After documenting botnet attack on ProPublica, DFR Lab faced its own attack from bots and impersonators, who use follows, likes, retweets to intimidate users
Twitter bots unleashed in a social media disruption tactic Tweets: Dave Zatz / @davezatz : Twitter should be able to programatically remove or restrict these nuisance accounts... Also still waiting on that ‘edit tweet’ button. http://twitter.com/... Hunter Walk / @hunterwalk : Twitter's inability to police bot abuse more effectively drives me nuts. And has real consequences. http://twitter.com/... @briankrebs : Twitter bots use likes, RTs in bid to intimidate journalists, researchers investigating Twitter bot activity http://krebsonsecurity.com/... Julia Angwin / @juliaangwin : Turns out it wasn't just us getting bombarded with Twitter bots last week. Tales from @briankrebs & @josephfcox http://www.thedailybeast.com/ ... http://twitter.com/... Eric Umansky / @ericuman : The weirdness continues. This Russian account tweeted just once: a smear of ProPublica, that somehow got 23k RTs.pic.twitter.com/S4F1lsIJEz @briankrebs : Bring on the bots and sock puppet accounts. Amazing how a tweet about Putin always engenders defensive responses about Trump. @briankrebs : Somehow I have 10k more followers this a.m. Either it was this tweet or someone's trying to get my account banned https://twitter.com/... @briankrebs : Serious question: What can be done (aside from stories in the media) to help Twitter & other social networks do more about bot accounts? See also Mediagazer
Context & Ripple Effects
The pattern here is retaliation against whoever documents it: after Krebs on Security reported that a botnet had been unleashed on ProPublica's reporters — an episode ProPublica itself later detailed in its account of bots and email bombs that forced reporters' email accounts closed — the researchers at DFR Lab who investigated that attack became the next target, hit with waves of bot follows, likes, and retweets designed to intimidate rather than persuade.
What makes the tactic notable is that it weaponizes Twitter's own engagement mechanics: no threats, just manufactured attention from fake accounts. The scale of the underlying problem was quantified a year later when analysis of 14M tweets found bots drove 34% of shares of low-credibility articles while making up only 6% of accounts — and users quoted in this piece, like Hunter Walk and Dave Zatz, point at Twitter's failure to police these accounts programmatically.
First-order effects
- DFR Lab and other journalists and researchers investigating bot activity are directly harassed through mass follows, likes, and retweets from impersonator accounts — intimidation delivered via the platform's own engagement signals.
Second-order effects
- Twitter faces mounting public pressure from high-profile users like Hunter Walk and Dave Zatz to restrict nuisance accounts programmatically, pushing moderation from reactive takedowns toward automated bot detection.
Third-order effects
- If documenting platform abuse reliably triggers platform abuse, independent research into inauthentic behavior gets priced with personal risk — a chilling effect on exactly the watchdog work platforms depend on, and a structural argument for regulators treating coordinated harassment as a platform-integrity issue.
The trend: Platform manipulation is evolving from propaganda at scale to retaliatory harassment of the researchers who expose it, with each documented attack becoming training data for the next.