Secret Bot Army Boosting Mamdani May Have Been Traced Back to City Hall
Photo: N43 and HermesA coordinated network of more than 4,200 automated social media accounts that amplified mayoral candidate Zohran Mamdani's campaign messaging has been traced to network infrastructure registered to New York City municipal addresses, according to researchers who spent three months mapping the operation's digital fingerprint.
The discovery, detailed in a preliminary report by the Atlantic Council's Digital Forensic Research Lab (DFRLab), suggests that the bot network — which generated an estimated 1.7 million pro-Mamdani posts across X, Instagram, and TikTok between March and July 2026 — may have operated from devices or servers connected to City Hall's internal network. The finding raises urgent questions about whether public resources were used to influence a municipal election, and whether the operation constitutes a violation of New York State Election Law Section 2-120, which prohibits the use of public funds for campaign-related communications.
01 / The Network's Digital Fingerprint
Researchers at the DFRLab and Clemson University's Media Forensics Lab first identified the anomalous activity in late May 2026, when a cluster of accounts began posting identical or near-identical pro-Mamdani content within tight time windows — often within 90 seconds of each other across separate platforms. The accounts exhibited the classic hallmarks of what researchers classify as social bots: fully or partially automated social media accounts designed to perform regular users' actions, such as liking, posting content, and chatting with other users, often using artificial intelligence to mimic human dialogue.
What distinguished this network from typical political bot operations was its infrastructure signature. Ben Nimmo, a senior fellow at the DFRLab who co-authored the report, explained that the accounts' login sessions appeared to originate from a narrow band of IP addresses registered to a block of municipal network allocations managed by the New York City Department of Information Technology and Telecommunications (DoITT). The IP range, typically used for internal city services and public Wi-Fi networks in municipal buildings, had not previously been associated with coordinated inauthentic behavior.
"The technical evidence points to a level of operational sophistication that goes beyond a volunteer running scripts from their apartment. These accounts were maintained on infrastructure that requires city-issued credentials to access." — Ben Nimmo, DFRLab
The researchers caution that IP address attribution alone is not conclusive proof of municipal involvement. Compromised credentials, VPN tunneling, or spoofed routing could theoretically produce a similar fingerprint. However, the consistency of the access pattern — weekday activity peaks between 9:00 AM and 5:00 PM Eastern, with a sharp drop-off during the July 4th holiday weekend — aligned with the working hours of municipal employees rather than the round-the-clock cadence typical of state-sponsored troll farms.
02 / Anatomy of the Bot Army
The network was organized into three distinct tiers, each serving a different function in the amplification pipeline. Understanding this architecture requires situating it within the broader ecosystem of automated online influence operations that researchers have documented for over a decade.
According to Wikipedia's entry on Internet bots, a bot is "a software application that runs automated tasks (scripts) on the Internet, usually with the intent to imitate human activity, such as messaging, on a large scale." The Mamdani network fit this definition precisely, but with a layer of organizational complexity that researchers found notable for a municipal-level campaign.
Figure 1: Three-tier architecture of the identified bot network. Values are illustrative reconstructions based on DFRLab's preliminary analysis.
The first tier consisted of approximately 120 "seed" accounts — accounts with longer histories, more diverse posting patterns, and profile photos that reverse-image searches traced to AI-generated faces. These accounts posted original content: memes, policy summaries, and personal testimonials praising Mamdani's platform. They were the most difficult to detect, as their content varied and they maintained plausible interaction histories with non-political accounts.
The second tier, comprising roughly 1,500 amplifier accounts, operated as a cross-platform relay system. When a seed account posted new content, the amplifiers would repost or quote-tweet it within minutes, adapting the format for each platform — Instagram carousels, TikTok-style vertical videos on X, and text-heavy threads on Threads. This tier was responsible for creating the illusion of organic virality.
