Marc Owen Jones Profile picture
Aug 2, 2021 24 tweets 11 min read Read on X
[Thread] 1/ Good evening, afternoon, or morning all! Tonight's thread is on #Turkey, and it will be a big one. Many have commented on the massive hashtag "Help Turkey" that rapidly reached 2.5 million tweets today. Read on for an in depth Twitter analysis > #Disinformation
2/ 1st, some brief context. The hashtag "help turkey" involved people calling for international help to combat Turkey's wildfires. Images like the one below were common. The tweet storm prompted reactionary nationalistic hashtags including "Strong Turkey" & "We Dont Need Help"
3/ Some felt the message being generated on the hashtag was designed to make Turkey look weak, incompetent and desperate. This, coupled with the scale of the campaign, suggested a possible influence operation. To be clear though. The hashtag had many real users. See below.
4/ In addition to this, many real people using the hashtag probably do so in good faith, simply because it is quite understandable that one would expect to ask for help during a crisis. Also, the popularity of the hashtag naturally meant others used it to discuss the hashtag
5/ Caveats aside for now. My initial analysis included several stages. Firstly, a network analysis of around 160,000 interactions from around 46000 unique Twitter accounts. The graph below shows how massive the sample was. I will now highlight some likely #manipulation
6/ Pay attention to the circled area. This community in green is interesting for a number of reasons. I resized the nodes (individual accounts) by how much they tweeted on the hashtag. I.e. the more they tweeted, the bigger the node. This is a useful measure because it it shows
7/ those entities that are really passionate about promoting the hashtag. In usual circumstances this could be passionate parties who feel strongly about an issue, or other parties attempting to influence a conversation for whatever purposes. Ordinarily, you'd expect these large
8/ nodes to be more evenly distributed across the network, but this green community is a community with a significant number of nodes using the hashtag a lot. A really interesting finding is that the most active node in the sample, the busiest, if you will, is/was @ege20281770
9/ Now what you'll notice about @ege20281770 is that it has no tweets, even though it was created today (02/08/2021) and tweeted a lot on the 'help turkey' hashtag. Twitter says there is still one tweet, but there are none, meaning the tweets were deleted
10) Now we know from past EPFL research that influence operations in Turkey often use this tactic of deleting tweets after writing on a hashtag. Here the Twitter algorithm reportedly registers the trend, but the account deletes tweets to avoid detection/be repurposed.
11/ With this in mind, if we look deeper into the green community that had a lot of highly active accounts in, we find more unusual things. One of these tactics is handle switching, where users change their Twitter handle. Let's look at Badboy2147. He has a big 15k following...
12/ Watch this video. Badboy2147 actually no longer exists. If you look at the video below, you'll see that his old username is cached. When you click on the link to his account it says 'this account doesn't exist'. Actually it does exist, but it has changed to Badboy353435 🤯
13/ What's more, the old badboy seems to have deleted his tweets about help turkey. This can be seen by trying to look at replies to his account. Also, if you check new badboy's timeline, there are no more 'help turkey' tweets, which presumably have been deleted. #deception
14/ Just to give you another example, here you can see how an account toprakofficial5 changed to jokerqueenn_ . Now within the suspicious green community of around 7400 accounts at least 70 have changed their name or been deleted, and it's still very early on. I'd expect
15/ more to change or be deleted. We've seen this tactic of handle switching elsewhere in the world, including the Gulf. See the linked report for more details. But in the meantime let's move to the next interesting aspect of this. cyber.fsi.stanford.edu/io/news/februa…
16/ A massive aspect of this was the copy pasta. Thousands of accounts tweeting the identical tweet (I won't write it here because it will add to the trend, but you can see it in the video) below.... #Turkey
17/ Now I am not certain of the origins of this tweet, but it was tweeted by what I believe are a lot of Turkish celebrities (see image). As I said before, a lot of the accounts tweeting this message are likely real ppl, inspired by celebrities and others, although what's
18/ not clear is who is telling people to copy and paste the English content as opposed to just retweeting it? Is it possible that people just know to do that? It is also odd that I tracked at least 105,000 instances of these English tweets, including retweets. I managed to
19/ scrape around 35,000 unique instances of this copy and pasted English tweet. In addition to this sheer volume of copy pasta, the peak activity occurred past midnight Turkish time. As you can see from the graph, most activity occurred at around 00.16 - which seems pretty late
20/ Another bizarre aspect of the trend was the copy and pasted multilingual calls translating as "turkey is on fire and needs help". Look at the video below. I managed to scrape thousands of these instances. Again many are replies to other accounts to generate engagement.
21/ Also like so many weird, seemingly manipulated trends, loads of BTS and K Pop fans retweeting this message. I counted around 200 who actually retweeted it. I can't imagine a lot of these are genuine, despite the popularity of Kpop...
22/ Also let's not forget precious nijiko!
23/ Anyway that's enough for today, probably time to go to bed. In sum, there is clearly a lot of manipulation going on 'help turkey'. In addition to being boosted by real people and celebrities, it is being artificially manipulated by what is likely to be thousands of sock
24/ puppet accounts. Exact numbers are hard to determine at the moment but I will try to over the next few days. I will also try and see what's going on on Strong Turkiye as a counter hashtag. Thanks for tuning in everyone. Good night and peace #deception

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Marc Owen Jones

Marc Owen Jones Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @marcowenjones

Oct 15
🧵1/🚨AI is learning Israel's disinformation.

