Search evidence and expert testimony
Abstract scattered dot illustration representing Fake Reviews and Review Manipulation

IssueReconstructionWhat existed, when, and under whose control?

Fake Reviews and Review Manipulation

Governing authority
16 CFR Part 465, effective 21 October 2024
Question at issue
Which reviews were inauthentic, when they appeared, and who controlled them
Primary evidence
Review timestamps, reviewer histories, archived profile captures, platform notices
When it arises
Competitor and consumer claims, and defense of a review-suppression allegation

A review dispute is a records problem: which reviews existed, when they arrived, and who controlled the accounts

What is actually in dispute

Review litigation looks like a truth dispute and behaves like a records dispute. What decides these matters is rarely whether a sentence about a business is fair. It is which reviews existed, when each arrived, from which accounts, and who had the ability to cause them. That is reconstruction, and it hits a structural obstacle immediately: the record you can see is a filtered, present-tense view of something curated by a non-party.

Three things follow. Reviews removed by the platform, by the reviewer, or in response to a demand are invisible in the current listing, so the surviving set is not the historical set. Timestamps are platform conventions, not a forensic clock. And the account behind a review is outside your view: identity, address, device, and creation date are held by the platform.

An expert who begins from those limits, states them, and reports what the visible record supports will produce an opinion that holds up. One who begins from a conclusion about who wrote what will not.

The federal rule, and the date it started to matter

The FTC's Trade Regulation Rule on the Use of Consumer Reviews and Testimonials is codified at 16 CFR Part 465. It was published in the Federal Register on 22 August 2024, and states its own commencement: "This rule is effective October 21, 2024." The Federal Register notice is the citation.

Those dates do real work. Conduct before 21 October 2024 is not conduct under the rule, and the FTC's older Section 5 authority over deceptive practices is a different theory with different elements. Dating a review cluster is not merely descriptive - it determines which body of law the conduct sits under.

The rule authorizes courts to impose civil penalties for knowing violations, up to $53,088 per violation. That figure comes from the FTC's inflation adjustment effective 17 January 2025 to the penalty under Section 5(m)(1)(A) of the FTC Act, and it did not increase for 2026, the Office of Management and Budget having directed in April 2026 that agencies continue using 2025 levels. Because the penalty runs per violation, the count of affected reviews is the multiplier - and exactly the enumeration an expert is asked to support.

Enforcement so far has included warning letters to businesses using fake reviews and to businesses conditioning incentives on positive reviews, cautioning that continued noncompliance could bring enforcement action and substantial penalties.

What Part 465 prohibits, section by section

The rule is short, and its sections reach conduct businesses do not always recognize as prohibited. The FTC's guidance supplies the descriptions below.

  • Section 465.2 - fake or false consumer reviews and testimonials. Writing, creating, selling, or buying them, and disseminating false testimonials on your own site. Note the boundary: a business is not liable merely for hosting user-submitted reviews it did not create or purchase.
  • Section 465.3 - reuse or repurposing. Reviews of one product presented as reviews of another.
  • Section 465.4 - buying positive or negative reviews. The prohibited act is conditioning an incentive on a review expressing "a particular sentiment": "you can't suggest to consumers that their reviews must be positive (or negative) in order to obtain a promised incentive."
  • Section 465.5 - insider reviews. Reviews by employees, relatives, or agents require clear and conspicuous disclosure, and it must be "unavoidable" - it cannot require clicking a link to be seen.
  • Section 465.6 - company-controlled review websites. Misrepresenting that a site the business controls provides "independent reviews or opinions" about products, including its own.
  • Section 465.7 - review suppression. Using false accusations, threats, intimidation, or an "unfounded or groundless legal threat" to get a negative review removed.
  • Section 465.8 - fake indicators of social media influence. Distributing follower or engagement metrics the distributor "knew or should have known to be fake."

The "knew or should have known" standard is where technical evidence enters. The FTC frames it around red flags, and names two that are measurable from a review corpus: reviews appearing "so quickly after purchase that it's doubtful they reflect real experiences," and "an unusually large number of reviews" in a short timeframe. Those are timestamp analyses, and they are among the few findings an expert can make without platform cooperation.

Platform policy and the federal rule are different standards

These two standards get conflated constantly, and it is the kind of error opposing counsel keeps in reserve.

