Keyboard Shortcuts

Keyboard shortcuts are available for common actions and site navigation.

Skip to content
  • Home Home Home, current page.
  • About
  • Have an account? Log in
benimmo's profile
Ben Nimmo
Ben Nimmo
Ben Nimmo
Verified account
@benimmo

Tweets

Ben NimmoVerified account

@benimmo

Writer, analyst, linguist. Studying security, disinformation, responses to it. Director of Investigations, @Graphika_Inc. RT ≠ endorsement.

United Kingdom
medium.com/dfrlab
Joined July 2009

Tweets

  • © 2019 Twitter
  • About
  • Help Center
  • Terms
  • Privacy policy
  • Cookies
  • Ads info
Ben Nimmo‏Verified account @benimmo

BREAKING: @Facebook just took down over 900 accounts, pages and groups associated with @TheBLcom and Epoch Media Group. Report from @Graphika_NYC and @DFRLab coming shortly.https://about.fb.com/news/2019/12/removing-coordinated-inauthentic-behavior-from-georgia-vietnam-and-the-us/…

10:27 AM - 20 Dec 2019
  • 381 Retweets
  • 530 Likes
  • Gary Machado Darryll Colthrust Linda Richmond 🆘🍑🌊🇺🇸 Constitution Whisperer Paavo Alander Lotta Hietaniemi ross buck Resisting Grinch Face Vilma Lahti
20 replies 381 retweets 530 likes
    1. New conversation
    2. Ben Nimmo‏Verified account @benimmo 13h13 hours ago

      One of the most interesting aspects was the way this network, which we call #OperationFFS, used AI-generated profile pictures. Interesting, but remember: the network sent up many signals of fake behaviour. It takes a lot more than a fake profile pic to hide a fake campaign.pic.twitter.com/fy3Tzj4fqV

      7 replies 95 retweets 135 likes
      Show this thread
    3. Ben Nimmo‏Verified account @benimmo 13h13 hours ago

      (#OperationFFS stands for "Fake Face Swarm", incidentally. Thanks for asking.)pic.twitter.com/IjexRObnAr

      7 replies 33 retweets 99 likes
      Show this thread
    4. Ben Nimmo‏Verified account @benimmo 13h13 hours ago

      There's already been strong reporting on this. H/t @snopes:https://www.snopes.com/news/2019/11/12/bl-fake-profiles/…

      4 replies 38 retweets 96 likes
      Show this thread
    5. Ben Nimmo‏Verified account @benimmo 13h13 hours ago

      And h/t @ExploitingNiche:https://analysis.leadstories.com/3471185-fake-faces-people-Who-Do-Not-Exist-Invade-Facebook-To-Influence-2020-Elections.html…

      2 replies 25 retweets 65 likes
      Show this thread
    6. Ben Nimmo‏Verified account @benimmo 13h13 hours ago

      And here's today's report from @Graphika_NYC and @DFRLab, on #OperationFFS.https://graphika.com/FFS

      1 reply 36 retweets 68 likes
      Show this thread
    7. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      There's a lot in this set: assets around the world in English, Spanish, Chinese, Portuguese, Vietnamese; feelgood content, anti-China content, pro-Trump content. But takedowns are about behaviour not content, so here are a few main points.pic.twitter.com/kQrBeEQDEx

      1 reply 16 retweets 47 likes
      Show this thread
    8. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      A ton of groups and pages - over 80 of them - posed as pro-Trump American patriots. They almost exclusively shared content from TheBL. But page transparency is a great thing. Most of the managers across those pages were in Vietnam.pic.twitter.com/5SCduzJEWG

      1 reply 36 retweets 84 likes
      Show this thread
    9. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      There were groups and pages focused on Taiwan, Hong Kong and China, too. A lot of them were managed by the same admins, grouped into clusters. (H/t @realShawnEib for the mapping.)pic.twitter.com/TmLsOc0LN1

      2 replies 16 retweets 54 likes
      Show this thread
    10. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      And a similar pattern in the US-focused ones. Dense cluster, same admins across lots of different groups.pic.twitter.com/d1hihUIpIB

      1 reply 13 retweets 51 likes
      Show this thread
    11. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      What's interesting in the US groups, which were all variants on a theme of pro-Trump messaging and TheBL content, was the faces of the admins. They were AI-generated. How can you tell? Well, human faces tend to asymmetry. Glasses, not so much.pic.twitter.com/lVIyiNaZG2

      6 replies 65 retweets 127 likes
      Show this thread
    12. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Here's the close-up of the two halves. Spot the difference.pic.twitter.com/5EqVOIEmF0

