ICYMI … We’re up to 600 signups up for my new 13-week email newsletter, Next Question by Life Story Magic, which launches next week.
It’s a a free, weekly, do-it-yourself life story project. Sound interesting? Subscribe here.
First edition ships next Monday. All the cool kids are doing it!
1 star do not recommend
Let’s talk about the risk of online reviews.
There’s the one we’ve been talking about for years, of course: fakes.
A 4.8-star average backed by thousands of reviews can be enticing, but buyer beware.
A British government report suggests between 11% and 15% of reviews are fake.
Tripadvisor and Trustpilot report figures suggesting that, on their platforms, the rte is probably somewhere between 7.4% and 9%.
My favorite blast from the past in this genre is a classic. Oobah Butler, who apparently made a living writing fake 5-star restaurants reviews, created a Tripadvisor listing for a fake restaurant.
He called it The Shed at Dulwich and stacked it with fake reviews. Eventually, it ranked No. 1 among London restaurants, despite the fact that it didn’t exist.
Now a new study suggests there might be a legitimate risk in writing reviews in the first place. Even the 100% truthful kind.
Writing in the journal Information Systems Research, Yan Leng, an assistant professor of information, risk, and operations management at the McCombs School of Business at the University of Texas at Austin, says patterns in publicly available review activity can help reveal users’ social ties.
That information could make it easier for spear phishers to identify and impersonate people a potential victim knows.
Let’s make sure we define spear phishing. In short, it’s an attempt by a bad actor to get passwords or money by contacting a victim while impersonating someone that victim trusts.
The researchers used public Yelp data covering 4,299 reviewers in Louisiana and Pennsylvania in 2020. On Yelp, both the review texts and the users’ friendship lists were publicly accessible.
That allowed Leng and her colleagues to infer connections from review behavior. Then then compared those presumed connections with the users’ disclosed Yelp friendships.
The connection to online reviews? According to Leng and her fellow researchers, patterns in people’s public reviews—especially patterns involving review length—made it possible to infer which Yelp users were connected, without using their friendship lists as an input.
The most revealing clue was review length.
Some connected users tended to write similarly long reviews. Other connected pairs showed complementary patterns, with one tending to write longer reviews and the other shorter ones.
Across thousands of users, those patterns enabled the model to begin reconstructing the social network.
Inferring connections between online reviewers from patterns in review length might sound a bit dubious, but Leng says her work shows there is a true signal hiding beneath the noise.
In fact, more identified connections mean more potential impersonation attempts—and the study’s model showed that an attacker could identify between 49% and 63% of Yelp reviewers’ social relationships from their activity.
The higher identification rate came with a higher level of false positives—wasted effort, from a scammer’s point of view—but the clear implication is that spear phishing is a numbers game.
For scammers, the return on investment scaled quickly: from 109% for 500 attempts to 1,098% for 10,000 attempts.
Interestingly, Leng’s recommendation isn’t for people like you and me to stop leaving reviews. Instead, it’s all on the platforms.
One of her suggestions: “small, carefully designed random changes to the data before it is released.”
An example would be for a platform to subtly vary a review’s displayed length without changing its meaning, thus blurring the linguistic fingerprint while preserving the usefulness of the underlying reviews.
Short version, in her words: “The platforms need to protect not only what users disclose, but also what others can infer.”
Other things worth knowing …
TechCrunch: The U.S. government is alerting millions of current and former military service members that their personal information was stolen during a months-long breach of Pentagon personnel records. A data breach notification says unauthorized users exploited a security vulnerability in a file-sharing system between October 2025 and mid-July 2026. The breach affects about 2.8 million living people.
AP: A copilot stabbed a captain Wednesday on a flight to Israel before passengers burst into the cockpit and wrestled with the attacker as the plane descended sharply and passengers screamed. The jetliner was stabilized and made an emergency landing in Saudi Arabia. Israeli Prime Minister Benjamin Netanyahu said Saudi Arabia arrested the copilot, who was not identified.
The Independent: Defense Secretary Pete Hegseth delivered a “field manual” filled with transcripts of his own speeches to roughly 600 troops attending his “State of the Force” address in Quantico, Virginia, on Wednesday. “Allow me to lay it out simply for the anti-American losers in our media,” Hegseth said. “The ideological clowns are out. The patriotic cowboys are in, with testosterone testing on top. Diversity is not our strength.”
AOL: President Trump’s controversial taxpayer-funded “public service announcements” are airing on CNN and MS NOW — two of the very networks he has been fighting to ban from the White House. Critics denounced the ads as propaganda and a potential violation of government ethics laws for being overtly political. Several congressional Republicans were among those criticizing them.
Semafor via Yahoo Finance: Overseas visitors to the U.S. are on track to drop by almost two million year-on-year, with even the FIFA Men’s World Cup failing to arrest the decline in tourism. Meanwhile, China is attracting more visitors with its visa-free entry policies, and Japan’s weak currency is drawing a record number of tourists. “We’re the only major country in the world losing visitation,” the head of the U.S. Travel Association said. “It’s mind-boggling.”
NYT: For U.S. passport applicants, the days of tracking down photo booths and waiting in endless lines at the post office are almost over. Starting next year, Americans seeking their first passports will be able to apply entirely online, Secretary of State Marco Rubio announced Tuesday.
NY Post: If you’re planning to cash out in Florida, pack your patience. The Sunshine State is the single worst place in the country to sell a home right now, with a staggering 206,508 homes currently on the market, according to a fresh ranking pitting 48 states against each other on how brutal their markets are for sellers.
Thanks for reading. Photo by Justin Morgan on Unsplash. I wrote about some of this at Inc.com. See you in the comments!
