Starting From the Network, Not the Content
When most people think about fake accounts, they picture the individual account: a suspicious profile photo, a thin posting history, an implausible follower-to-following ratio. These individual signals are real and useful, but they are rarely sufficient on their own. The reason is that account-level indicators are relatively easy for campaign operators to improve. A profile photo can be generated. A posting history can be built over months. Follower ratios can be managed. Individual account profiles have become less reliable as primary detection signals precisely because they are the most visible target for adversarial improvement.
The structural patterns that remain reliably detectable are not at the individual account level. They are at the network level: the relationships between accounts, the timing patterns of coordinated activity, the graph structure of the amplification network. Networks are much harder to fake convincingly than individual accounts, because doing so requires maintaining consistency across dozens or hundreds of accounts simultaneously, and the statistical requirements for what a "natural" network looks like are harder to simulate than the requirements for what a "natural" account looks like.
How Fake Account Networks Are Typically Built
Understanding network structure starts with understanding how these networks are constructed. A coordinated account network is not assembled randomly. It has an operational logic: different accounts serve different roles, and the network structure reflects those roles.
In the campaigns that have been publicly documented following platform enforcement actions, a typical structure involves several tiers. A small number of anchor accounts have the most developed profiles and posting histories and serve as the apparent origin points for the content the campaign wants to spread. These are the accounts most invested in appearing credible, because they carry the content itself and may be quoted or referenced in coverage of the story they are amplifying.
A larger group of amplifier accounts exists primarily to boost the reach and apparent resonance of the anchor accounts' content. These accounts may be less carefully developed, but they are responsible for the volume of engagement that makes the story appear to be spreading organically. Their individual profiles matter less than their collective contribution to apparent engagement metrics.
A third tier, present in more sophisticated campaigns, involves infiltration accounts: accounts with established histories in specific communities that can be deployed to spread the content within those communities in ways that appear to come from within the community rather than from outside. These are the most resource-intensive to build and are reserved for campaigns where the specific community is the target audience.
The Structural Patterns That Betray Coordination
Each tier of this network architecture leaves distinctive structural traces. The anchor-amplifier relationship produces a bipartite graph pattern: a small number of accounts receiving disproportionate amplification from a larger cluster that does not have an equivalent amplification relationship with other content. An amplifier account that consistently reshares content from the same three to five anchor accounts across multiple campaigns, while rarely sharing content from other accounts of similar profile, is exhibiting a structural asymmetry that is inconsistent with genuine interest-driven behaviour.
Temporal coordination within the amplifier tier produces the timing clustering signals discussed in earlier articles. But the specific pattern in a well-structured campaign network is more informative than general temporal clustering. The timing pattern often shows waves of amplification that correspond to tiered deployment: anchor accounts post first, then a first wave of amplifiers engage, then a second wave follows. The wave structure has a distinctive signature in the timing data that is inconsistent with independent accounts spontaneously discovering and sharing the same content.
The graph clustering coefficient within coordinated networks tends to be unusually high. Accounts within the network interact with each other at rates far exceeding what would be expected from independent individuals with similar stated interests. Clustering coefficient analysis requires comparing the actual density of interactions within a suspected cluster to the density that would be expected given the cluster's size and the platform's general interaction rate distribution. The baseline comparison matters: without it, high clustering within a small set of accounts is easy to find coincidentally and provides little information.
The Cases That Look Organic
Not every pattern that resembles coordinated behaviour is coordinated behaviour. Genuine communities of interest exhibit interaction patterns that superficially resemble coordinated networks: members know each other, they share each other's content, they respond to the same events at similar times because they follow the same information sources. A community of independent journalists covering the same beat will show coordinated-looking activity patterns when a major story breaks in their space, because they are all responding to the same genuine stimulus simultaneously.
The distinguishing feature is whether the coordination is stimulus-driven or deployment-driven. Genuine communities show elevated coordination around genuine events and low coordination between them. Coordinated networks show elevated activity specifically around the content they are deployed to amplify, but their coordination pattern does not follow the structure of genuine community responses: it precedes the organic signal rather than following it, and it does not distribute across the broad range of topics a genuine community of interest would engage with.
Content validation is also relevant here. Genuine grassroots activity around a concern that multiple people independently share tends to produce varied content: different framings, different emphasis, different levels of detail, reflecting independent people engaging with the same issue from their own perspectives. Coordinated amplification produces the structural similarity in content that the previous article described. The combination of network structure analysis and content analysis is much more reliable than either alone for distinguishing genuine collective behaviour from manufactured coordination.
Detection Without Platform Access
The most detailed network analysis would require access to platform-internal data: session logs, device fingerprints, IP clustering information that platforms use in their own detection operations. Most organisations outside the platforms themselves do not have this access. The question is how much can be reliably detected from public-facing data alone.
The honest answer is: enough to catch the large majority of operational campaigns. The most sophisticated network operators, those who have invested in making their networks appear credible over extended periods and who carefully manage the timing and volume of their activity to stay below detection thresholds, represent a small fraction of the overall campaign population. They are also typically operating against higher-value targets than most brand safety teams or newsroom trust desks encounter regularly.
For the larger population of coordinated campaigns using standard operational patterns, public-facing account data provides sufficient signal for confident detection if analysed systematically. The combination of account profile analysis, posting cadence examination, cross-account interaction patterns, and content structure comparison produces a multi-signal picture that is reliable for the cases that matter most in practice. The detection gap at the top of the sophistication distribution is real; it should not be used to dismiss the value of detection capability against the much larger volume of less sophisticated campaigns below it.
Building Detection Into Operations
For organisations trying to incorporate network analysis into trust operations, the practical starting point is to establish what a baseline "normal" network looks like for the account populations relevant to your monitoring scope. Without a baseline, anomaly detection produces too many false positives to be operationally useful. With a baseline calibrated to your specific context, the structural anomalies that indicate coordinated behaviour become distinguishable from the natural variation in genuine community activity.
This calibration work takes time and requires a period of manual investigation to build the reference cases that training data and threshold-setting require. Teams that skip the calibration phase and deploy detection tools directly against live data typically encounter precision problems early, which undermines analyst confidence in the tools before they have had a chance to be useful. Starting with a smaller, well-understood scope and expanding as the baseline confidence improves is a more reliable path than trying to achieve broad coverage immediately.