What a review bombing campaign actually is
A review bomb is a burst of reviews posted not to describe an experience but to move a number. In the local-business version, a third party posts — or pays other people to post — one-star reviews of a business they never bought anything from, in enough volume to visibly drag the star average down.
Three terms are worth separating before anything else, because owners use them interchangeably and they behave differently. A review is a single public rating, usually with text, attached to a business listing. The rating is the star average those reviews produce, and it is the thing a searcher actually sees. The profile is the Google Business Profile that renders both in the local pack, on Maps, and in the knowledge panel beside a search for the business name. An attack on the reviews is aimed at the rating; the damage arrives through the profile.
Google's own policy vocabulary for this is fake engagement — "content that is not based on a real experience" — and rating manipulation, both named categories in the Prohibited and restricted content policy that governs Maps user-generated content. Naming the right category matters later, so it is worth knowing now.
Two motives sit behind the same mechanic, and the remedy differs:
- Competitive suppression. A rival tries to push the rating below the point at which a searcher will click. The target is your conversion rate.
- Review extortion. The attacker bombs the profile and then demands payment to make it stop. Google publicly confirmed this pattern and said it had built detection for it in April 2026. This is not an SEO problem. It is an extortion problem, and it should be handled as one from the first hour.
Three neighboring things get called review attacks and are not. Review gating — soliciting feedback only from customers who say they are happy — is a violation the business commits against itself. Review hijacking is a marketplace problem, where reviews are moved onto a different product listing. And a complaint page ranking for your brand name is a reputation problem on the search results page, not a rating problem on your listing.
The finding that explains why reporting feels useless
Start with the uncomfortable statistic, because it reframes everything a victim is told to do.
The only analysis of deleted Google reviews with a stated dataset and period is a study published by the local SEO software company Localo, which reports analyzing 335,520 deleted Google reviews across 22,292 Business Profiles, removed between November 2023 and January 2026. Its headline finding is that 89.1 percent of those deleted reviews were five-star.
Read that again. Google's review-removal machinery is overwhelmingly catching fake positive reviews — businesses inflating their own ratings — which is also exactly where the Federal Trade Commission's enforcement history points. A business being bombed with one-stars is a minority case inside a system built around the opposite problem. Nobody tells owners this, and it is the single best explanation for why the reporting process feels unresponsive when you are the one being attacked.
Two caveats belong with the number, and I would not print it without them. Localo sells review management and audit tooling, so it has a commercial interest in the subject, and its sampling method is only partly disclosed. More importantly, this is a study of reviews that were deleted. It has a denominator, but the wrong one: it cannot tell you what share of reported reviews get removed, and it does not separate removals Google initiated on its own from removals that followed an owner's report. Treat the 89.1 percent as a strong indication of where the enforcement effort is pointed, not as an established fact about your odds.
The same analysis of deleted Google reviews reports a median lifetime of 60 days before a review is deleted, with 34.7 percent removed within ten days, and it reports that nearly 30 percent of removal events were batch deletions. Google's own guidance is that assessing a reported review "typically takes several days". Put those together and you get the honest timeline: think in weeks, plan for two months, and do not build a recovery around removal happening quickly. The batch-deletion figure carries a practical instruction too — Google removes coordinated clusters as clusters, so the pattern is the thing to describe.
The scale is real, and Google publishes the numbers
Whatever the removal queue is prioritizing, the behavior itself is industrial. In its April 2026 post on protecting businesses on Maps, Google states that in 2025 it blocked or removed over 292 million policy-violating reviews, blocked 79 million inaccurate or unverified edits, restricted more than 782,000 policy-violating accounts, and removed over 13 million fake Business Profiles. The equivalent 2024 figures, from Google's April 2025 post, were 240 million reviews, 70 million edits, 12 million fake profiles and 900,000 restricted accounts.
Those numbers cut both ways, and a reference that quotes only one direction is selling something. They prove the attack is common. They also prove Google catches an enormous amount of it automatically, which is why a well-established profile usually survives a burst of fake one-stars with its rating essentially intact. And they are unaudited: Google publishes no methodology, no definition of "policy-violating", and no false-positive rate, so they are strong evidence of scale and weak evidence of accuracy.
The April 2026 post also describes a defensive behavior a victim needs to recognize. When Google detects a spike of policy-violating reviews on a profile, it removes the offending content, pauses new reviews on that profile, alerts the owner, and may display a banner to consumers noting suspicious activity. If your profile abruptly stops accepting reviews during an attack, that is Google's mitigation firing — not a further stage of the attack. Whether the consumer-facing banner helps you is genuinely unclear and arguably cuts against you, since a customer reading it cannot tell the victim from the perpetrator.
One more change matters and is easy to miss: Google said in April 2025 that it had begun to revisit reviews more frequently to identify new abuse patterns "even months after they were originally posted". Fake reviews that survive the initial filter can still be removed retroactively. "Nothing happened when I reported it" is not the end of the story.
Certain damage to conversion, unproven damage to ranking
This is where most writing on the subject overclaims, so here is the boundary drawn as precisely as the evidence allows.