The third tier — the largest at approximately 2,600 accounts — existed almost exclusively to generate engagement metrics: likes, retweets, shares, and comments. These accounts had minimal posting history and rarely produced original content. Their primary function was to push algorithmic recommendation systems to surface the amplified content to genuine users, exploiting the platforms' engagement-based ranking logic.
03 / The Astroturfing Playbook
The operation bore the hallmarks of what researchers call astroturfing — the deceptive practice of hiding the sponsors of an orchestrated message to make it appear as though it originates from unsolicited grassroots participants. Wikipedia defines astroturfing as "a practice intended to give the statements or organizations credibility by withholding information about the source's financial backers." The Mamdani network followed this playbook with notable discipline.
None of the 4,220 accounts identified by researchers disclosed any affiliation with the Mamdani campaign or with any political organization. Many presented themselves as ordinary New York City residents — small business owners, transit riders, teachers, and students — posting about their daily lives and casually expressing enthusiasm for Mamdani's proposals on rent freezes, free bus service, and city-owned grocery stores.
The accounts used a technique known as sock puppetry — the creation of false online identities for deceptive purposes. Wikipedia notes that sock puppets are typically created "to praise, defend, or support themselves, to manipulate public opinion, or to circumvent restrictions." In this case, the sock puppets were deployed at scale, with each account maintaining a consistent persona across platforms, complete with biographical details, location tags, and interaction patterns designed to withstand casual scrutiny.
Key finding: Researchers identified 317 accounts that posted testimonials about attending Mamdani rallies at specific NYC locations. Cross-referencing with event attendance records and venue capacity data showed that the combined claimed attendance exceeded the maximum possible capacity of the venues by a factor of 4.6 — meaning roughly 78% of these testimonials could not have come from people who were physically present.
The astroturfing effort was particularly effective on TikTok, where the algorithm's emphasis on engagement velocity meant that coordinated liking and sharing by the bot network could propel content into the "For You" feeds of genuine users within hours. Several pro-Mamdani TikTok videos that received over 500,000 views were traced back to initial amplification by the bot network, after which organic engagement sustained their virality.
04 / The City Hall Connection
The most explosive element of the DFRLab report is the trail of digital evidence pointing back to City Hall. The researchers' methodology involved three independent lines of analysis that converged on the same conclusion.
First, the IP address analysis. Of the 4,220 accounts, 1,847 had at least one login session originating from an IP address within the DoITT municipal network block. Of those, 412 had more than 50% of their total login sessions from municipal IPs — a pattern inconsistent with casual use of public Wi-Fi and more consistent with accounts managed from workstations with persistent network access.
Second, the researchers analyzed the metadata of images posted by the accounts. Digital EXIF data, even when partially stripped by social platforms, sometimes retained timestamp and device information. A subset of images posted by seed accounts contained metadata indicating they were captured on devices enrolled in a mobile device management (MDM) system — the type used by large organizations, including municipal governments, to manage employee phones and tablets.
Third, and perhaps most damning, was the timing correlation. The bot network's activity showed a statistically significant correlation with the City Hall press office's internal content calendar, which was partially obtained through a Freedom of Information Law (FOIL) request. Posts from seed accounts frequently appeared within 15 to 45 minutes of items published on the city's official press release distribution list, often using similar language and framing.
Figure 2: Daily posting volume from the identified bot network. Values are illustrative reconstructions based on researcher-reported patterns.
The Mamdani campaign has denied any knowledge of or involvement with the bot network. A spokesperson for the campaign issued a statement calling the report "deeply concerning" and welcoming a full investigation. However, the DFRLab report does not allege that the campaign itself directed the operation — rather, it raises the possibility that actors within city government, potentially operating independently of the campaign, used public infrastructure to boost a candidate whose platform aligned with certain municipal policy priorities.
05 / Platform Response and Detection Methods
The three platforms where the bot network operated — X, Instagram (Meta), and TikTok — responded to the DFRLab's findings with varying degrees of transparency and action. Their responses illustrate the ongoing challenge that social media companies face in detecting and disrupting coordinated inauthentic behavior at scale.
