On the surface, posting online reviews looks like a win-win activity. It helps both businesses we like and people who might frequent them.
But although posting reviews can benefit others, it can also put us all at risk, according to new research from the McCombs School of Business at The University of Texas at Austin. It can inadvertently expose our personal connections and make us and our online friends more vulnerable to cyberattacks.
The research focuses on a particular kind of email attack called spear phishing. A bad actor impersonates someone the target user trusts. The actor tries to trick the target into sending money or disclosing confidential information, such as passwords or bank accounts.
In recent years, phishing has become big business, says Yan Leng , assistant professor of information, risk, and operations management at McCombs. From 2021 to 2023, she reports, the FBI’s Internet Crime Complaint Center received nearly 1 million complaints involving $305 million in losses.
“Social influence is a good thing,” Leng says. “The problem is that network data could be leaked.”
By network data, Leng means information about our social relationships with people we’re connected to online. They can be on social platforms such as Facebook and review platforms such as Amazon, Google, or Airbnb.
Unlike Facebook, most review platforms don’t list a person’s friends. But Leng suspected that a phisher could figure out someone’s friends from their online behavior, such as reviews they wrote and ratings they provided.
She investigated, with Yijun Chen of the University of Melbourne; Xiaowen Dong of the University of Oxford; Junfeng Wu of the Chinese University of Hong Kong, Shenzhen; and
Guodong Shi of the University of Sydney.
The researchers used the business review platform Yelp and covered 4,299 reviewers from Louisiana and Pennsylvania in 2020. On Yelp, unlike many review platforms, both texts of reviews and lists of friends were publicly accessible.
That allowed Leng to cross-check her work. First, she analyzed people’s reviews to deduce their networks of connections with other users, as a cyber-attacker might do. Then, she compared those presumed connections with their actual lists of friends.
She found that an attacker could correctly identify 49% of users’ social relationships purely from their online behavior, while incorrectly labeling only 10% of unconnected pairs as connected. When that false-alarm rate rose to 20%, an attacker could correctly identify even more relationships: up to 63%.
Why? The most salient clue was the lengths of Yelp reviews. When two people follow each other, Leng found, there’s an observable relationship between the lengths of their reviews.
If my friend writes longer reviews on Yelp, she explains, I follow suit and also write longer reviews. Another kind of relationship is that, if my friend writes longer reviews, I write only a short review, which can complement theirs.
Once a spear phisher infers a user’s relationships on Yelp, they can send scam texts or emails to that person’s friends, Leng says.
Volume matters, she adds. The more connections a scammer can identify, the more impersonation attempts they can make, and the higher their returns on the costs of targeting and sending emails. For the Pennsylvania data, returns soared from 109% for 500 attempts to 1,098% for 10,000 attempts.
Unfortunately, Leng says, existing privacy laws, such as the European Union’s General Data Protection Regulation, don’t fully protect against this kind of privacy risk. Even if a platform doesn’t publish users’ friend lists, bad actors can infer them from seemingly harmless behavioral data.
To start with, platforms should evaluate whether they’re creating this type of risk, she says. Besides review platforms, e-commerce marketplaces and media-sharing platforms can be vulnerable.
Then, they should develop safeguards to reduce risk. One strategy, she suggests, is to add noise, which she defines as “small, carefully designed random changes to the data before it is released.”
A platform could subtly alter the text of reviews, to vary their lengths without changing their meanings, she explains. That could blur the behavioral fingerprints that reveal relationships without making the data useless for the platform’s own analytics.
In simulations, the researchers found the strategy reduced economic incentives for cyber-attackers, sometimes even making returns negative.
How much noise to add could be a challenge, she cautions. Each platform could choose a privacy budget, based on how much information it needs to retain and how much social privacy risk it is willing to accept.
One thing is clear to her: The current level of privacy risk is unacceptable. Says Leng, “The platforms need to protect not only what users disclose, but also what others can infer.”
“ When Behavioral Data Betray Users: A Diagnostic and Protective Framework Against Social Interaction Leakages ” is published in Information Systems Research.
Information Systems Research
When Behavioral Data Betray Users: A Diagnostic and Protective Framework Against Social Interaction Leakages
28-May-2026