Google's user-contributed content policy for Maps bars fake engagement, defined as "content that is not based on a real experience or does not accurately represent the location or product in question." It bars "reviews or ratings that have been paid for, directly or in kind" and "content that has been posted from multiple accounts by or at the request of one person." Merchants must not solicit content that does not represent a genuine experience, must not offer incentives "in exchange for posting any review or revision or removal of a negative review," and must not post negative content about competitors "to undermine that business' or product's reputation." The policy text is public.

Read that against Section 465.4. The platform bars incentivized reviews outright; the rule bars conditioning an incentive on a particular sentiment. A business that offered a discount for "an honest review" may have violated the platform policy while remaining outside the rule. A report that treats a policy violation as a rule violation has made a legal characterization it cannot support.

Scale matters too. Google reported for 2025 that it blocked or removed more than 292 million policy-violating reviews, removed more than 13 million fake business profiles, and restricted posting on more than 782,000 accounts. It also sends proactive email alerts to owners about suggested profile changes - dated emails in a client's inbox, and an underused evidence source in profile-hijacking matters.

What detection methodology actually looks at

There is no certified method here, and a report should say so first. What exists is a set of signals, each with a rationale and a failure mode; the strength of an opinion comes from how many independent signals point the same way.

  • Temporal clustering. Timestamps compressed into bursts inconsistent with the business's transaction volume, which the FTC's red-flag framing recognizes as an indicator.
  • Reviewer graph overlap. Accounts reviewing the same set of unrelated businesses, particularly across implausible geographies.
  • Account history. Single-review accounts, accounts created within a narrow window, accounts with no photographs, no other contributions, generic display names.
  • Text characteristics. Near-duplicate phrasing, product names used in forms a customer would not use, absence of specific detail, and repeated template structure.
  • Rating distribution shape. Genuine distributions are typically J-shaped or bimodal. An implausibly smooth one, or an overwhelmingly five-star run arriving in a burst, is not.
  • Geographic implausibility. Location patterns inconsistent with a local service business.
  • Response artifacts. The Google Business Profile API now exposes machine-readable fields on a review reply indicating reply state and policy violation, showing whether the business's replies were moderated or rejected.

The framing I would defend on the stand is narrow: a defined set of reviews exhibits a stated number of independent characteristics inconsistent with organic accumulation, each with its own basis and limitation, and the combination is unlikely to have arisen by chance. Not that any individual review is false.

What the public record hides

Six limitations, all of which belong in a report rather than waiting to be asked about.

  1. You cannot see the account. Reviewer identity, IP address, device, and creation date are held by the platform. Without third-party discovery you reason from a public surface designed for shoppers, not investigators.
  2. The removed reviews are invisible. If the platform already removed suspected fakes, the surviving record understates the manipulation; if it removed legitimate ones, the record overstates it. With 292 million removals in a year, the public dataset is filtered and the filter is undocumented.
  3. The base rates are unknown. No published, validated false-positive rate exists for any signal above, which goes directly to the error-rate factor a court will ask about.
  4. Timestamps are platform conventions. An edited review may carry the original date or the edit date, and the display does not always say which.
  5. Dataset provenance will be questioned. Scraping may violate a platform's terms, and Google classifies automated querying of Google as machine-generated traffic, a spam policy violation.
  6. Attribution is the hardest step. Showing a cluster is inauthentic is one opinion; showing a specific defendant caused it is a different and usually weaker one. Separate them explicitly and say which the evidence reaches.

Suppression as a separate claim

Section 465.7 reaches the other direction: false accusations, threats, intimidation, or an unfounded or groundless legal threat used to remove a negative review. Google's policy separately bars incentives offered for the revision or removal of one. A business that leaned on unhappy customers has exposure under both, on different theories.

The evidence here is documentary rather than technical: demand letters, platform removal notices, settlement agreements with review-removal clauses, and, through discovery, the platform's record of which removals a legal complaint prompted. The technical contribution is narrow - establishing that a review existed, that it later did not, and when it stopped appearing - through archived captures, dated notification emails, and contemporaneous exports.

This is also the part of a review matter that expires fastest. Listings are not comprehensively archived, notification emails get deleted, and nobody exports a review page until it is evidence.

Where these opinions fail

The recurring failures are consistent enough to list.

