Twitter (now X) is an important tool for social discourse, but what happens when the “person” tweeting is actually a bot? In the early 2010s, investigations by ICSI researchers – along with collaborators from UC Berkeley, George Mason University, and Twitter – unearthed a vast marketplace for usernames that could be exploited to send spam or disrupt genuine conversations. The work led Twitter to successfully suspend millions of fraudulent accounts. 

It all started with Russia’s 2011 parliamentary elections, when hashtags used to organize protests related to the elections were being flooded with spam. UC Berkeley PhD student Kurt Thomas and colleagues analyzed 2.4 million spam tweets, which were generated at a staggering rate of 1,846 posts per minute at their peak, surrounding a particular protest in Moscow’s Triumfalnaya Square. They traced the spam associated with this protest alone to over 25,000 accounts using machines around the globe. In a second study, the team dug deeper into the vendors who generate and sell fake Twitter accounts. With Twitter’s permission, the researchers purchased hundreds of thousands of fake Twitter accounts from over two dozen merchants, which they used to develop a classifier to detect fraudulent accounts sold online. Based on the ICSI research team’s findings, Twitter disabled millions of accounts, representing 95% of the usernames generated by the 27 merchants studied.

This story was published in January 2026 as part of a retrospective series highlighting ICSI’s accomplishments and impacts over the years. To learn about our ongoing work, explore our Core Research Themes.