A sockpuppet is an online identity created to deceive other users about who is speaking. The operator, called the sockmaster or puppeteer, controls the fake account while presenting it as independent rather than an extension of themselves. The name comes from the children's toy: a hand pushed inside a sock and given a voice, the puppeteer hidden from view. Someone speaks through a disguise while the real actor stays concealed.
The practice matters to marketing because it corrupts signals that consumers, search engines, and platforms rely on to judge authenticity. A product with hundreds of five-star reviews or a social account with a large following functions as a proxy for genuine, independent approval. A sockpuppet breaks that proxy, manufacturing the appearance of many voices from what is, in fact, one.
How the deception works
A sockpuppet operation has three components: an identity, a platform, and a purpose. The identity is fabricated or borrowed, with a name, a photograph often generated or scraped from elsewhere, and enough detail to pass a casual glance. The platform is wherever public reputation is measured: a review site, a forum, an encyclopedia, or a social network. The purpose is usually one of a few goals: to praise the puppeteer's own product, attack a competitor, simulate a groundswell of independent opinion, or evade a suspension on the operator's primary account. The logic is simple: if creating an identity is cheap and unverified, one operator can multiply their apparent presence indefinitely.
Execution has industrialised. On the low end, a single person opens several free email addresses and a matching set of social accounts by hand. On the high end, operations documented by HUMAN Security's Satori threat intelligence team in July 2026 run fleets of physical or cloud-hosted mobile devices that register, warm up, and operate accounts convincing enough to pass a platform's trust checks. A single operator could launch such campaigns for as little as 5,000 dollars upfront using an ecosystem the report calls FunFoneFarm, combining phone farms, virtual devices, and AI tools that turn browser-automation scripting into a plain-language request, removing the skill that once gated entry.
The operator is anyone with an incentive to inflate perceived approval: a merchant paying for five-star reviews, an agency seeding forum posts praising a client, or a campaign manufacturing grassroots support, a related but distinct practice called astroturfing. Facing them are the platforms hosting the gamed signal, including Amazon, Google Business Profiles, Meta, and Wikipedia's editor community, each running models trained to spot patterns, such as many new accounts registering in a short window, that a lone genuine user would not produce.
Origin and evolution
The phrase predates the internet. The Oxford English Dictionary traces "sock puppet" to a non-digital sense, a person controlled by another, citing a 2000 example from U.S. News and World Report. Pseudonymous self-review is older still: Walt Whitman and Anthony Burgess both wrote anonymous, flattering reviews of their own books, and Benjamin Franklin used invented correspondents to argue his positions.
The internet-specific sense emerged on Usenet in the 1990s, where the Jargon File defines a sock puppet as a pseudonym a poster uses to follow up their own message and simulate independent support. The term gained mainstream visibility through Wikipedia's struggles with it, whose sock puppetry policy holds that the general expectation is one editor, one account, and that using multiple accounts to deceive or distort consensus is a serious violation. The problem's scale became public in 2015, when the Wikimedia Foundation disclosed that hundreds of accounts tied to a paid-editing ring called Orangemoody had extorted businesses by threatening rejection of draft articles unless they paid for "editing services."
Social platforms formalised their own version under a different name. Facebook, now Meta, introduced the term coordinated inauthentic behavior in an October 2018 blog post, defining it as networks of accounts working together to mislead people about who is behind them, regardless of content. Nathaniel Gleicher, then Facebook's head of cybersecurity policy, described an early enforcement action as the removal of 82 pages, groups, and accounts from Iran targeting the United States and United Kingdom, a framework Meta has since applied to state-linked operations from Russia and Iran, treating the deceptive network structure, not the content, as the violation.
Regulation arrived later, and specifically for commerce. The US Federal Trade Commission's rulemaking on consumer reviews and testimonials, finalised on August 14, 2024, created a federal prohibition covering one flavour of sockpuppetry: the purchase or sale of fake indicators of social media influence. Section 465.8 of the rule, effective October 21, 2024, makes it unlawful to sell or buy followers, views, or likes generated by a bot or fake account where the buyer knew or should have known they were fake, with a maximum civil penalty of 51,744 dollars per violation at finalisation.
