Review bombing does its worst damage in the first day, and most of that damage is avoidable. What happens in the first 24 hours determines whether you end up with a documented removal case or a profile full of fake one-star reviews and no evidence left to prove it. This is the hour by hour playbook.

What is review bombing?

Review bombing is a coordinated burst of negative reviews posted over a short window, usually by people who were never customers. The trigger is typically a competitor, a viral social post, an online pile-on, or a paid attack service. The signature is volume and timing, not the content of any individual review.

That signature is also your best asset. A single fake review is hard to prove. Fourteen of them arriving between 9:02pm and 9:40pm, from accounts with no other local activity, is a pattern, and patterns are exactly what Google's fake engagement policy is written to catch.

What should I do in the first hour?

Capture evidence, and do it before anything else. Attackers delete accounts and edit reviews as soon as removal requests start landing, and once that evidence is gone you cannot get it back. Nothing else you do in the first day matters as much as this.

1

Screenshot every review with its timestamp

Full-page captures, not crops. You want the review text, the star rating, the reviewer name, and the posted time visible in one image. Do this for every review in the wave, including any that seem borderline legitimate.

2

Capture each reviewer's profile

Click through to every reviewer. Record their total review count, when the account appears to have been created, and what else they have reviewed. Accounts with one review, or a scatter of reviews across distant cities, are the clearest signal.

3

Build a timing log

List every review in a spreadsheet with its exact posted time. Clustering is the single most persuasive element of a coordinated activity case, and it is invisible unless someone writes it down.

4

Find the trigger

Search your business name on social platforms and Reddit. Attacks almost always have an origin post. Finding it tells you whether this is a competitor operation, an organized pile-on, or a misdirected campaign meant for another business.

Do this before you report anything. Filing reports is what alerts an attacker that you have noticed. Evidence captured after that point is frequently evidence that no longer exists.

What should I do in hours two to six?

Alert your team, check whether the attack is spreading to other platforms, and decide whether the reviews share a common false claim. Coordinated attacks often repeat a specific accusation, and if that accusation is checkable, your business records become part of the case.

Tell your staff not to engage. Employees who find the reviews on their own frequently respond from personal accounts or post about it publicly, and both make the situation harder to resolve. One person owns the response.

Then check your other profiles. Attacks that begin on Google often spread to Yelp, BBB, and, when the source is an employment grievance rather than a customer one, Glassdoor. Catching the spread early means you document all of it at once instead of rebuilding the case per platform.

Should I respond to each review?

No, not in the first hours. A wall of defensive owner replies makes a coordinated attack read like a genuine customer dispute to anyone scrolling the profile, and it buries the timing pattern that makes the attack obvious. Post one measured response once the wave settles.

When you do respond, respond once, near the top of the wave, and keep it short. Something factual works better than something defensive: a note that you have no record of these transactions, that the reviews arrived together in a single evening, and that you have reported them. That tells a real prospective customer what they need to know without arguing with fourteen anonymous accounts.

What not to write: accusations naming a competitor, sarcasm, anything revealing customer details, and anything you would not want quoted back later. Attackers screenshot owner responses and use them to escalate.

What should I report, and how?

Report the reviews as fake engagement rather than one at a time under mixed categories. Coordinated inauthentic activity is a single pattern, and a filing that presents it as one pattern is far stronger than fourteen separate complaints that each look like a business unhappy with a bad rating.

The self-service flag is worth using for the obvious ones, particularly any that contain slurs, advertising, or content plainly aimed at a different business. Those often clear quickly on their own. For the rest, the reporting form has no field for your timing spreadsheet or your account analysis, which is the structural limit covered in our guide to reporting a review yourself.

This is the point where a documented filing does the work a flag cannot. Coordinated attacks are among the strongest cases in Google review removal precisely because the evidence is quantitative: timestamps, account ages, review counts, and geographic scatter, presented together.

What should I avoid doing?

Do not contact the reviewers, do not buy positive reviews to offset the damage, and do not ask staff and family to post. Each of these turns a recoverable situation into a policy violation of your own, and Google enforces against businesses that manipulate their own ratings.

The instinct to flood the profile with positive reviews is the most dangerous one, because it feels constructive. A sudden burst of five-star reviews immediately after a burst of one-star reviews is the same statistical signature the attackers just produced. Profiles have been suspended for exactly this. If you want to build genuine reviews back, do it steadily over the following weeks, from real customers, with no incentive attached.

Contacting reviewers directly is the second trap. If they are acting in bad faith, contact gives them new material. If one turns out to be a real customer caught in the wave, the outreach can read as pressure.

Does Google remove review bombing?

Yes, when the coordination is documented. Google's fake engagement policy covers coordinated inauthentic activity directly, and batch filings that demonstrate the pattern succeed at a much higher rate than individual reports. The constraint is evidence, not eligibility.

Some of the wave may come down through Google's own automated detection without any action from you, particularly if the attack used low-quality accounts. Do not count on it. Automated systems catch the crude operations and miss the careful ones, and the careful ones tend to do more damage because the reviews read as plausible.

How long does recovery take?

Removal of a documented coordinated attack typically resolves within 1 to 7 business days after filing. Rating recovery takes longer, because your average has to be pulled back by genuine reviews once the fake ones are gone. The math of that recovery is worth understanding before you set expectations.

The good news is that removals restore the rating retroactively. A removed review stops counting toward your average entirely, so a successful batch removal can return a profile close to where it started rather than requiring you to out-review the damage. That is a meaningfully different outcome from the slow grind of offsetting reviews that stay up, which we work through in detail in our piece on how many five-star reviews it takes to recover a rating.

The 24 hour checklist

  • Screenshot every review with visible timestamps, before reporting anything
  • Capture every reviewer profile, review count, and posting history
  • Build a timing log listing each review and its exact posted time
  • Locate the trigger post or origin of the attack
  • Tell staff not to engage, and designate one responder
  • Check Yelp, BBB, and Glassdoor for spread
  • Flag the obvious text-visible violations through the self-service tool
  • Post one measured public response, not fourteen
  • Preserve any business records that contradict a repeated factual claim
  • Do not buy reviews, solicit a counter-wave, or contact reviewers

Under Attack Right Now?

Coordinated attacks are the strongest removal cases when the pattern is documented early. Send us the reviews and we will assess them free.

Start Your Free Evaluation