Overview
During the early testing phase of the unphish blog in January 2026, comments remained enabled across several test articles before the broader blog section officially launched.
At the time, these pages were primarily being used to test layouts and publishing workflows. The blog section itself was not yet publicly accessible through the main website navigation, and the articles had not been actively promoted.
Within days, moderation notifications began appearing.
Not genuine discussion or reader engagement, but large volumes of repetitive submissions containing shortened URLs, affiliate-style promotions, and unrelated marketing messages.
Over the following few months, the activity continued steadily across the first few test blogs. Each article ultimately received an estimated 80-100 submissions, despite not being publicly surfaced through the website itself.
Importantly, none of the comments appeared legitimate.
The scale, speed, and consistency of the activity suggested the submissions were not genuine user engagement.
The Abuse Activity We Observed
The majority of submissions followed a highly repetitive structure.
Most included:
- generic first names followed by numbers
- Gmail addresses
- shortened outbound links
- affiliate or commission-focused language
- unrelated promotional messaging
None of the submissions appeared related to the article content itself. Instead, the activity appeared focused on inserting promotional or referral-style links onto publicly accessible pages.
Across multiple posts, the submissions repeatedly promoted:
- affiliate programs
- commission offers
- referral campaigns
- cryptocurrency-related promotions
- external traffic-driving links
(Example of Affiliate-focused spam and a shortened outbound link)
(Example of unrelated cryptocurrency-themed promotional spam)
(Example of repetitive referral-style messaging)
The same behavioural patterns appeared repeatedly across multiple articles over several months.
Author names repeatedly followed similar formats such as:
- Zoe4310
- Adeline2884
- Oscar3428
This naming structure strongly suggests automatically generated or templated identities rather than genuine users.
The submissions also originated across multiple IP addresses and network providers rather than a single identifiable source. Several IP hostnames appeared to use residential or dynamically assigned ISP infrastructure, while the messaging structure itself remained highly repetitive across submissions.
The links themselves also followed a clear pattern. Many comments used URL shortening services rather than direct destination URLs, obscuring where the links ultimately resolved.
Importantly, these were not debates, questions, or attempts at genuine engagement. The submissions were unrelated to cybersecurity, phishing, takedowns, or the broader themes of the articles themselves.
Taken together, the behaviour strongly suggested automated abuse activity rather than legitimate user interaction.
Public Comment Forms Are Easy Automation Targets
Public comment sections have long been a common target for automated spam activity, particularly on widely used content management systems such as WordPress.
Because WordPress powers a significant portion of the public web, automated abuse campaigns frequently target WordPress-powered pages, publicly accessible forms, and comment sections at scale. These campaigns do not necessarily target high-profile websites specifically. Instead, automated systems continuously scan the internet for accessible pages containing common WordPress structures, comment functionality, or public submission fields.
Importantly, a page does not need to be linked in a website’s navigation to become discoverable. If a page exists publicly online, it may still be identified through automated crawling activity, RSS feeds, XML sitemaps, direct URL discovery, or broader internet-wide scanning processes.
This likely explains why the unphish test blogs were still able to attract spam activity despite not being publicly promoted or accessible through the primary website navigation.
Research into WordPress comment spam also shows that modern automated campaigns commonly rely on:
- automated link insertion
- repetitive promotional messaging
- referral or affiliate-focused campaigns
- large-scale bot submissions
- rotating identities and IP addresses
The repetitive structure, scale, and persistence of the submissions observed across the unphish test blogs were consistent with the broader patterns commonly associated with automated comment abuse campaigns.
Why These Campaigns Still Exist
Despite improvements in moderation systems, CAPTCHA protections, and automated filtering tools, public comment sections continue to attract abuse because they still provide value to the operators behind these campaigns.
A publicly accessible comment section offers something highly attractive: the ability to place links or promotional content onto legitimate websites at scale.
Importantly, these campaigns do not necessarily rely on high success rates. Automated systems can distribute content across thousands of websites simultaneously at very low cost, meaning even minimal interaction may still generate value for the operators behind the campaign.
The activity observed across the unphish test blogs aligned closely with broader patterns commonly associated with automated comment abuse, including repetitive messaging structures, rotating identities, shortened URLs, and externally focused promotional content.
The use of URL shortening services was also notable. Shortened links can obscure the final destination of a URL, making it harder for users and automated filters to immediately determine where a link ultimately resolves. Research into phishing campaigns has also shown that shortened URLs are commonly used to mask malicious destinations and bypass basic detection mechanisms.
This broader ecosystem helps explain why even low-visibility or temporary test environments can still become targets for automated abuse.
Final Observation
The activity observed across the unphish test blogs did not appear targeted specifically at unphish itself. Instead, the behaviour was more consistent with opportunistic automated abuse operating continuously across the public web.
What made the activity notable was not the sophistication of the comments themselves, but the speed and scale with which publicly accessible functionality was discovered and abused, even within low-visibility test environments that were not actively promoted or surfaced through the website’s primary navigation.
As the activity continued, the comment functionality was ultimately removed from the test blog environment. While comments were never intended to be a long-term feature of the unphish blog, the experience still provided useful visibility into how quickly publicly accessible forms can begin attracting automated abuse once exposed online.
Importantly, users should remain cautious when interacting with links posted within public comment sections. As observed throughout this activity, externally submitted comments may contain shortened URLs, promotional redirects, or links to unrelated third-party content, making it difficult to immediately verify where a link ultimately leads.
More broadly, the activity reinforces an important reality of today’s online threat landscape: publicly accessible digital infrastructure is continuously scanned and interacted with by automated systems at scale, often far faster than expected. Similar behavioural patterns can also be observed across online marketplaces and phishing activity, where newly exposed public content is rapidly identified and acted upon through automated processes, as explored in our Depop marketplace scam case study.