Bot network detection: how to spot a bot network or coordinated pile-on on your page
Call it a bot network, a troll farm, brigading, fake accounts or a pile-on: it is a group of accounts acting together to make one post, one page or one person look universally hated. From inside the comments it feels like a hundred angry individuals. From the outside, five signals give it away: timing, phrasing, account age, repetition across posts, and shared links. This guide explains each signal, how to check it by hand, what to record while it is happening, and how to show the pattern to a platform or the police.
7-day free trial on every plan · hosted in Australia · cancel anytime

A word of caution. The five signals below point to coordination; they do not prove it, and real people who are genuinely angry sometimes trip them too. Clarify's detection is the same: it proposes groups with a suspicion score and its reasoning, it can miss a network or group accounts that are not working together, and nothing becomes a record until a person reviews it and clicks Apply. Treat every group as a lead to check, not a verdict, and never name an account publicly as a bot on the strength of a pattern alone. Clarify is software, not a lawyer, and nothing here is legal advice.
Why a bot network looks organic until it is not
- Each comment is plausible on its own. No single message is the problem. The problem is that forty of them arrived in eleven minutes.
- The page only shows you the page. You cannot see that the same accounts did the same thing to three other pages last night.
- It sets the tone for everyone else. Genuine readers see a thread that is already hostile and either join in or leave. That is the point of it.
- By the time it is obvious, the evidence is scattered. Hidden, deleted, screenshotted on three phones, and impossible to put back in order.
The five signals, and how to check each by hand
Timing
Organic backlash builds over hours as people see the post. A coordinated wave lands in a burst: several flagged accounts on one post within minutes of each other, often outside the hours your audience is normally awake. Sort the comments by time and look for the cluster.
Phrasing
People who are genuinely angry say it differently from each other. Accounts working from a shared script say it the same way: identical sentences, the same unusual spelling, the same hashtag nobody else uses. Search the comments for an odd phrase and count how many accounts used it.
Account age
A burst of accounts you have never seen before, all arriving on the same post, is the strongest single signal. Open a few profiles: created recently, few or no posts of their own, a stock-looking photo, and a comment history that is all pile-ons.
Repetition across posts
The same message dropped on many posts, or the same group of accounts turning up under every post for a week, is a campaign rather than a reaction. Check your last five posts for the same names.
Shared links and shared names
A few accounts pushing the same obscure link, or the same username appearing on two platforms doing the same thing, connects accounts that are pretending to be strangers.
What to do while it is happening
Do not argue in the thread. Replies feed the algorithm and the participants. Hide, do not delete. The platform's hide removes a comment for everyone except the person who wrote it, so the evidence stays and nobody gets a screenshot of a censored gap. Record the burst as one event, with the time window, the post, and the accounts, rather than as forty separate complaints. Mute the persistent ones for a day or a week rather than blocking, which tells them it worked.
If the page belongs to an MP, a council or a club with other members, tell whoever can see across pages. One office sees a bad night. A party or club HQ sees the same sixteen accounts hitting six members.
How Clarify finds the same five signals automatically
On every sync, Clarify's own checks look for hard evidence across recent comments: the same text from different accounts, several flagged accounts hitting one post within minutes, a burst of never-before-seen accounts on the same post, the same obscure link pushed by a few accounts, and the same username on two platforms. Each finding is a receipt. The AI then weighs the receipts together with what the comments say and proposes a group, with a suspected coordinator and its reasoning.
Open the group and every member has a suspicion score, and the combined timeline badges comments posted within thirty minutes of each other, so the wave is visible at a glance. Quick Report produces a timestamped, confidential dossier for a platform, the eSafety Commissioner or police, and the whole group can be raised as one case. Nothing becomes a record until a person clicks Apply. This is one part of how social media threat monitoring works in Clarify.

Showing the pattern to a platform or the police
A platform's inauthentic behaviour team and a police officer want the same thing: the pattern laid out so that it is obvious without your commentary. One timeline, all accounts, with the burst marked. A list of the accounts with their creation dates and the phrase they shared. The posts they hit, in order. And, separately, any comment in the wave that crosses from abuse into a threat, because that one is reported on its own merits and the pattern is context for it. The guide to reporting a threatening comment in Australia covers that path.
A pile-on is not, by itself, a crime. Coordinated harassment can be, and inauthentic coordinated behaviour breaks every major platform's rules. The evidence you keep is what moves it from the first category to the second.
Frequently asked questions
What is a coordinated pile-on on social media?
A coordinated pile-on is a group of accounts acting together, by arrangement or from a shared script, to flood a post, a page or a person with hostile comments so that the target looks universally disliked and genuine readers are driven away. It is distinguished from an organic backlash by timing (comments arrive in a burst), near-identical phrasing, a cluster of new or empty accounts, the same message repeated across many posts, and shared links or usernames across platforms.
Is a pile-on the same thing as a bot network or a troll farm?
They overlap, and from your page they look identical. A bot network is a set of automated or semi-automated accounts run from one place; a troll farm is people paid or organised to do the same job by hand; brigading is a crowd recruited from somewhere else to descend on one target; a pile-on is what any of them produces. The five signals (timing, phrasing, account age, repetition across posts, shared links) work for all of them, because they detect coordination rather than what is behind it.
Is a coordinated pile-on illegal in Australia?
