Case Studies

What the Cyberharpoon intelligence engine has delivered.

Real engagements, desensitized. The methodology and results below are from actual client work — identifying details redacted where clients have not publicly acknowledged the engagement.

BADS Forensic Publicly-traded micro-cap, US-listed Nov 2025 — 3-week engagement

Bot-network forensic on a US micro-cap stock during a promotional pump cycle

What we did

Applied the BADS (Bot Activity Detection System) methodology to social-media chatter around a US-listed micro-cap during an active promotional cycle. Cross-referenced social-media intelligence collection across X, Reddit, and Telegram with public trading-volume and account-behavior signals, then ran network-graph analysis to identify coordinated clusters versus organic retail conversation.

What we found

  • 27+ inauthentic accounts identified across two distinct coordination clusters, with shared posting cadence and near-identical narrative templates.
  • Two separate coordination networks — one focused on price-target narratives, the second on rebuttal-of-critics activity — sharing infrastructure signatures.
  • Approximately 72% decline in cluster posting activity in the two weeks after the report was delivered, consistent with either detection-avoidance or budget exhaustion.
  • Composite Mark Score bands assigned to each account with documented false-positive expectations at each threshold.

Outcome

Client used the deliverable — forensic timeline, tagged account list with Mark Scores, and narrative-cluster diagram — to inform an internal legal and communications response. Findings were preserved in a format suitable for regulatory referral at the client's discretion.

Methodology footnote: Bot probability scores are derived from behavioral heuristics (posting cadence, account age, template overlap) combined with network-graph analysis (shared followers, co-engagement patterns, infrastructure fingerprints). Every scored account ships with the threshold band and documented false-positive rate at that band. The 72% activity-decline figure is measured as delta in cluster posting volume across the two weeks pre- and post-delivery, using the same collection window on both sides.
Brand Protection Fortune-500 entertainment client (NDA) Feb 2026 — 48-hour turnaround

Distinguishing organic backlash from bot-amplified defense during a reputational event

What we did

During a fast-moving reputational event, the client needed to know within 48 hours whether the negative conversation on X and Instagram was organic public sentiment or a coordinated amplification operation — and whether the defensive counter-narrative was organic support or paid-inauthentic activity. Ran a 50,000+ post collection across the two platforms, then applied the same behavioral-heuristics and network-graph stack used in BADS forensic work, tuned for brand-signal rather than market-manipulation signal.

What we found

  • Approximately 2,400 inauthentic accounts identified across 12 coordination clusters, distributed across both the attack narrative and the defensive counter-narrative.
  • Organic sentiment isolated and re-scored after removing inauthentic amplification — with the organic baseline meaningfully different from the raw platform metrics.
  • Two of the twelve clusters exhibited infrastructure overlap with clusters previously observed in unrelated engagements — suggesting a reusable operator, not a bespoke campaign.
  • Delivered inside the 48-hour SLA window from initial brief.

Outcome

Client used the report to shape its public response strategy — separating the questions of "what does the real public think" from "what is being manufactured" — and to inform legal preservation of the identified inauthentic activity.

Methodology footnote: Post count reflects the total collection window across both platforms during the event, not unique conversation threads. Cluster count of 12 is defined as coordination groups meeting three or more behavioral-signature thresholds. The 2,400 bot figure is the count of accounts meeting a Mark Score threshold documented in the report with its stated false-positive expectation. All figures are self-reported from the client deliverable and have not been independently audited.
Recon Business Intelligence Regional SMB, hospitality vertical Aug 2026 — 4-hour Recon Standard delivery

Competitive intelligence and narrative audit for an independent specialty coffee roaster

What we did

Standard 4-hour Recon delivery on an independent specialty coffee roaster preparing for a wholesale-expansion decision. Full 6-tab dashboard: competitive intelligence via audience-overlap and search-result-adjacency signal collection, narrative and brand intelligence with per-platform footprint scoring, live sales-intelligence lead extraction from the last 14 days of conversation, gap analysis with severity heatmap, and a 30-day social-media game plan.

What we found

  • Three real market competitors identified — none of which the client had named on their internal shortlist — surfaced through audience-overlap and search-result-adjacency signals rather than category tags.
  • Two live narrative themes trending in the specialty-coffee vertical with strong subject-fit scores — actionable within the 30-day content plan.
  • Eight active engagement leads pulled from the last 14 days: prospects publicly asking wholesale-supplier questions the client's service directly answers.
  • Ten ranked gaps, two flagged as critical severity, each tied to observed demand signals and shipped with per-gap remediation recommendations.

Outcome

Client used the report to reshape the wholesale outreach shortlist and to reprioritize the 30-day content calendar around the two identified narrative themes. This is representative of the deliverable structure — the full redacted walkthrough for a comparable subject is available at /sample-report.html.

Methodology footnote: Competitor selection is not category-tag lookup; it is a signal-graph across audience overlap, search-result adjacency, and engagement-pattern proximity. Every competitor identified in the deliverable includes the specific signals that surfaced them. Engagement-lead count reflects prospects meeting explicit-question criteria in the collection window, not passive-follower lists. Gap severity ratings are qualitative, tied to demand-signal evidence documented alongside each ranking. This subject is a composite of a representative Recon engagement in the hospitality vertical.

How we count

Every number on this page was documented with its methodology at the time of client delivery. Each engagement ships with the raw heuristics used, the threshold bands assigned, the collection window covered, and the false-positive expectation at each threshold.

Clients receive the methodology alongside every finding — not as an appendix, but as an in-line audit trail on the finding itself. If a Mark Score, a cluster count, or a lead count appears in a Cyberharpoon deliverable, the client can see exactly how it was derived and what would move the number.

We report findings, not marketing metrics. If a number appears above, it was defensible at the time of client delivery and is subject to independent scrutiny.

Credibility, honestly

None of the numbers on this page have been independently audited by a third party.

What we can offer instead

  • Redacted methodology attached to every finding. Every claim above is backed by documented heuristics, thresholds, and false-positive expectations shipped with the original deliverable.
  • Sample raw evidence available under NDA for enterprise prospects evaluating BADS forensic or brand-protection work.
  • $99 Recon Lite as a hands-on evaluation of the underlying engine. Run a report on a business you already know inside-out. Grade entity resolution, competitor selection, social-data accuracy, narrative intelligence, sales-lead relevance, decision-maker accuracy, gap analysis, and source traceability yourself.
Test the engine yourself — $99 Recon Lite →