How does Vetric help defenders spot a network of people who do not exist?

September 16, 2026
#
 min read
Omer Bachar
CEO and Co-Founder
See Vetric for yourselfSchedule a chat with an expert from our team to see how Vetric can work for your business.
Book an intro call

Anthropic published its September threat report last week, and two cases in it describe the same shift from different angles. A French advertising agency ran roughly 70 fabricated news websites with 70 matching X accounts and more than 250 inauthentic commenting accounts behind them, publishing at least 8,913 articles in about 20 languages and shifting its political position to suit whichever client was paying. An Istanbul technology company operated over 1,000 fake X accounts aimed at Malaysian voters, and fielded a request for one million artificial views on the prime minister's account.

What stayed with me was smaller than any of the numbers, because the fake reporters had faces: AI-generated profile photos, invented biographies, and fabricated spokespeople quoted in articles that nobody wrote.

It is worth being specific about who that lands on. The Malaysian operation worked from census and electoral records to target race, religion and royalty across all 222 parliamentary constituencies, and it ran a fabricated outlet called Malaysia Pulse to carry the material. A voter who read one of those stories had no way of knowing the outlet existed to reach him, or that the reporter whose face sat above the byline had never existed at all. What he was misled about was how many of his countrymen believed a thing, and that is close to the only thing an election is built to measure.

Fraud has a number attached to it, because someone lost a sum and it can be counted. A population that has quietly recalibrated what it believes its neighbors think has no such number, and it could be that the damage from these operations only becomes visible years later, in turnout, in trust, in which institutions people stop bothering to argue with. That uncertainty is a reason to treat the assembly stage seriously rather than a reason to wait.

A convincing stranger used to be expensive

For most of the internet's life, a persuasive fake person cost real money, because someone had to write the biography, source a photograph that would survive a reverse image search, keep the posting history warm, and answer when a real person replied. That cost is what held influence operations to a size defenders could see. Ten personas needed a team. A thousand needed a government.

Generative models removed that cost line by line, so the photograph is free, the biography is free, and the twentieth language is free. An operation that sells influence as a service and swaps its politics to suit the client is only possible once producing a position costs nothing.

The fake has to live somewhere

While a fabricated person is useless in private, it becomes worth something once it has a profile, a follower graph, replies, and an audience that has already gathered somewhere. Social platforms are where these operations get built, which makes them the place where the building can be seen.

Anthropic notes that most of the operations it disrupted never reached an authentic audience, because they were caught mid-assembly. That is the part worth holding onto, since accounts get registered before they post, networks accumulate followers before they matter, and sites publish into an empty room for months to earn enough history to look old. The gap between a network existing and a network working is where defense actually happens.

Defenders get the same multiplier, on one condition

"Sophisticated attacks no longer require sophisticated attackers," the report says, and it earns that line on the cyber side of the research, where one individual reached inside at least 14 of the 42 organizations he went after and another group produced more than a dozen possible zero-day findings in a single month. The same collapse is what put a thousand personas within reach of an advertising agency, because the labor that used to separate a hobbyist from a state team was the same labor in both places.

The reverse of that line holds too, and a trust and safety team of six can now reason across a million accounts, but only on one condition, because a model reasons only over what reaches it. An analyst who used to review 50 profiles a day and now reviews 50,000 has gained nothing if the network was assembled on a platform their tooling never touches. AI raised the ceiling on what defenders can process, but it left the floor exactly where it was, at what they can see.

How Vetric helps defenders see a network while it is still being built

An analyst about to tell a platform that 400 accounts are one network has to be able to show why, because a signal an analyst cannot trace is a signal an analyst will not act on, and at this volume the tracing is most of the job.

Showing why means seeing the places where personas get built and rehearsed, and that visibility is the layer Vetric supplies to the platforms and teams doing the work. Four things tend to give a network away, for example:

  • The same face and the same words, in a lot of places. Nobody producing a thousand profiles writes a thousand biographies, so the photo repeats, the phrasing repeats, and it repeats across platforms, including the small ones where a network can be built quietly while the attention sits elsewhere.
  • Who follows whom. One account looks like a person, but four hundred accounts that opened in the same period and mostly follow each other look like one thing, and that is what turns a list of profiles into a network.
  • How an account behaves over time. Real people post unevenly, going quiet for a week, arguing at midnight, disappearing on holiday. A persona that was manufactured rather than lived tends to have a history that begins all at once, or a rhythm too even to be a life.
  • Where the claim showed up first. Take one allegation and find the first place it appeared, which is often a small site or a closed channel, weeks before the version anyone noticed. It gives a team early warning, and it shows the story was planted rather than grown.

The first three point at who is behind it, and the fourth at when it started.

While the scoring, the attribution, the evidence pack, the takedown request and the decision to act belong to the teams that own them, Vetric's part is making sure the ground they work with is the ground the adversary actually used.

The window is still open

Every operation in that report was assembled in public before it was aimed at anyone, with accounts sitting idle, sites publishing to nobody, and personas building a history because a history is what makes them work. That preparation is a cost the attacker still pays, and it is the one advantage on the defending side that AI did not erase.

Seeing it in time is a solvable problem, and it is the part Vetric intends to keep solving.