Back to dashboard

Suspicious posting burst detected

Alert ALT-2026-0042 · demo data

High severity · Open

@thomasgere

X / Twitter · detected 13 Sep 2026, 03:12 UTC

What changed

A burst of 23 posts in 40 minutes promoting a cryptocurrency giveaway, written in a tone that does not match this account's history. Several posts include shortened links not previously used by this profile.

Why it was flagged

  • Sudden flood of posts

    23 posts in 40 minutes — usual rate is 2–3 per day.

  • Off-brand financial content

    Repeated crypto giveaway language never seen in 18 months of posting history.

  • Unusual language patterns

    Sentence structure and emoji usage differ sharply from the account's baseline style.

  • Odd hours

    Posts went out between 02:47–03:12 UTC; this account is normally active 08:00–19:00.

  • New shortened links

    Links redirect through a domain first seen today, flagged by two threat feeds.

Timeline

  1. 02:47 UTCFirst unusual post detected on @thomasgere
  2. 03:05 UTCPosting rate crossed anomaly threshold (15 posts / 30 min)
  3. 03:12 UTCGuardian AI raised alert ALT-2026-0042 and sent notification
  4. 03:12 UTCEmail alert queued to account owner (demo placeholder)

Suggested next steps

  1. Change the password on the affected account immediately.
  2. Revoke access for any third-party or AI apps under the platform's connected-apps settings.
  3. Review and delete any posts you did not author.
  4. Re-enable two-factor authentication, preferably with an authenticator app or security key.
  5. Check your email for platform sign-in alerts from unknown devices or locations.

This is a demonstration alert with fictional data. Guardian AI is a best-effort aid and may miss or misreport real incidents. See the Limitation of Liability.