Graphika
Research Reports/The Case of the Inauthentic Reposting Activists
GatedOct 27, 2020

The Case of the Inauthentic Reposting Activists

On October 27, Facebook took down a small network of inauthentic accounts, mostly on Instagram, that posted political, activist, and engaging content about the United States in Spanish and English. The network was operated by people from Mexico and Venezuela. Neither Facebook nor Graphika at this stage is able to pinpoint the operator of this network with enough confidence to share an attribution. This report highlights the tactics and narratives shared by the inauthentic pages and notes that s

Trust & SafetyInfluence Operations
Ben Nimmo, Camille François, C. Shawn Eib & Léa Ronzaud
Graphika Research
Share
Free Download

Access the Full Report

Get the complete findings from Graphika's latest research, including in-depth network analysis, narrative mapping, and intelligence across platforms.

By submitting this form, you agree to receive communications from Graphika.

The network began posting in Spanish in April and added its first English-language accounts in July. It focused on a handful of core themes, primarily in the United States: Latinx identity and pride, the Black Lives Matter (BLM) movement, uplifting and positive-thinking content, gender equality, LGBTQIA+ rights and the environment. The English-language content focused primarily on feminism and BLM. Very few posts referenced the impending U.S. election. A small number of the memes and images used in this campaign were previously used in Instagram-centric operations run by the Russian Internet Research Agency (IRA), but this is insufficient to attribute the activity.

Facebook said that it “began this investigation based on information about this network’s off-platform activity from the FBI.” In its statement announcing the takedown, it wrote that some of the people behind the activity appeared to be unwitting accomplices, but that the operation as a whole tried to conceal its coordination and “used fake accounts to create fictitious personas and post content.” This included some people claiming to work for a Poland-linked firm called “Social CMS” that did not appear to exist.

“Some of these accounts posed as Americans supporting various social and political causes and tried to contact others to amplify this operation’s content,” Facebook’s statement said.

Influence operations have been known to use unwitting accomplices in recent years: the IRA for instance has operated through unwitting accomplices in at least three operations focused on the U.S. 2020 presidential election in the past year. They are documented in the following Graphika reports: Double Deceit, Unlucky 13 and Step Into My Parler.

The network had mixed success in building an audience. The most followed account, which mainly posted “Latinx life” humor and feel-good memes, had just over 14,000 followers when it was taken down. This was double the following of the next most popular account, which also posted humorous memes. Of the 22 Instagram accounts in the set, 15 had under 2,000 followers each. The operation appeared to still be in audience-building mode when it was taken down: it did not systematically promote a specific political message, but posted engaging and/or divisive content and invited users to react.

Written By

Ben Nimmo

Head of Investigations

Ben Nimmo was Head of Investigations at Graphika, where he led an expert team of OSINT investigators in detecting, identifying and analyzing inauthentic behavior and information operations online. He specializes in analyzing patterns of online disinformation and influence operations across varying platforms and geographical regions. He is now the Principal Investigator, Intelligence & Investigations at OpenAI.

Camille François

Chief Innovation Officer

Camille François works on cyber conflict and digital rights online. She was the Chief Innovation Officer at Graphika, where she led the company’s work to detect and mitigate disinformation, media manipulation and harassment.

C. Shawn Eib

Analyst

Léa Ronzaud

Senior Analyst

Léa Ronzaud leads monitoring and investigations into the detection and tracking of Russian influence operations and violent extremist groups. She also researches nihilistic violent extremism and hacktivism. Léa’s work has helped disrupt efforts by extremists in multiple countries to orchestrate real-world harm and exposed the inner workings of nation-state influence operations from Russia, China, and Iran.

Full Report

Download the complete PDF

The full report includes the complete network graph maps, raw attribution indicators, cross-platform topology analysis, and the full takedown timeline with platform-level data.

  • Full network graph visualizations
  • Attribution indicators with confidence scores
  • Raw behavioral modeling data
  • Takedown coordination timeline
Free Download

Access the Full Report

Get the complete findings from Graphika's latest research, including in-depth network analysis, narrative mapping, and intelligence across platforms.

By submitting this form, you agree to receive communications from Graphika.

Act on This Intelligence

See How Graphika Can Help Your Team Act on This Intelligence

This report is one of 600+ investigations Graphika’s team has published. Our platform gives your analysts continuous access to the same intelligence — plus the tools to apply it to your specific threat environment.

60+ government agencies briefed
Used by NATO and EU Parliament
Contributed to 200+ platform takedowns