerge across thousands of reviewers. If two people consistently write similar-length reviews, or if one writes long and the other short in a complementary way, the model picks up on that signal. Across a large dataset, those patterns reconstruct the social network.
How accurate is this, though? Forty-nine to sixty-three percent is a range. What's the false positive rate? Because if you're a scammer sending ten thousand phishing emails, you need to know which ones are actually going to work.
The study does acknowledge higher identification rates come with more false positives. But from a scammer's perspective, that's just a cost of doing business. The ROI still scales massively.
Why is review length the strongest signal? That seems almost random.
People who know each other might share similar communication styles, or they might deliberately write differently to avoid being obvious. Either way, there's a pattern. It's not that review length alone is definitive—it's that across thousands of data points, these patterns become statistically significant.
But we should be careful here. This is based on Yelp data from 2020. Yelp's privacy settings have changed. The friendship lists aren't public anymore. So how much of this is still a live threat?
That's a fair question. The vulnerability Leng identifies is real, but the specific attack surface she studied may have already been partially closed. That doesn't mean the principle is wrong—it means platforms need to stay ahead of it.
And the solution is to randomize review lengths?
Not just that. It's about adding noise to the data in ways that don't destroy its usefulness. You still get honest reviews, but the linguistic fingerprints that reveal social ties get blurred.
Which means platforms have to do the work. Users can't protect themselves from this on their own.
Exactly. This isn't a password you can strengthen or a privacy setting you can toggle. It's structural.
Der Puls
- A vulnerability hiding in plain sight: the mundane act of reviewing a restaurant can betray your closest social connections to bad actors scanning for targets.
- Researchers reconstructed 49 to 63 percent of real social relationships among thousands of Yelp users using only public review patterns — never once consulting a friendship list.
- The financial incentive is staggering — spear phishing campaigns leveraging this data can yield returns exceeding 1,000 percent at scale, turning a low-effort deception into a highly profitable operation.
- The burden of defense, the researcher argues, should not fall on users but on the platforms themselves, which have long protected explicit disclosures while ignoring what can be quietly inferred.
- A proposed solution is deliberately modest: randomizing displayed review lengths just enough to blur social fingerprints, without diminishing the usefulness of reviews for honest readers.
In the quiet act of writing a restaurant review, millions of people unknowingly sketch a map of their social world — one that scammers have learned to read. Research from the University of Texas at Austin reveals that the length and pattern of public online reviews can expose who knows whom, giving spear phishers the intelligence they need to impersonate trusted contacts with devastating precision. The finding reframes a familiar question about digital privacy: it is not only what we choose to share, but what others can deduce from the shape of our sharing, that places us at risk.
An assistant professor at the University of Texas at Austin has identified an unsettling vulnerability embedded in one of the internet's most ordinary habits. Yan Leng, of the McCombs School of Business, published research showing that the patterns in how people write online reviews — particularly review length — can reliably reveal their real-world social connections. For spear phishers, who craft convincing scams by impersonating someone a victim already trusts, this kind of intelligence is precisely what they need.
Leng and her colleagues studied four thousand Yelp reviewers from Louisiana and Pennsylvania during 2020, when both review texts and friendship lists were publicly visible. Without consulting the friendship data at all, their model inferred between 49 and 63 percent of users' actual social relationships simply by analyzing reviewing patterns. Connected users tended to write reviews of similar length, or showed complementary habits — one consistently longer, the other shorter. These linguistic fingerprints, aggregated across thousands of accounts, were enough to partially reconstruct an entire social network.
The economic stakes sharpen the concern considerably. When researchers modeled the returns on spear phishing campaigns powered by this data, the numbers were striking: a campaign of five hundred attempts might yield a 109 percent return on investment, while one reaching ten thousand targets could climb to 1,098 percent. Impersonation becomes more convincing — and more profitable — the more accurately an attacker can identify a victim's real connections.
Leng's response to this finding is notably restrained. She does not call for people to stop writing reviews. Instead, she places responsibility on the platforms, recommending subtle, carefully designed obfuscation — such as slightly randomizing the displayed length of reviews without altering their content. The goal is to blur the fingerprint without diminishing the review's value to genuine readers.
The deeper lesson her work surfaces is one the industry has been slow to absorb: protecting users means guarding not only what they knowingly disclose, but what patient analysis of their behavior can quietly reveal about them.
A researcher at the University of Texas at Austin has uncovered an unexpected vulnerability hiding in plain sight: the way people write online reviews can expose their social connections to scammers.
Yan Leng, an assistant professor of information, risk, and operations management at McCombs School of Business, published findings in Information Systems Research showing that patterns in publicly available review activity—particularly the length of reviews people write—can reveal who knows whom. For spear phishers, who succeed by impersonating someone a victim trusts, this is valuable intelligence. The attack works like this: a scammer contacts a target while pretending to be a friend or colleague, requesting passwords or money. If the attacker can identify who that person's actual connections are, the deception becomes far more convincing.
Leng and her colleagues analyzed four thousand Yelp reviewers from Louisiana and Pennsylvania during 2020, a period when both review texts and friendship lists were publicly visible on the platform. They built a model to see whether they could infer social connections just from reviewing patterns, without ever looking at the friendship data. The results were striking. Connected users often wrote reviews of similar length. Other pairs showed complementary patterns—one person consistently writing longer reviews, the other shorter ones. Across thousands of reviewers, these linguistic fingerprints allowed the researchers to reconstruct portions of the social network. Their model identified between 49 and 63 percent of the reviewers' actual social relationships.
Review length emerged as the strongest signal. While this might seem like a tenuous connection—that how much someone writes about a restaurant could reveal who their friends are—Leng's work demonstrates a genuine pattern beneath the noise. The implications for attackers are straightforward and grim. More identified connections mean more targets for impersonation attempts. And spear phishing, it turns out, is fundamentally a numbers game. When researchers modeled the economics of such attacks, the return on investment scaled dramatically. A scammer attempting five hundred phishing messages might see a 109 percent return. At ten thousand attempts, that figure climbed to 1,098 percent.
What makes this discovery particularly important is what Leng does not recommend. She is not calling for people to stop writing reviews. Instead, she places the responsibility squarely on the platforms themselves. Her suggestion is elegant: platforms should make small, carefully designed random changes to data before releasing it publicly. One example would be subtly varying how long a review appears without altering its actual content or usefulness. This would blur the linguistic fingerprint that reveals social ties while keeping the reviews themselves intact and valuable to genuine users.
The core insight is simple but profound. Platforms have long focused on protecting what users explicitly disclose—passwords, friend lists, direct messages. But they have largely ignored what others can infer from the patterns in that data. As Leng puts it, the platforms need to protect not only what users knowingly share, but also what can be deduced from it. For millions of people writing honest reviews every day, that distinction could mean the difference between a safe online presence and exposure to a carefully targeted scam.
Bemerkenswerte Zitate
The platforms need to protect not only what users disclose, but also what others can infer.— Yan Leng, assistant professor at University of Texas at Austin