Posting online reviews may seem like a win-win activity, helping businesses attract customers while giving other consumers useful information. But new research from the McCombs School of Business at The University of Texas at Austin suggests that seemingly harmless reviews may also reveal information about users’ social connections, potentially leaving them and their online friends more vulnerable to cyberattacks.
The study focuses on spear phishing, a targeted form of phishing in which an attacker impersonates someone the victim trusts to persuade them to send money or disclose sensitive information. Yan Leng, assistant professor of information, risk, and operations management at McCombs, notes that phishing has become increasingly costly. Between 2021 and 2023, the FBI’s Internet Crime Complaint Center received nearly one million complaints involving about $305 million in losses.
Leng and colleagues investigated whether attackers could reconstruct users’ social networks simply by examining their online behaviour. Although many review platforms do not publicly display friendship connections, patterns in reviews and ratings may provide clues about who knows or interacts with whom. The researchers examined Yelp data involving 4,299 reviewers from Louisiana and Pennsylvania in 2020, where both reviews and users’ friend lists were publicly accessible.
The researchers first analysed review behaviour to predict connections between users, much as a cyberattacker might. They then compared those predicted relationships with users’ actual friendship networks. Their analysis found that an attacker could correctly identify 49% of social relationships based solely on online behaviour, while incorrectly identifying 10% of unconnected pairs as connected. With a higher false-alarm rate of 20%, as many as 63% of relationships could be identified.
One particularly revealing behavioural signal was review length. The researchers found observable relationships between the lengths of reviews written by connected users. For example, when one friend wrote longer reviews, another might also begin writing longer reviews. In other cases, one person might write shorter reviews that complemented a friend’s longer contributions. Such patterns can create behavioural fingerprints that reveal relationships even when friendship information itself is hidden.
This information could make spear-phishing campaigns more effective. Once attackers infer who is connected to whom, they can impersonate trusted contacts and send targeted scam messages or emails. The researchers found that identifying larger numbers of relationships could substantially increase attackers’ potential financial returns. In the Pennsylvania data, estimated returns increased from 109% for 500 attack attempts to 1,098% for 10,000 attempts.
Existing privacy protections may not fully address this problem because sensitive information does not necessarily have to be directly disclosed to create risk. Instead, attackers may infer relationships from apparently harmless behavioural data. The researchers say review platforms, e-commerce marketplaces, and media-sharing services should therefore examine whether the information they publish could unintentionally expose users’ social networks.
One possible safeguard is to introduce carefully designed “noise” into publicly available data. For example, platforms could subtly modify review text so that its length varies while its meaning remains unchanged, making behavioural patterns more difficult to detect. Simulations suggested this approach could reduce attackers’ financial incentives and sometimes make attacks unprofitable. Leng argues that platforms should therefore protect not only information users explicitly disclose, but also sensitive information that others may be able to infer from their behaviour.
More information: Yan Leng et al, When Behavioral Data Betray Users: A Diagnostic and Protective Framework Against Social Interaction Leakages, Information Systems Research. DOI: 10.1287/isre.2024.1469
Journal information: Information Systems Research Provided by University of Texas at Austin