Why it matters for marketers
Sockpuppetry intersects with paid media where trust signals double as purchase triggers. Product reviews are the clearest case: a shopper choosing between similarly priced items uses star ratings as a proxy for quality, which is why fake review markets persist despite enforcement. Amazon has pursued fake review brokers through litigation since April 2015, reporting more than 250 million suspected fake reviews blocked before publication by 2023. In October 2024, Amazon and Google filed parallel lawsuits against Bigboostup.com, a site selling fake reviews for both platforms, an unusual instance of two rivals coordinating against the same target.
The advertising side compounds the reviews side. Facebook banned roughly 3.5 billion fake accounts in 2025, and more than 38 billion over the past eight years, according to an analysis published by VAB, the video advertising trade body, a proxy figure that nonetheless establishes scale: fake accounts are a recurring, high-volume enforcement category. They matter to advertisers because ad delivery and targeting assume an account represents a real buyer; when a meaningful share is sockpuppet-controlled, budget goes toward entities that were never going to convert. Reputation management supplies a third front, since a business facing negative coverage can drown it out with fabricated positive sentiment through paid reviews or coordinated social accounts, a practice the FTC's rule addresses through its ban on company-controlled review websites falsely claiming independence.
Limitations and disputes
Detection remains an asymmetric fight. Platforms train models on patterns of inauthentic behaviour, such as synchronised posting times or auto-generated usernames, but operators adapt as soon as a pattern becomes detectable. Cloud-phone services carry a property physical devices lack, malleability, letting an operator change a virtual device's reported identifiers on demand, while some providers add residential proxies and anti-detection browsers that mask multiple accounts from being flagged together. The arms race rarely favours the defender for long, since spinning up a new identity costs far less than proving one is fake, and generative AI has narrowed the labour bottleneck too: a single bot can now sustain hundreds of convincing conversations simultaneously, in any language, letting review-writing and forum-posting sockpuppetry run at a volume no manual process can match.
A persistent dispute concerns where legitimate pseudonymity ends and sockpuppetry begins. Using an alternate identity is not inherently deceptive; anonymous speech carries long-standing protection, and platforms including Wikipedia permit alternate accounts for privacy, provided the operator discloses the connection when it matters. The violation is not a second identity but its use to simulate independence it lacks, a line not always obvious, and enforcement has been criticised as both too aggressive and too permissive. Removal figures describe what was caught, not what got through, and a widely cited estimate placing fake users or bots at roughly 40 percent of measured web traffic is contested by researchers.
Disambiguation
Sockpuppet versus astroturfing. A sockpuppet is an individual fake identity. Astroturfing is the broader campaign that often deploys many sockpuppets to simulate a spontaneous grassroots movement, the coordinated, large-scale version of the same deception.
Sockpuppet versus meatpuppet. Wikipedia and other communities distinguish a sockpuppet, a fake identity controlled by one person, from a meatpuppet, a real person recruited to argue a position without disclosing the relationship. The deception in meatpuppetry lies in hidden coordination between genuine people, not fabricated identity.
Sockpuppet versus Sybil attack. Sybil attack, a term Microsoft researcher John R. Douceur introduced in a 2002 paper, is the general computer science term for any entity presenting multiple false identities to a system, covering peer-to-peer networks and distributed reputation systems broadly. Sockpuppet is the older, more colloquial term for the same behaviour on social platforms and review sites.
Sockpuppet versus bot account. A bot account is typically fully automated and often discloses its nature. A sockpuppet is defined by deceptive intent rather than whether a human or script operates it; an automated account can still function as a sockpuppet if designed to pass as an independent human voice.
Recent developments
The deception has industrialised on the supply side even as detection has industrialised on the platform side. HUMAN Security's broader State of AI Traffic research found automation growing eight times faster than human traffic on the web, complicating enforcement since platforms are simultaneously trying to welcome legitimate AI agents while blocking the fraudulent automation sockpuppetry relies on. Regulatory attention has broadened in parallel. The UK's Competition and Markets Authority secured undertakings from Amazon in June 2025 on fake reviews, using powers under the Digital Markets, Competition and Consumers Act 2024 that classify fake reviews as always unfair regardless of context, letting the regulator fine companies directly rather than only through the courts. In the United States, Google's search spam guidelines added a prohibition on undisclosed incentivised reviews in July 2026, enforced through the same manual-action mechanism the company uses for other spam, extending scrutiny from a review's authenticity to how it was solicited.
