Review Length Can Reveal Social Networks, Enabling Spear-Phishing Attacks
A study from the University of Texas at Austin found that online review patterns, such as the length of reviews, can expose a user's social connections on platforms like Yelp. Attackers could exploit this leaked network data to craft spear-phishing emails impersonating trusted contacts. The researchers analyzed 4,299 Yelp reviewers and suggest that even seemingly innocuous posting behavior carries security risks.
The study analyzed 4,299 Yelp users across Louisiana and Pennsylvania, leveraging Yelp's public friend lists to verify predictions. Researchers found that review-length correlations between connected users provided the strongest signal, with mutual following relationships showing measurable stylistic convergence. Attackers could identify 49% of social ties at a 10% false-positive rate, rising to 63% when allowing 20% errors.
The economic incentive is substantial. FBI data logged nearly one million phishing complaints from 2021–2023, with $305 million in reported losses. For Pennsylvania users, projected scammer returns jumped from 109% on 500 targeting attempts to 1,098% on 10,000 attempts, demonstrating how network inference scales profitability.
This research highlights how seemingly benign digital footprints carry hidden privacy costs. Review platforms rarely disclose social graphs, yet behavioral signals like text length may effectively reconstruct them, meaning users who believe they post anonymously are more exposed than assumed. Spear-phishing attacks leveraging inferred connections could erode trust in online communities, particularly for small businesses and frequent reviewers whose visible activity makes them attractive targets. The findings may pressure platforms to reconsider what behavioral data they expose, though balancing transparency with security remains a complex trade-off.