Google's guidance on improving local ranking defines prominence as being "based on info like how many websites link to your business and how many reviews you have", and states flatly that "More reviews and positive ratings can help your business's local ranking." That is Google, in its own documentation, saying reviews are a local ranking input. It is real and it should not be waved away.
What Google does not say, anywhere, is how heavily reviews weigh, whether the weight sits on the count or on the score, or whether a fall from 4.8 to 4.2 moves anything at all in the local pack. It is entirely consistent with Google's wording that review count contributes to prominence while review score mainly governs whether a searcher clicks. Practitioner surveys of local ranking factors consistently place review signals below proximity, primary category and profile completeness — but those surveys aggregate opinion, not measurement, and should be labeled that way every time they are used.
So the defensible statement is narrow: a fake-review attack reliably damages conversion, the click and call rate from a listing whose stars have visibly fallen, and may have a smaller, unquantified effect on ranking. Nobody outside Google has published a controlled experiment isolating star rating from review count, category and proximity. Anyone who gives you a percentage for the ranking effect is guessing, and anyone who tells you removal will restore a lost position is guessing twice — whether ranking recovers after removal, and how fast, has never been publicly measured either.
The arithmetic decides how much trouble you are in
Before doing anything else, do the division. It determines whether this is an emergency or an annoyance, and most owners skip it because panic is faster than a calculator.
A profile with 11 reviews averaging 4.9 falls to roughly 3.1 when nine fake one-stars land — 53.9 existing star-points plus nine, over 20 reviews. That is best-in-pack to visibly mediocre inside a week, and every customer who looks you up during that week sees it. The identical nine one-stars against several hundred genuine reviews move the average by hundredths of a star and are functionally invisible.
Review volume is therefore the single best defense available against this attack, and it is the only one that has to be built before the attack. It is also the reason the conditions under which review bombing still works are specific rather than general:
- Low review counts, where the arithmetic does the attacker's work for them.
- New or recently verified profiles, where Google has no behavioral baseline for the listing and no history of legitimate reviewers to compare against.
- Platforms with weaker filtering than Google — smaller directories, niche industry review sites, complaint-style sites — where a handful of entries can dominate a search for your brand name even though your Google stars never moved.
- Regulated and high-trust sectors — medical, legal, childcare, anything that involves entering a customer's home — where one credible-sounding fabricated safety allegation does damage no star average captures.
If you are a well-reviewed business with a long history, the honest advice is that you are largely self-defending. Report the reviews, because it is free, and then go back to work.
Telling an attack from a bad week
Look at pattern, not at content. One harsh review is a customer. Twelve in four days is an event.
- Velocity against your own baseline. The signature is a step change: months at nought to two reviews a week, then eight to fifteen negatives inside 72 hours. Sorting your reviews by newest shows this in about a minute.
- Reviewer account history. Click through each one. The tells are an account created recently, a single contribution, no photographs, or a scattered history of reviews in places the account cannot plausibly have visited in that timeframe.
- A described transaction that cannot have happened. No appointment, no order, a service you do not offer, a staff member who does not exist, an incident on a day you were closed. This is the most useful evidence you can gather, because it maps directly onto Google's fake engagement category rather than onto your opinion of fairness.
- Textual homogeneity. Repeated phrasing, the same misspelling, the same sentence shape across supposedly unrelated reviewers.
- Rating-only bombs. A cluster of bare star ratings with no text is common and harder to argue on content grounds. Report the cluster, not the wording.
- Cross-platform timing. Check the other review surfaces the same hour. A matching timestamp cluster on two independent platforms is far stronger evidence than anything on one.
What it is mistaken for. A genuine service failure that produced a real cluster of angry customers — a bad shipment, a staffing change, a price rise, a news story. Before calling it an attack, check whether the reviews describe the same real incident. Also consider the aftermath of review gating being switched off, which makes a business's natural negative rate visible for the first time and feels exactly like sabotage; and a local-pack drop caused by proximity, category or a profile edit, which is faster and larger than anything stars do.
What to do, in order, starting this morning
- Do not respond publicly yet. Owner replies to fake reviews are the most common self-inflicted wound on this page. They add text and freshness to the review, they read defensively to every future customer, and an angry reply is sometimes precisely what the attacker wanted. Once the removal route is exhausted, a short factual line — no record of this transaction, this has been reported — is appropriate, written for the next reader rather than for the reviewer.
- Preserve the evidence before it disappears. Screenshot every review with the reviewer name, date and profile visible; save the reviewer profile pages; export your review history. Reviews vanish. Screenshots do not, and if this becomes a legal matter they are the only record that will exist.
- Report each review through the Business Profile reviews management tool, individually, choosing the policy category that actually fits — usually fake engagement or off-topic, never "I disagree".
- Appeal a refusal once, and spend it well. If a report comes back as no policy violation, the same tool offers an appeal covering up to ten reviews. It is documented as a one-time option per review, so appeal with new evidence — the absent transaction record, the account histories, the cluster timeline — not with a restatement of the first submission.
- Describe the pattern, not only the reviews. Dates, count, your normal rate, and the characteristics the accounts share. A cluster is easier to have removed than any single review inside it.