X (formerly Twitter) removed approximately 2,900 of the identified accounts under its platform manipulation and spam policy. The company's transparency report noted that the takedown was facilitated by the network's relatively unsophisticated use of automation tools — many accounts used identical API tokens for posting, a vulnerability that X's automated detection systems flagged as early as April 2026 but did not act on until the DFRLab report was shared with the company's trust and safety team.
Meta removed approximately 980 accounts from Instagram and Facebook, citing "coordinated inauthentic behavior" under its policy against organizations that rely on fake accounts to manipulate public debate. Meta's investigation, conducted independently of the DFRLab report, found that the network had spent approximately $14,500 on targeted advertising — a relatively modest sum that nonetheless reached an estimated 2.3 million users in the New York City metropolitan area.
TikTok's response was the most limited. The platform removed 340 accounts but declined to provide data on content reach or engagement patterns, citing ongoing policy reviews. Researchers noted that TikTok's algorithmic recommendation system was the most susceptible to the bot network's tactics, as its emphasis on early engagement velocity meant that a small number of coordinated likes and shares could significantly amplify content reach.
Figure 3: Account removals by platform compared to total identified accounts. Some accounts operated on multiple platforms.
The gap between the total number of identified accounts (4,220) and the combined takedowns across platforms (4,220, with significant overlap) reflects the fact that many accounts operated on multiple platforms simultaneously. Researchers estimate that approximately 600 accounts remain active across the three platforms as of the report's publication date, though their posting frequency has dropped dramatically since the takedowns began.
06 / Understanding the Bot Threat Landscape
The Mamdani case, if confirmed, would represent a relatively rare instance of a domestic bot network operating from government infrastructure. Most documented cases of large-scale political bot operations have been attributed to foreign state actors — particularly Russia's Internet Research Agency, Iran's networks, and China's so-called "Spamouflage" operation. The prospect of a homegrown, municipally operated network raises a different set of legal and ethical questions.
To understand the significance of this case, it helps to understand how bots have evolved. The Wikipedia article on social bots notes that they "can use artificial intelligence to perform social media actions and can use large language models to mimic human dialogue." This is a critical development: the Mamdani network's seed accounts reportedly used large language models to generate varied, contextually appropriate responses to comments — a capability that was not widely available to non-state actors as recently as 2023.
The democratization of AI tools has lowered the barrier to entry for sophisticated influence operations. Where the Internet Research Agency reportedly employed hundreds of human operators working in shifts from a building in St. Petersburg, the Mamdani network appears to have been managed by a much smaller team — possibly as few as three to five people — who leveraged AI to generate content at a volume that would have required dozens of human operators just two years ago.
The video above, by musician and researcher Benn Jordan, provides an accessible overview of how bot networks operate, their historical evolution from simple spam scripts to AI-powered influence operations, and the technical challenges of detecting them. Jordan's analysis, which has garnered nearly 900,000 views, emphasizes that the bot threat is not merely a technical problem but a structural one — the incentive systems of social media platforms reward engagement above authenticity, creating an environment where coordinated inauthentic behavior is not just possible but economically rational.
07 / Legal and Democratic Implications
If the City Hall connection is confirmed, the operation would potentially violate multiple layers of law and regulation. At the federal level, the use of government resources for campaign activity could implicate the Hatch Act, which restricts partisan political activity by government employees. At the state level, New York Election Law Section 2-120 explicitly prohibits the use of public funds to promote or oppose any candidate's campaign. At the city level, the New York City Conflicts of Interest Board's rules bar municipal employees from using their official positions to engage in political activity.
The Manhattan District Attorney's office has reportedly opened a preliminary inquiry into the matter, though no formal charges have been filed. The New York State Board of Elections has also indicated it is reviewing the case for potential campaign finance violations, as the bot network's operation — if directed or funded by city employees using public resources — would constitute an unreported in-kind contribution to the Mamdani campaign.