Timeline
- 2000: The Oxford English Dictionary's earliest citation for the non-digital sense of "sock puppet," meaning a person controlled by another
- 1990s: The term acquires its internet-specific meaning on Usenet, describing a pseudonym used to simulate independent support for one's own posts
- 2002: Microsoft researcher John R. Douceur publishes "The Sybil Attack," formalising the general computer science concept of one entity presenting multiple false identities to a reputation system
- April 2015: Amazon files its first lawsuit against fake review brokers
- August 31, 2015: The Wikipedia community discovers the Orangemoody paid-editing ring, involving 381 sockpuppet accounts used to extort businesses
- October 2018: Facebook publishes the blog post defining and naming coordinated inauthentic behavior as a distinct enforcement category
- 2020: Amazon reports blocking more than 200 million suspected fake reviews before publication
- November 8, 2022: The FTC publishes an advance notice of proposed rulemaking on consumer reviews and testimonials, including fake indicators of social media influence
- 2023: Amazon pursues legal action against more than 150 individuals and businesses for review abuse across the United States, China, and Europe, and blocks more than 250 million suspected fake reviews
- August 14, 2024: The FTC finalises its rule on consumer reviews and testimonials, including Section 465.8 on fake indicators of social media influence
- October 21, 2024: The FTC's final rule takes effect
- October 28, 2024: Amazon and Google file parallel lawsuits against Bigboostup.com over fake reviews sold across both platforms
- June 2025: The UK Competition and Markets Authority secures undertakings from Amazon on fake reviews under the Digital Markets, Competition and Consumers Act 2024
- July 2026: HUMAN Security's Satori team publishes the FunFoneFarm report, documenting AI-assisted fake account creation at an entry cost of approximately 5,000 dollars
- July 2026: Google adds a search guideline prohibiting undisclosed incentivised reviews
Related PPC Land coverage
- AI cuts scam farm entry cost to $5,000, HUMAN Security research shows - Documents the FunFoneFarm ecosystem, including AI-assisted fake account creation, account warm-up practices, and astroturfed social media accounts sold as an off-the-shelf service.
- Facebook banned 3.5 billion fake accounts in 2025, VAB analysis finds - Reports the scale of Meta's account-removal enforcement and the fraud-strike thresholds advertisers are permitted before a ban.
- Google bans undisclosed incentivized reviews, sites face manual action - Covers the July 2026 search guideline prohibiting fake and undisclosed incentivised reviews and its manual-action enforcement path.
Summary
Who. Sockpuppets are created by individuals, marketing operators, review brokers, and state-linked information operations, and are countered by platform trust-and-safety teams at companies including Amazon, Meta, Google, and the Wikimedia Foundation, alongside regulators such as the US Federal Trade Commission and the UK Competition and Markets Authority.
What. A fake or disguised online identity used to deceive others about who is speaking, most often to inflate apparent support, review a product favourably, evade a ban, or simulate independent grassroots opinion.
When. The non-digital sense of the phrase dates to at least 2000, the internet-specific usage emerged on Usenet during the 1990s, and enforcement has intensified through a series of platform policies and legal actions from 2015 onward, most recently regulatory action from the FTC in 2024 and the UK's Competition and Markets Authority in 2025.
Where. Sockpuppets appear wherever a platform measures reputation through user-generated signals: product review sections, social media account graphs, online encyclopedias, forums, and comment sections.
Why. The practice exists because manufactured consensus is cheaper to produce than genuine consensus, and because marketing, commerce, and public discourse all rely on aggregated signals of independent approval that a single disguised operator can fabricate at scale, a vulnerability that generative AI and phone-farm infrastructure have made significantly cheaper to exploit.
Discussion