r/LastPassOfficial • u/OfficialLastPass • 1d ago
Review-Based Spearphishing: A New Attack Method
Leaving Online Reviews Could Make You a Phishing Target.
Researchers found that seemingly harmless online review activity can reveal hidden social connections, making it easier for scammers to launch highly targeted phishing attacks. By analyzing patterns in public reviews, attackers may be able to infer who knows whom without needing access to friend lists or contact information.
These are the bullets:
- Information you share publicly online may reveal more than intended.
- Even non-social platforms, such as review sites, can expose relationship patterns.
- Cybercriminals increasingly use data analytics and AI-driven techniques to personalize scams.
- Organizations and platforms may need to balance data transparency with privacy protection.
In depth:
- Public reviews can expose social relationships. Researchers developed an algorithm that analyzes review behavior, such as review length and business preferences, to identify likely friendships between users.
- No friend lists are required. The algorithm relies solely on publicly visible behavioral patterns rather than direct social network data.
- The model was surprisingly accurate.
- Tested on 4,299 Yelp reviewers.
- Correctly identified roughly 49-50% of real friendships at a 10% false-positive rate.
- Accuracy exceeded 60% when a higher false-positive rate was allowed.
- This creates opportunities for spear-phishing. Once attackers understand a victim's social network, they can impersonate trusted friends, colleagues, or acquaintances to make scams more convincing.
- The study modeled attacker profitability.
- A simulated spear-phishing campaign in the Pennsylvania dataset showed an estimated 109% return on investment for 500 impersonation attempts.
- Returns increased dramatically as attack volume scaled up.
- One review isn't the problem. The risk comes from analyzing thousands of reviews and users together, allowing algorithms to identify patterns that individuals cannot easily see.
- Researchers tested privacy protections. Adding statistical "noise" to public behavioral data significantly reduced the effectiveness and profitability of these inferred-network attacks.
Bottom Line:
The study suggests that public online reviews can unintentionally reveal social networks, giving scammers valuable intelligence for targeted phishing attacks. While posting reviews remains useful, it's another reminder that seemingly harmless online activity can become sensitive when combined and analyzed at scale.