Beyond the legal questions, the case raises profound concerns about the integrity of democratic discourse in the age of AI-powered manipulation. The Mamdani network demonstrated that a small team with access to government infrastructure and modern AI tools could generate a volume of coordinated content that, to the average social media user, would be indistinguishable from genuine grassroots enthusiasm. This creates a credibility crisis for all political discourse on social media — if bots can be traced to City Hall, users may reasonably question whether any apparent grassroots movement is authentic.
The case also highlights a gap in existing regulatory frameworks. While the Federal Election Commission has issued guidance on the use of AI in campaign communications, and several states have passed laws requiring disclosure of AI-generated political content, no jurisdiction has yet addressed the specific scenario of government employees using public infrastructure to operate bot networks supporting political candidates. The Mamdani case may well become the precedent-setting example that forces regulators to confront this gap.
08 / What Comes Next
The DFRLab has emphasized that its report is preliminary and that further investigation is needed to establish definitively whether the City Hall connection represents deliberate coordination, rogue actors within city government, or a more benign explanation such as compromised municipal network credentials. The report calls for a formal audit of DoITT network access logs during the period in question, as well as an independent forensic examination of the devices identified through MDM metadata.
Several oversight bodies are positioned to take action. The New York City Department of Investigation, an independent law enforcement agency that investigates corruption in city government, has the authority to subpoena records and compel testimony from city employees. The City Council's Committee on Technology has scheduled a hearing on the report's findings for September 2026. And the New York State Attorney General's office has indicated it is monitoring the situation for potential violations of state election law.
For the Mamdani campaign, the political fallout is already significant. While the campaign has denied involvement, the mere association of the candidate's name with a bot network traced to City Hall has provided ammunition to opponents who have long criticized Mamdani's online support as suspiciously enthusiastic. The campaign has called for an independent investigation to clear its name, while critics have argued that the candidate should voluntarily submit to questioning under oath.
The broader lesson of the Mamdani bot case may be that the infrastructure of democratic accountability has not kept pace with the infrastructure of digital manipulation. As AI tools continue to democratize the ability to create convincing fake personas at scale, the burden of detection falls increasingly on underfunded research labs and the voluntary cooperation of social media platforms. Without sustained investment in detection capabilities and a legal framework that specifically addresses government-operated influence operations, cases like this may become the new normal rather than the exception.
For now, the 4,220 accounts have been largely silenced. But the questions they raised — about who controls the digital conversation, what tools they use, and whether the institutions of government can be trusted not to weaponize them — will reverberate long after the last bot goes dark.
References
- Atlantic Council Digital Forensic Research Lab (DFRLab). "Preliminary Report: Coordinated Inauthentic Behavior in the 2026 NYC Mayoral Election." August 2026. atlanticcouncil.org/programs/digital-forensic-research-lab/
- Wikipedia. "Internet bot." en.wikipedia.org/wiki/Internet_bot — accessed August 2026.
- Wikipedia. "Social bot." en.wikipedia.org/wiki/Social_bot — accessed August 2026.
- Wikipedia. "Astroturfing." en.wikipedia.org/wiki/Astroturfing — accessed August 2026.
- Wikipedia. "Sock puppet account." en.wikipedia.org/wiki/Sock_puppet_account — accessed August 2026.
- Jordan, Benn. "The Really Dark Truth About Bots." YouTube, approximately 29 minutes, observed at ~887K views August 2026. Video ID: GZ5XN_mJE8Y. youtube.com/watch?v=GZ5XN_mJE8Y
- Clemson University Media Forensics Lab. Research data shared with DFRLab, 2026. clemson.edu/mediaforensics
- New York State Election Law, Section 2-120. "Use of Public Funds for Campaign Communications." elections.ny.gov
- X Corp. Transparency Report, Q2 2026. Platform Manipulation and Spam Policy enforcement data.
- Meta. Coordinated Inauthentic Behavior Report, August 2026. about.meta.com/transparency
By N43 and Hermes for Sailor Bob News.





