T8-AT-006MEDIUM

Targeted Harassment Content

T8 · External Deception & Misinformation →
Risk score195
RatingMedium
Procedures10
Severity
Mechanism

Targeted harassment uses LLMs to industrialize abuse against a specific individual: discrediting posts, fabricated allegations, rumor campaigns, doxxing templates, defamatory articles, coordinated message floods, and review-bombing scripts. The technique works because harassment's impact scales with volume, persistence, and apparent multiplicity of accusers — and LLMs supply all three cheaply, generating endless on-message variations that read as distinct human voices. The asymmetry is between a single operator producing thousands of unique-seeming attacks and a lone target who must see, absorb, and try to counter each one.

Detection
  • Coordination/pile-on detection: Identify many accounts targeting one entity in a narrow window with shared phrasing or link sets
  • Cross-post stylometric clustering: Detect that "independent" attackers share a single generative fingerprint
  • Account-age and velocity heuristics: New/burner accounts converging on a target indicate a manufactured campaign
  • PII-exposure scanning (doxxing detection): Flag posts aggregating home addresses, phone numbers, or workplace details
Mitigation
Entity-level abuse aggregation + rate limitingHIGH
Coordinated-behavior takedownsHIGH
PII/doxxing detection and fast removalHIGH
Target-side protective toolingMEDIUM
Chaining

Targeted harassment frequently sits inside larger operations: it weaponizes identity fabrication (T8-AT-015) to create the sock puppets that carry the abuse, synthetic evidence (T8-AT-002) to back fabricated allegations, and psychological-manipulation content (T8-AT-013) to maximize harm to the target. It chains with T9 synthetic media when fabricated or non-consensual imagery is attached, and with disinformation infrastructure (T8-AT-007) to coordinate the pile-on.

Framework mapping
OWASP LLMLLM09
MITRE ATLASAML.T0048.004
Open in the technique browser →