What the Early-Access Submissions Showed
Over the period of Refute's early-access programme, we reviewed 500 stories submitted by brand safety and newsroom trust teams who flagged them as suspicious. The submissions came from organisations across media, consumer goods, and professional services, all participating in the programme before the product's wider availability.
We are not going to overstate what this dataset represents. Five hundred stories from organisations that had already decided something looked suspicious is not a representative sample of all content on any given platform. Self-selection bias is real: teams that submitted stories were already alert to the possibility of coordinated behaviour, and the stories they submitted skewed toward cases where something already looked off to an experienced eye. The patterns we found reflect what was in front of teams alert enough to flag potential manipulation, not the full distribution of coordinated behaviour across the internet.
With that caveat clearly stated, the patterns are worth discussing because they recurred consistently enough to be predictive, and understanding them practically helps trust teams allocate investigation time more effectively.
Pattern One: Thin Account Cluster Amplification
The most common pattern, present in roughly 60% of submissions that were subsequently confirmed as exhibiting coordinated behaviour, involved amplification by a cluster of accounts sharing several characteristics: recent creation dates (within a three-to-six-month window), thin posting histories before the campaign, minimal genuine follower engagement, and near-simultaneous posting or reposting activity concentrated in a short time window.
The visual pattern when you plot this account cluster's activity over time is unmistakable. The cluster is essentially quiet, posting sporadically and generating little engagement, until a specific story surfaces. At that point, their activity spikes sharply and then returns to low levels once the amplification window closes. The spike-and-return pattern around specific content is a strong indicator of operational coordination rather than genuine interest.
What made these cases distinctive was not that any individual signal was unusual in isolation. Newly created accounts exist for many legitimate reasons. Accounts that are mostly quiet are common. Simultaneous engagement with trending content is normal. The pattern that distinguished coordinated behaviour was the co-occurrence of all these signals in a cluster of accounts with no obvious organic reason to be connected.
Pattern Two: Recycled Narrative Templates
The second most common pattern, present in approximately 45% of confirmed cases, involved content that showed high template similarity across supposedly independent accounts. The content was not identical, which would be straightforward to detect. Instead, posts from different accounts followed recognisable rhetorical structures: the same underlying argument framed in superficially different language, the same claim sequences presented in varied vocabulary, and the same call to action embedded in posts that otherwise looked distinct.
Manual detection of this pattern is cognitively demanding because each individual post reads naturally. The similarity is not in individual phrases but in the structure of the argument being made. It requires reading many posts in parallel and noticing the structural regularity that would not be apparent from reading any one post in isolation. Algorithmic detection using document structure comparison rather than exact-match methods is substantially more reliable for this pattern than human review at any volume.
In several cases, the template similarity extended across content published in different languages, suggesting centralised authorship with translation steps rather than independent actors who happened to reach similar conclusions. The translated versions retained the underlying argument structure even where the specific vocabulary was very different, which is a reliable indicator of translation from a shared source rather than independent composition.
Pattern Three: Inauthentic Authority Signals
The third pattern was subtler and present in approximately 30% of confirmed cases. These involved accounts that had been built specifically to appear credible before being deployed in a campaign: accounts with multi-month or multi-year histories, genuine-looking follower patterns, and apparent subject-matter expertise signalled through their posting history. When these accounts amplified a story, they did not present the thin-cluster profile of the first pattern. They looked, individually, like real specialists or engaged community members.
What revealed the coordination in these cases was not any single account's profile but the network structure connecting them. Accounts that present as independent experts in a field but consistently interact with the same small cluster of other accounts, repost each other's content, and exhibit coordinated timing around specific events while being silent during the intervening periods are showing the structural signature of a managed network even when each account individually appears credible.
These cases required the most investigation time and had the highest initial false positive risk. The account-level signals were designed to resist easy classification, and the first-pass assessment of individual accounts often produced ambiguous results. The network analysis layer was essential for reaching confident conclusions, and it was the layer that most of the submitting teams lacked the tooling to execute themselves.
What We Did Not See: The Cases Worth Acknowledging
Roughly 35% of submissions, after analysis, showed no significant indicators of coordinated inauthentic behaviour. These were cases where the content had spread rapidly through what appeared to be genuine organic interest, where the account network amplifying it was diverse and did not exhibit coordination signals, or where the posting patterns were consistent with independent individuals responding to a real news event rather than a manufactured one.
These cleared cases are worth discussing specifically because they illustrate the risk of over-detection. Trust teams that submitted these stories had a genuine sense that something looked suspicious. In most cases, the cue was the speed of spread or the apparent uniformity of the sentiment being expressed. Speed and apparent uniformity are not reliable proxies for coordination. Genuine stories spread fast. Genuine public concerns produce temporarily homogeneous sentiment.
A detection process that confirmed all five hundred submissions as coordinated would have been worse than useless. The cleared cases represent real situations where acting on a false positive could have led to incorrect characterisation of organic content as manufactured, with all the editorial and reputational consequences that implies. Maintaining the discipline to clear as well as confirm is as important as the detection work itself.
Where Investigation Time Pays Off
The three patterns provide practical guidance for where investigation time is best spent. Cases exhibiting the first pattern, thin account cluster amplification, are often resolvable quickly with account-level analysis and are the ones most worth catching early. Cases exhibiting the second pattern, template similarity, require content analysis tools but can be confirmed with moderate effort. Cases exhibiting the third pattern, inauthentic authority signals, require full network analysis and are genuinely time-intensive to investigate reliably.
For teams with limited capacity, a triage approach that quickly characterises which pattern a submission most closely resembles, and allocates investigation depth accordingly, produces better coverage with finite analyst time than treating all submissions as requiring the same depth of investigation.