On 13/08, a fake quote attributed to Hamas official Khalil al-Hayya circulated on X:

“The countdown to the next massacre has begun. Next time we will slaughter all the Jews"

It was debunked, but Gemini later stated it as fact > Image
2/ Firstly, this super sus account was the first I could find spreading the rumour on X (7.49 am UK time 13/08). @RonanMark572778 - whoever this 'pilot and physician' is has sent >113k tweets since July 2023. He also has a verified account (rememeber verification = algo boost). Image
3/ The narrative then was picked up on X by other accounts and influencers, changing ever so slightly. Accounts like @FleurHassanN @thevoicetruth1 (lol) got a lot of engagement and 'legitimised' the rumour.

NOTE: Not one of these accounts is providing a source to the quote. Image
Read 15 tweets
Oct 6
🧵🚨1/ This verified X account posing as an American doctor has been spreading pro-Israel propaganda, justifying the killing of journalists, and posting predominantly anti–Sudanese Armed Forces content. The account is fake.>
#disinformation #gazagenocide #Sudan Image
2/ The first clear red flags are the tweets versus creation date ratio.

The account was created in 2009, but has only tweeted 1090 times, and the first of those was on April 2025. This means the account has been appropriated/hacked/bought and its old tweets scrubbed. Image
3/ I located the unique user id of the account. I ran this user id via the botometer archive of bots and it tells me that in February 2023 the account was called 'sitaramks', not 'nate_jone' Image
Read 15 tweets
Oct 6
1/ Propaganda botnet alert! About 50 accounts, tweeting in English & Arabic, have pushed out thousands of posts about #Sudan’s war over the past few months. Almost all certainly using genAI, all pushing a pro-UAE, anti-SAF & anti Muslim (Brotherhood) narrative. #disinformation Image
2/ They all follow the same script:

> Blame Burhan, the Sudanese Armed Forces (SAF) and the Muslim Brotherhood for Sudan’s suffering.
> Praise the UAE for “stability” and “humanitarian aid.”
> Wrap it all in moral language about peace, tolerance, and unity. Image
3/ Much of the phrasing is synthetic: with odd, weird idioms, and em dashes. Classic traces of Chat GPT or another LLM agent. The slogans repeat across accounts:

e.g. “Brotherhood’s Butler”, “Brotherhood in Uniform”, “Ministry of Brotherhood Enforcement”, "Sudan bleeds" Image
Read 14 tweets
May 22
🤖 1/ Ok this is pretty wild. I saw some sus pro-Israel astroturfing activity on a BBCNews Facebook post about aid arriving in Gaza. Lots of Hasbara comments like "Hamas will take the aid". The following 2 identical posts were side by side so I looked into it. #disinformation Image
2/ Specifically I looked at Dean O' Connor. Firstly up, there were two almost identical Dean O'connor pages, both created on consecutive days last week (15 + 16 May). The one that posted is the one on the right. Image
Image
Image
3/ When I reverse image searched the picture I was inundated with dozens of pages from forums about romance scams asking about people using this same picture. A lot of people scammed out of thousands. Someone even asked on Quora about O'Connor! Image
Read 7 tweets
May 15
Macron Cocaine Thread/ - The first 10 hours of the @EmmanuelMacron @Keir_Starmer @ZelenskyyUa Cocaine disinformation.

Seemed to be promoted initially by a few dubious accounts like @Veritiste @SitgesFranck @99percentyouth @SilentlySirs @goddeketal

#disinformation Image
2/ Before being boosted by the right-wing ecosystem and conspiracy accounts e.g. @DineshDSouza @RealAlexJones @CollinRugg. No serious journalists reported this story (because it's absurd). Nonetheless, those tweeting in the first 10 hours generated over 103 million views on X! Image
3/ The boosting of the info by Putin's envoy Kirill Dmitriev was via Alex Jones, who as the above timeline shows - wasn't the first to put it out on X - but the most widely viewed. Image
Read 4 tweets
Apr 29
🚨1/ Fake News Alert: A number of accounts are spreading false information that a church in #Wales was burned down by two Pakistan migrants/muslims. There are other narratives, but this is the dominant one. It is false but has obtained millions of views. some data> #disinfo Image
2/ It is true that a church did burn down. It was set alight by two local teenagers. The South Wales police have tweeted that other rumours circulating are false - they are of course talking about the false info about the ethnicity of the attackers (right). Image
Image
3/ The most shared claim comes from 'RadioEuropes'. This is a 'Dysinfluencer' account - an account that repeatedly spreads false and malicious information - in this case xenophobic and anti-Muslim content. You can see its false tweet garnered over 3.6 million views Image
Read 12 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(