For over a year, an unknown entity has been hijacking Bluesky accounts and incorporating them into a spam network that aggressively follows real users while serving up a mix of political posts, news links, and plagiarized photographs. While these accounts generally get suspended sooner or later, the operators of the network continue to replace them with new batches, making minor tweaks to the network’s behavior along the way. In the past, the spam accounts’ posts rarely received much engagement; however, the latest batch of accounts have had more success, with multiple posts going somewhat viral in August and September 2026.
This spam network consists of at least 24 Bluesky accounts, and is most likely substantially larger. The set of accounts studied was obtained by starting with the accounts @bilautaly.bsky.social, @calista747.bsky.social, and @savannahleea.bsky.social, and scanning the followers of major accounts they follow for additional accounts meeting the criteria below:
account follows at least 10,000 accounts
account follows at least 3 times as many accounts as it has followers
account has fewer than 100 posts
gap in activity of at least six months (if account is sufficiently old)
account has a stolen profile photo or has posted multiple stolen photos
account is not cryptocurrency or porn-themed
Most, but not all, of the accounts in the network also have a mismatch between their handles and display names; for example, @eduardoegomes.bsky.social has the display name “Lily”. The display names are a mix of random first names, political phrases such as “ProgressiveBloom”, and fruit/vegetable emoji.
Two of the accounts in the network, @celine2017.bsky.social and @edenwhisper.bsky.social, originally posted in Portuguese but switched to English following a gap in activity of almost two years. This, along with the fact that nearly every account in the network has a similar gap in activity, and the fact that most have display names that are unrelated to their handles, strongly suggests that the network consists mostly or entirely of hijacked accounts.
The accounts in this spam network frequently post photographs of various aspects of their alleged lives, including but not limited to their alleged meals, scenes from alleged walks around cities in California, and alleged dogs belonging to their alleged neighbors. Reverse image searches confirm, however, that most (and likely all) of these photographs are plagiarized, and many have been in circulation for years on various parts of the Internet. The majority of the images appear to have been pilfered from other social media platforms, generally TikTok, Instagram, or Facebook.
The majority of the accounts in this network use photos of animals, people, or landscapes as avatars, and as with the photographs in their posts, these images are plagiarized. Most were previously posted or used as avatars on other social media sites; some can also be found on stock photo sites. Google image search outperformed TinEye for tracking down other uses of these particular images.
As mentioned earlier, this is not the first incarnation of this particular Bluesky spam network (several earlier versions were covered previously on this blog). The latest batch of accounts has, however, been markedly more successful at getting real users to pay attention to its content. In the last two months, many of the accounts in the network have racked up significant numbers of reposts, likes, and replies on their political and news posts, with little indication that any of the users engaging with this material are aware that they are interacting with fake accounts.
How are these accounts getting traction? While their main method for growing their audiences appears to be simply to follow as many accounts as possible with the hope of being followed back, some of their growth can also be attributed to Bluesky’s starter pack feature. Most of the accounts in the network are in multiple starter packs, generally politically-themed packs created by liberal users. Some of the accounts are also listed on so-called “follow train” posts, which consist of a list of accounts to follow, presented with the understanding that the accounts on the list will follow back.
The accounts in this network have a handful of other unusual behaviors that, while not present on every account, do occur frequently enough to constitute a pattern. For example, roughly half of the accounts have put up posts that reference specific news stories or headlines, but link to the news outlet’s home page rather than to the article or video under discussion. While it is possible that this is the result of human error, it is more likely a glitch resulting from some type of automation malfunctioning.

There are indications that these spam accounts are attempting to send direct messages to other Bluesky users. Several of the accounts in the network have asked other users publicly why they are unable to message the user they are replying to; the answer, in each case I reviewed, is simply that the person the spammer attempted to message does not have their direct messages open to accounts they do not follow. It is presently unclear what, exactly, the spam accounts are attempting to send to legitimate users via DM.
While this spam network has been around in various forms for some time, its behavior has evolved slightly with each new group of repurposed accounts. If the goal of the network is to build an audience of legitimate users, the effort appears to be succeeding for the moment, as many of the spam accounts have grown sizable followings, and garnered noticeable engagement on their posts. While the viral posts thus far have been largely benign, the spam network’s increasing ability to get real users who post about U.S. politics to amplify its messaging is concerning, especially with the U.S. midterm election approaching. It will be interesting to see how this network’s behavior evolves over the coming months, along with what steps Bluesky takes to disrupt it.










