This term is unusual on this site, because it is not a word people coined and a dictionary later recorded. It is a category in one company's rulebook: Meta writes that where adversarial threat actors use false identities to engage in sophisticated forms of inauthentic behaviour, they engage in what it has defined as coordinated inauthentic behaviour. [1]
That matters more than it sounds. It means the definition is owned, it can be revised without notice, and other platforms use adjacent phrases for adjacent things.
Why the wording is doing careful work
The category turns on inauthentic, not on coordinated. People coordinating in the open — a campaign, a fan community, a union — are not doing this, however organised or effective they are.
The reason a platform draws the line there is that account provenance is the one thing it can actually see and you cannot. It knows what was created when, from where, and by whom. From outside, all you ever have is the output, and the output of a genuine movement and a manufactured one can be identical.
That asymmetry is the whole practical lesson of this page. The judgement rests on evidence that is structurally unavailable to a reader.
What it takes to actually establish it
The clearest picture of what this looks like from the inside is worth reading less for the detail than for how the detail was obtained.
On 16 February 2018 a United States grand jury indicted thirteen Russian individuals and three Russian companies. The allegations describe an organisation employing hundreds of people for its online operations — from creators of fictitious personas through to technical and administrative support — running on an annual budget of millions of dollars. [2] They further allege the use of stolen or fictitious American identities, fraudulent bank accounts and false identification documents. [3]
Two things there matter more than the numbers.
The first is what establishing it required. Not observation of the output, which is all you will ever have, but a grand jury, financial records, and cooperation from the platforms. Every fact that decides the question — who opened the accounts, from where, paid by whom — sat on the far side of a line no reader can cross. This is the page's central point arriving in the strongest possible form: a case documented this well is also a case that took a criminal investigation to make out.
The second is the restraint. Announcing the charges, the Department of Justice stated that there is no allegation in the indictment that the charged conduct altered the outcome of the 2016 election. [4] It also noted that everyone charged with a crime is presumed innocent unless proven guilty in court. [5]
Read those two sentences again, because they are doing something unusual. That is a prosecutor holding the evidence, declining to claim the larger thing that almost everyone else claimed on much less. Note also what that first statement does not establish: that the conduct had no effect. It records that the indictment did not allege one, which is a narrower and more honest statement than either side of the argument it got used in.
This site cannot tell you how the case ended — the archived source is the announcement of the charges and nothing after it, and these remain allegations. That gap is itself the lesson. If a documented and prosecuted instance still has to be described this carefully, an argument you are having on a Tuesday cannot support the certainty it invites.
Recognising it
Signals, none of them evidence on their own:
- Accounts created in a cluster, active on one topic and nothing else
- Identical or near-identical phrasing across supposedly unconnected voices
- Posting rhythms that fit one working day rather than many separate lives
- Profiles with no history that predates the campaign
- The same handful of accounts appearing wherever a subject comes up
Every one of these has an ordinary explanation. New accounts are new for mundane reasons; people who read the same sources sound alike; enthusiasts really do turn up wherever their subject appears. Nothing in that list can establish who is behind an account, and treating it as though it can is how real people get accused of being fake.
The honest difficulty
There is no version of this you can confirm from where you are standing, and that is not a limitation of your effort.
The temptation is to reason backwards: the argument feels coordinated, therefore the accounts are inauthentic. That inference is unavailable. Coordination you can sometimes infer; inauthenticity you cannot, because it is a fact about who holds the accounts.
Which makes the accusation cheap and hard to answer. Anyone accused of being part of a network has no way to disprove it, and the accusation reads to onlookers as though it has been established. If you find yourself about to state it as settled, say the honest thing instead: it looks that way, and you cannot know.
What to do
Do not accuse. You cannot establish it, and being wrong does to somebody else exactly what was being done to you.
Describe the pattern, once, for the people reading. Not who these accounts are, but what you have noticed: the same phrasing, the same arrival, the same absence of history.
Send it to the people who can see the metadata. Platforms have reporting categories for this, and it is the one route where the invisible evidence is actually visible. How to report, and what a report does.
Then stop. You are not the audience — the wider readership is — and replying to each account individually spends your evening on the one thing that cannot work. The reasons disengaging works differently at scale apply here more than anywhere.