Opining on a single review. The signals here are population-level. An opinion that one review is fake asks the method to do something it never could, and Rule 702(d)'s requirement that the opinion reflect a reliable application of the method to the facts is where that fails.

Sliding from pattern to attribution. "These reviews are inauthentic" and "the defendant procured them" are two opinions with two evidentiary bases. Merging them is the most common overreach here, and usually unnecessary, because the pattern opinion plus the documentary record often gets counsel where they need to go.

Treating the visible listing as the record. Without archived captures and the client's own notifications, an expert describes what survived moderation and calls it what happened.

Conflating platform policy with the federal rule. A self-inflicted wound.

Unstated collection methodology. How the corpus was gathered, on what dates, with what tool, and under what terms will be asked. Document it as you collect - collection is the one part of this work that cannot be redone.

Frequently Asked Questions

When did the FTC's fake review rule take effect?

The Trade Regulation Rule on the Use of Consumer Reviews and Testimonials, codified at 16 CFR Part 465, was published in the Federal Register on 22 August 2024, and the rule states that it is effective 21 October 2024. Both dates matter in a matter with conduct spanning that window, because conduct before the effective date is not conduct under the rule. Earlier conduct may still be reachable under the FTC's general authority over deceptive acts and practices, but that is a different theory with different elements.

What is the civil penalty for violating the FTC review rule?

The rule authorizes courts to impose civil penalties for knowing violations, and the current maximum is $53,088 per violation. That figure comes from the FTC's inflation adjustment effective 17 January 2025 to the penalty under Section 5(m)(1)(A) of the FTC Act. It did not increase for 2026, because the Office of Management and Budget directed in April 2026 that agencies continue using 2025 penalty levels. Because the penalty runs per violation, the number of affected reviews or postings drives the exposure, which is why the count is contested.

Can a business be liable for fake reviews it did not write?

Under Section 465.2 a business is not liable merely for hosting user-submitted reviews it did not create or purchase. Liability attaches to writing, creating, selling, buying, or disseminating fake reviews and testimonials. Separate provisions reach related conduct: conditioning incentives on a particular sentiment, failing to disclose insider reviews from employees or relatives, presenting a company-controlled site as independent, and distributing engagement metrics the distributor knew or should have known were fake. Whether particular facts fall inside any of those is a question for counsel.

Can an expert prove that a specific review is fake?

Not reliably, and an opinion framed that way is vulnerable. The available signals - timing clusters, reviewer account histories, overlapping reviewer graphs, text similarity, rating distribution shape, geographic implausibility - are population-level indicators with no published, validated false-positive rate. The defensible opinion is that a defined set of reviews exhibits several independent characteristics inconsistent with organic accumulation, each stated with its own basis and limitation. Identifying which individual reviews are inauthentic generally requires account-level data that only the platform holds.

Is offering a discount in exchange for a review illegal?

The federal rule and the platform policy answer differently, and the difference matters. Section 465.4 prohibits conditioning an incentive on a review expressing a particular sentiment - the FTC's phrasing is that you cannot suggest reviews must be positive or negative to obtain a promised incentive. Google's Maps content policy is broader and bars incentivized reviews outright, including reviews paid for directly or in kind. So conduct can violate the platform policy while sitting outside the rule. Treating the two as one standard is a mistake opposing counsel will exploit.

How do you prove a negative review existed and was later removed?

Through dated evidence created at the time, because the current listing shows only what survived. The usable sources are archived captures of the review page, the business's own dated notification emails from the platform, any exports or screenshots taken contemporaneously, the reviewer's own copy if the reviewer is available, and, through third-party discovery, the platform's record of the removal and what prompted it. None of this is preserved by default. Preservation instructions should go out before anyone decides whether there is a claim worth filing.

What discovery is needed to prove review manipulation?

The material that matters sits with non-parties. From the platform: account creation dates, IP and device identifiers, posting histories, moderation and removal records, and the reasons for any removals. From the opposing party: contracts with reputation or marketing vendors, payment records, communications about reviews, customer contact lists used for solicitation campaigns, and any templates or scripts. From a vendor, if one is identified: the account inventory and the posting schedule. Public review data supports pattern findings; attribution to a party generally does not survive without the records above.
Keep reading

Read the guides

An entry states what a rule requires or what a dispute turns on. A guide walks the sequence — what you do, in what order, before the evidence is gone.

Top