- Run the same process on every other platform in parallel. Google's outcome does not predict anyone else's.
- Out-publish the attack. Legitimately asking real customers for reviews — no gating, no incentives, both of which are themselves FTC Rule violations — changes the arithmetic faster than any appeal resolves. This is the remedy that actually works at scale, and it is the one most owners skip because it does not feel like justice.
- If money was demanded, treat it as extortion. Report it to law enforcement and to the FBI's Internet Crime Complaint Center, and tell Google that extortion is involved, because Google says it specifically detects that pattern. Do not pay.
What does not help: buying positive reviews to offset the negatives, which violates both Google's policy and the FTC Rule and gets the profile suspended; asking staff and family to post, which requires disclosure of the connection under the same Rule; deleting and recreating the Business Profile, which destroys the genuine review history that was your actual defense; mass-emailing support; and disavow files or Search Console reconsideration requests, neither of which has any connection to reviews whatsoever.
What the law gives you, and what it does not
The FTC's Rule on the Use of Consumer Reviews and Testimonials, 16 CFR Part 465, took effect on 21 October 2024. Three sections bear on this attack. Section 465.2 prohibits fake or false consumer reviews, including reviews that misrepresent that the reviewer exists or had an experience with the business. Section 465.4 prohibits providing compensation in exchange for reviews expressing a particular sentiment, "whether positive or negative" — that is the provision reaching a competitor who pays for a bombing campaign against you. Section 465.7 covers review suppression, and matters here mainly as a warning: a threatening letter to a genuine negative reviewer can put you on the wrong side of it.
Now the limitation, stated plainly because most coverage buries it. The FTC's own questions and answers on the Rule confirm that it provides no private right of action. You cannot sue under it. It creates civil-penalty exposure enforceable by the FTC — real deterrence, and a real paragraph in a demand letter — but not a case you can file. Two further honest gaps: whether a competitor who personally writes rather than buys fake reviews is reached by Part 465 is a live ambiguity the FTC's guidance does not resolve, and I found no FTC enforcement action under the Rule against a competitor review-bombing campaign. The enforcement history is dominated by businesses inflating their own ratings, which is the same pattern the 89.1 percent finding shows.
What you can actually bring is ordinary state law. Defamation is the classic claim where a review makes a fabricated factual assertion — food poisoning, theft — about an identifiable business. Tortious interference fits where the attacker is an identified competitor and the campaign can be tied to them. Both require care: elements and defenses vary by state, several states have anti-SLAPP statutes that create real fee exposure if you sue over what turns out to be protected opinion, and unmasking an anonymous reviewer generally means filing suit and subpoenaing the platform, which is slow, expensive, and frequently ends at a VPN and a disposable email address. Get counsel before threatening anyone.
Frequently asked questions
A competitor is leaving fake one-star reviews. Will Google remove them?
Some of them, probably not all, and not quickly. Report each one individually under the policy category that fits, then describe the cluster — dates, volume against your normal rate, shared account characteristics — because Google removes coordinated groups as groups. Google says assessment "typically takes several days"; the only published dataset of deleted reviews puts the median lifetime of a review before deletion at 60 days. Reviews that survive the first pass can still be removed later, so a refusal is not final.
Did the fake reviews cause my ranking drop?
Possibly, but check the likelier causes first. Google says reviews "can help" local ranking without saying how much, and nobody outside Google has measured what a falling star average does to position. A sudden local pack drop is far more often a changed primary category, an edited profile field, a proximity shift, or a suspension. Compare your profile's fields against what they should say before concluding the stars did it.
Should I reply to a fake review?
Not on the first day. A reply adds text to the review, keeps it fresh, and is read by every future customer — who will judge your tone, not the reviewer's. Once you have reported it and the removal route is exhausted, one short, unemotional line stating that there is no record of the transaction and that the review has been reported is appropriate. Write it for the next customer, not for the attacker.
My profile has stopped accepting new reviews. Is that part of the attack?
Almost certainly the opposite. Google said in April 2026 that when it detects a spike of policy-violating reviews it removes the content, pauses new reviews on the profile, alerts the owner, and may show a warning banner to consumers. A pause during an attack is Google's mitigation firing. Google has not published what triggers it or how long it lasts, so treat the mechanics as undocumented.
Someone is demanding payment to make the reviews stop. What do I do?
Treat it as extortion from the first hour, not as a marketing problem. Preserve every message with headers and timestamps, do not pay, do not negotiate, and report it to local law enforcement and to the FBI's Internet Crime Complaint Center. Tell Google that extortion is involved when you report the reviews — Google stated in April 2026 that it built detection specifically for this pattern. Paying identifies you as a business that pays.
Should I buy positive reviews to bring the average back up?
No, and it is the fastest way to turn a bad week into a lost listing. Paying for reviews expressing a particular sentiment violates 16 CFR 465.4 regardless of direction, it violates Google's policy, and the removal machinery is demonstrably good at catching exactly this — 89.1 percent of the deleted reviews in the only published dataset were five-star. Ask real customers instead, without gating and without incentives.