Not by itself. A pile-on becomes a legal matter when the comments in it cross into threats, menacing or harassing behaviour under the Commonwealth Criminal Code or state law, or into adult cyber abuse under the Online Safety Act 2021. Separately, coordinated inauthentic behaviour breaks the rules of every major platform, which is why the pattern itself is worth reporting to the platform even when no single comment is unlawful.
Can you find out who is behind a fake account?
Not from the page itself, and usually not from the platform directly. What you can do is document the pattern: which accounts, when they were created, what they said and where, which is the evidence police need to ask the platform for the account's details, and which the eSafety Commissioner can use its information-gathering powers on in an adult cyber abuse case. Clarify's account tracker keeps that history per account across all of your pages, and the same username appearing on two platforms is one of the receipts coordination detection records.
Can I tell for certain that the accounts are bots?
Rarely, and you do not need to. What you can show is coordination: the same words, the same minute, the same new accounts, the same posts. Whether the hands on the keyboards belong to one person, a paid group or automated accounts matters less than the fact that they are acting together. Clarify shows a suspicion score and its reasoning for each account rather than a verdict, and a person decides what to do with it.
Should I turn off comments during a pile-on?
A public body often cannot, and for anyone else it hands the campaign its win. A better pattern is to hide the hostile comments rather than delete them, mute the persistent accounts for a day or a week, switch on auto-hide for the categories you trust (slurs and spam, for example) so the clear-cut cases disappear the moment they land, and keep replying to the genuine questions so the thread stays yours.
How does Clarify detect coordination?
On every sync, Clarify's own checks look for the same text from different accounts, several flagged accounts hitting one post within minutes, a burst of accounts it has never seen before on the same post, the same obscure link pushed by a few accounts, and the same username on two platforms. Each finding is a receipt. The AI weighs the receipts together with the comments' content and proposes groups with a suspected coordinator and its reasoning. A person reviews the group and clicks Apply before it becomes a record.
Read how it works, step by step
- Coordination GroupsSometimes abuse isn't a collection of individuals; it's a campaign. Coordination Groups is where Clarify identifies clusters of accounts acting together: bot…
- The Account TrackerThe Account Tracker is your watch list: accounts that have been flagged for threats, repeated abuse, suspected fakery, or coordinated behaviour.
- Muting a commenterSome accounts aren't worth a case or a block. They're just a persistent nuisance who turns up on every post. Muting is for them.
- Auto-hiding commentsAuto-hide lets Clarify hide the worst comments for you, the moment they're found, so a slur or a spam link isn't sitting on your Page waiting for someone to…
Pricing
Coordination detection, the account tracker, muting and auto-hide are in every plan. Prices in Australian dollars; every plan starts with a 7-day free trial, and paying yearly gives two months free.
More from Clarify
- Threat monitoring and reportingSocial media threat monitoring for Australian MPs, councils and public figures. Clarify watches your own pages for threats, preserves the evidence, and builds police and eSafety-ready reports.
- Replies in your voiceClarify drafts replies to the comments on your Facebook, Instagram, TikTok and Threads pages in your own voice, checks the facts on the web, and posts nothing until a person approves it.
- Comment moderationClarify sorts every comment on your pages as a threat, abuse, spam, misinformation, a question or fine, hides the clear-cut cases if you switch that on, and keeps every decision reversible.
- Media monitoringClarify watches Google News, GDELT and the outlets you add for mentions of you about once an hour, confirms each story is really about you, summarises it and scores its tone.
- Publishing with approvalsClarify schedules posts to Facebook, Instagram, TikTok and Threads from one calendar with your diary beside it, drafts them in your voice, and routes every post through an approval queue.
- MPs and candidatesSocial media threat monitoring and comment moderation for MPs, candidates and electorate offices. Clarify logs threats as evidence for police, hides abuse, and drafts replies staff approve.
- Councils and community groupsSocial media threat monitoring and comment moderation for local councils. Clarify keeps abuse and threats out of the feed with the evidence a police report needs, and drafts replies staff approve.
- Small businessClarify reads and sorts the comments on a small business's pages, drafts replies in the owner's voice, hides scams and spam, and schedules posts to every platform from one calendar.
- Sporting clubs, parties and peak bodiesClarify HQ lets a club, party or peak body see when one account is targeting several of its members across their own pages, and work referred cases together. Free for organisations.
- AthletesSocial media threat monitoring for athletes. Clarify reads the comments before they do, hides abuse the moment it lands, logs threats with evidence, and puts a real supporter in every morning brief.
- Creators and influencersClarify sorts a creator's Instagram, TikTok, Threads and Facebook comments, hides spam and abuse, mutes fake accounts, logs threats, and drafts replies to real questions in the creator's voice.
- Threatened on Facebook? How to report itSomeone threatened you on Facebook, Instagram or TikTok: when it is a police matter, how the eSafety Commissioner's adult cyber abuse scheme works, and what evidence to keep.
- Protecting staff from online abuseProtecting the staff who read your social media comments: the psychosocial risk of moderating abuse, what work health and safety law expects, and the practical steps that cut their exposure.
- Threat monitoring for a campaignHow a candidate's team sets up social media threat monitoring in a week, what to log from day one, and how to carry the evidence into the electorate office after polling day.
- Everything Clarify does, on one pageSocial media threat monitoring for Australian public pages: Clarify flags threats and coordinated accounts, keeps the evidence for police or eSafety, and drafts replies you approve.
