The Hidden Risk in Your Google Reviews: How Scammers Map Your Social Circle

200+ Articles published
5 IT topics covered
20+ Years of IT expertise
CE+ Cyber Essentials Plus
Share
In This Article
    Speedster IT
    Worried About Cyber Threats?

    Get a free cyber security review and find out where your business is exposed.

    Explore Cyber Security

    A new academic study has found that the reviews you leave online, on Google, Yelp, Amazon or Airbnb, can quietly reveal who your friends, family and colleagues are, even if you have never linked a single social account. Researchers at the University of Texas at Austin’s McCombs School of Business found that an attacker could correctly identify 49% of a user’s real-world social connections using nothing more than patterns in their review activity, while wrongly flagging only 10% of unconnected pairs as linked.

    For most people, that sounds harmless. But for scammers, it is exactly the kind of detail that turns a generic phishing email into a convincing, personalised one, and personalised attacks are far more likely to succeed. It is a pattern our cyber security specialists see often, the most effective phishing attempts rarely look random, they lean on details that feel unnervingly specific. This post explains what the research found, how to spot an attack built this way, and the practical steps you and your team can take to stay one step ahead, alongside the wider employee cyber security training that helps a team recognise it.

    What the Research Found

    Who Ran the Study

    The study, led by Yan Leng at McCombs alongside Yijun Chen, Xiaowen Dong, Junfeng Wu and Guodong Shi, examined 4,299 reviewers across Louisiana and Pennsylvania. Rather than looking at who follows whom, the researchers looked at review length. When two reviewers on the same platform are genuinely connected, a pattern often emerges: one consistently writes longer, more detailed reviews while their contact writes shorter ones, or both settle into a similar length over time.

    What They Found

    That pattern alone was enough to statistically map out real relationships with striking accuracy, all from public review data that most people assume is anonymous or, at worst, tied only to their own profile.

    How Attackers Turn Reviews Into a Map of Your Life

    From Reviews to a Target List

    An attacker does not need your friends list, your contacts, or access to your accounts. All they need is enough public review history to spot the same behavioural patterns the researchers found, then build a believable list of who knows whom. From there, a phishing message can reference a business you actually visited, a purchase you actually made, or a review you actually wrote, all details that make the message far harder to spot as fake.

    Why This Works at Scale

    This matters because of scale. The FBI’s Internet Crime Complaint Center logged close to a million phishing complaints in the United States between 2021 and 2023 alone. Research into phishing economics also shows that returns on a campaign rise sharply with volume, from around 109% at 500 attempts to over 1,000% at 10,000 attempts. Automated techniques like review-mapping are valuable to criminals precisely because they let this kind of targeting happen at scale, without a human having to research each victim individually.

    How to Spot This Kind of Attack

    Warning Signs to Watch For

    Look out for these warning signs:

    • A message referencing a specific review you left, a business you visited, or a purchase you made, sent from someone you do not recognise.
    • An unexpected “account verification” or “loyalty reward” request tied to a business you reviewed, particularly if it arrives shortly after you posted.
    • Personal details in the message, a companion’s name, a specific date, or your neighbourhood, that you only ever mentioned in the review itself and nowhere else.
    • A sudden increase in targeted offers, calls or messages shortly after you leave a particularly detailed review.

    If a message ticks any of these boxes, treat it with the same caution you would apply to any other unsolicited request for personal or financial information. Our guide to the most common social engineering attacks covers the wider tactics criminals use to make a scam feel credible.

    Two Ways to Protect Your Identity When Leaving Reviews

    You do not need to stop leaving reviews altogether. Two practical options exist, depending on how much protection you want.

    Option 1: Change Your Display Name (Keep Your Existing Account)

    If you would rather keep using your main Google account, the simplest fix is changing how your name appears publicly:

    • First name and initial: for example, “Alex M.” or “Sarah K.”
    • A generic alias: built around a hobby or interest, such as “The Coffee Enthusiast” or “Local Foodie”
    • A realistic but invented name: one that shares nothing with your actual identity, such as “Jordan Rivers”

    To change it on Google:

    1. Go to your Google Account settings at google.com
    2. Select Personal info from the menu on the left
    3. Under Basic info, select Name
    4. Update your name or set a nickname, then choose how you would like it to display publicly

    Option 2: Use a Separate “Burner” Account (Highest Level of Protection)

    If you regularly review sensitive places, medical clinics, hotels, or businesses close to home, it is worth setting up a completely separate Google account used only for reviews:

    Work With Speedster IT

    Want IT support that actually works?

    Talk to us about how your IT is supported today, and what a managed IT partner should be taking off your plate.

    Talk to Our Team
    • Zero personal data: use a made-up name and username, with no personal details attached
    • Isolate the risk: avoid linking it to your real phone number or main recovery email where possible, so that even if the account’s review pattern is mapped, all an attacker reaches is an inbox you rarely check, not your real personal or work email

    Further Privacy Settings Worth Checking

    A few extra changes will reduce how much Google publicly broadcasts about you as a reviewer:

    Restrict Your Profile

    On Google Maps, tap your profile icon, go to Your Profile, then Profile Settings, and turn on Restricted Profile. This stops strangers from seeing a full list of every review, photo and place you have posted about in one place.

    Remove Your Profile Photo

    A profile picture is an easy target for reverse-image searches that can trace back to your LinkedIn, Facebook or Instagram. A plain avatar, a landscape image, or no photo at all is safer.

    Watch What You Write

    Avoid naming who you were with (“my husband and I loved this”), specific dates (“we visited last Tuesday for my birthday”), or your exact neighbourhood. Keep the review focused on the business itself.

    Why This Matters for Your Business Too

    What This Means for Your Team

    This is not only a personal concern. Employees who leave reviews on their own accounts, of restaurants, suppliers, competitors, or even your own business, can unintentionally expose details about your organisation’s wider network of contacts and relationships. The same review-mapping technique that targets consumers can be adapted to build a picture of a company’s staff and suppliers, which is exactly the kind of groundwork that precedes a targeted spear-phishing or business email compromise attempt.

    Building Layered Protection

    It is a good reminder that broader cyber security training for employees should cover more than passwords and suspicious attachments. Staff also need to understand how everyday online activity, including the reviews they leave in a personal capacity, can be pieced together by attackers. Pairing that awareness with technical safeguards such as multi-factor authentication and ongoing dark web monitoring gives your business layered protection rather than relying on any single defence.

    Keep Reading

    We take the same approach ourselves. If you leave us a review, we would always encourage applying the same privacy-conscious habits covered here, they cost nothing and take a few minutes to set up.

    If phishing and social engineering are already a concern for your business, our piece on why phishing attacks are surging and how UK businesses are paying the price is a good next read, and our password security guide covers the account-level basics every reviewer, and every employee, should already have in place.

    For a wider review of your organisation’s exposure to social engineering and phishing, get in touch with our cyber security team.

    Ready to Talk?

    Let’s fix this properly.

    Book a free consultation with one of our engineers and find out what better IT support actually looks like.

    Get In Touch