      1 reply 12 retweets 51 likes
      Show this thread
    13. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Turns out earrings are difficult, too.pic.twitter.com/2Ihw8db488

      2 replies 17 retweets 66 likes
      Show this thread
    14. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Again, here's the closeup. There's no rule that says earrings have to match, of course, but the blurriness and general effect are telling.pic.twitter.com/JbkMWQdhDx

      1 reply 10 retweets 43 likes
      Show this thread
    15. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Perhaps counter-intuitively, backgrounds are even harder, because there's more variation in scenery than there is in faces.pic.twitter.com/mWtwRfjwBt

      2 replies 14 retweets 56 likes
      Show this thread
    16. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Always worth looking at the background on pics like this, in fact.pic.twitter.com/k1aBp9mvL7

      1 reply 9 retweets 41 likes
      Show this thread
    17. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      There were a lot of pics like this. Dozens at least in the accounts we looked at, both admins and members of groups.These are a sample.pic.twitter.com/odJom00GpI

      2 replies 15 retweets 39 likes
      Show this thread
    18. Ben Nimmo‏Verified account @benimmo 12h12 hours ago

      Fun trick that works for now, though I guess the AI will evolve pretty fast: see what happens when you make all 40 opaque and superimpose them. Note how the eyeballs line up? (H/t @conspirator0 and @ZellaQuixote for the idea)pic.twitter.com/tdAIK69C4n

      8 replies 41 retweets 124 likes
      Show this thread
    19. Ben Nimmo‏Verified account @benimmo 11h11 hours ago

      But I'll say again, it takes much more than fake faces to hide a fake operation. There were other indicators of fakeness too. These were all admins on the same group. All uploaded their only profile pics in the space of an hour.pic.twitter.com/sqIG22bjcE

      2 replies 12 retweets 52 likes
      Show this thread
    20. Ben Nimmo‏Verified account @benimmo 11h11 hours ago

      These were the clustered admins on the China-focused assets. Ten admins, all with profile pics taken off the web - often from Vietnamese sites.pic.twitter.com/R4zGGtJNFH

      1 reply 7 retweets 29 likes
      Show this thread
    21. Ben Nimmo‏Verified account @benimmo 11h11 hours ago

      These were another cluster. Note the sources, and...pic.twitter.com/xX7d3ipbHj

      2 replies 5 retweets 25 likes
      Show this thread
    22. Ben Nimmo‏Verified account @benimmo 11h11 hours ago

      ... note how they all uploaded different profile pics at first, in a batch in September, and then changed in a batch on November 4.pic.twitter.com/SslBvRX7fS

      3 replies 6 retweets 31 likes
      Show this thread
    23. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      Here's the coordinated bit in action. Same post from TheBL, different admins, different groups, all in just over an hour.pic.twitter.com/rpduXQErTx

      2 replies 7 retweets 32 likes
      Show this thread
    24. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      Even with AI-generated profile pics, somebody thought it would be a good idea to reuse them.pic.twitter.com/XYAQP888w4

      1 reply 7 retweets 30 likes
      Show this thread
    25. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      It wasn't just activity on Facebook. There were at least some Twitter assets too. Some looked like spam retweeters, amplifying posts from @TheBLcom and @TheBLNews. They are no longer with us.pic.twitter.com/4BRCPaQTBI

      1 reply 8 retweets 30 likes
      Show this thread
    26. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      And there was this interesting YouTube channel. It posted three videos, two of them advertising TheBL, the third one showing President Trump insulting journalists. Three videos, 15 responses, 51 subscribers. And 1.8 million views.pic.twitter.com/roFdpQAOxS

      1 reply 8 retweets 26 likes
      Show this thread
    27. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      Oddly, that may not all have been organic.pic.twitter.com/kGySBi8gz2

      1 reply 4 retweets 23 likes
      Show this thread
    28. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      Some of this activity was demonstrably automated, using Postcron on both Facebook and Twitter. Note the profile pic for "Davidson Susan", too.pic.twitter.com/ZnKI3LrxsX

      1 reply 7 retweets 22 likes
      Show this thread
    29. Ben Nimmo‏Verified account @benimmo 10h10 hours ago

      Final thought: multiple layers of research went into this. There's a community building around these issues. We need to keep building it, to make sure future operations get exposed early enough. // Thread ends.

      4 replies 15 retweets 62 likes
      Show this thread
    30. End of conversation
    • © 2019 Twitter
    • About
    • Help Center
    • Terms
    • Privacy policy
    • Cookies
    • Ads info