Fifteen 1-star reviews inside three hours. Forty by the next morning. Most from accounts with no other activity, all echoing some version of the same complaint, and no message asking for money anywhere in sight. Your rating just cratered and your Google Business Profile reads like a warning label. That's review bombing, and it moves fast enough that the wrong first move locks in damage before you've figured out what's actually happening.

This is a different animal from extortion. An extortionist wants payment and says so directly. A review-bombing attack often carries no ask at all: a pile-on tied to a viral clip, a competitor trying to knock you out of the map pack, an ex-employee rallying friends, or a mob that formed around something only loosely connected to your actual business. If a payment demand does show up alongside the flood, that's a separate emergency with its own playbook, covered in our review extortion guide. Everything below is for the version where nobody wants anything except to bury you.

How to tell it's an attack, not just a bad week

The tell isn't the star rating, it's the shape of the data around it. A real wave of complaints tracks roughly with how many customers actually walked through the door or called that week. An attack doesn't. A dozen or more 1-star reviews land within hours, sometimes minutes apart, with no matching jump in foot traffic, orders, or bookings. Read the text and a second signal shows up: phrasing repeats almost word for word across accounts that have never reviewed anything else, and the complaints stay vague on purpose, "worst service ever," "avoid this place," "total scam," because nobody behind them actually transacted with you. A genuine angry customer names a date, a server, an order number. A bombing campaign can't, since it isn't describing anything real.

Step one: don't respond, not yet

Every instinct says post something immediately, reply to each review, defend the business in public before the damage compounds. Resist it. A rushed, emotional response gets screenshotted and reposted faster than the original reviews did, and it hands whoever's running the campaign fresh material to keep it going. Staying quiet for the next few hours while you work through documentation and reporting costs you nothing. A defensive reply typed at 11pm in the middle of a pile-on almost always costs something.

Step two: document before anything disappears

Screenshot every review the moment you see it: full text, star rating, reviewer name, and a visible timestamp. Do this before you flag anything, because flagging can prompt reviewers to edit or delete their post once they sense pushback, and a vanished review is far harder to build a removal case around later. Save the reviewer profile links too, and keep a running log with dates. Past a handful of reviews, put it in a spreadsheet: name, post time, exact text, link. That log becomes your evidence file whether you flag the reviews yourself or hand the case to someone else.

Step three: flag each review on its own

There's no Google tool for reporting "a coordinated attack." There's a flag button on each individual review, and that's the unit Google's system actually processes. Work through your list one review at a time, pick the closest policy violation (fake engagement, off-topic content, spam), and submit. It's tedious at volume, which is exactly why attacks running past a hundred reviews often stall when an owner tries to clear them solo between customers.

What Google does on its own

Google's abuse-detection systems watch for the same spike pattern you just learned to spot, and on a severe enough attack they sometimes pause new review submissions on a profile automatically, showing visitors a notice explaining why. It's a real protection, and it does happen. It's also not something you can request, trigger, or speed up by asking; the system decides on its own, and plenty of attacks that deserve the pause never get it. Treat it as a possible bonus, not a plan.

Forty fake reviews in two days and no idea where to start flagging?

We take on review-bombing clusters as their own case type. Send the profile links, we confirm within 24 hours whether we accept, and cleared cases land in 3-7 days (median 4). Pricing runs per review; if you're staring at a large cluster, reach out and we'll talk through the case before anything's billed.

Book a 10-min call

If a ransom demand shows up in the middle of it

Sometimes the flood arrives first and a message asking for money follows a day later, once your rating has already tanked and you're motivated to make it stop. At that point you're no longer dealing with plain review bombing, you're dealing with extortion, and the response changes: never pay, and work through the sequence in our review extortion guide instead. There's no guarantee the reviews come down even once you've paid, and paying tells whoever's running the campaign you're a soft target worth hitting again.

Getting the reviews removed for good

Flagging individually clears some of an attack on its own; Google does take coordinated fake activity seriously once it's reported correctly. What it doesn't reliably clear is the full cluster, especially past 15 or 20 reviews, where borderline cases sit in a queue indefinitely while your rating stays wrecked. That's the gap a removal service closes: working every review in the batch in parallel instead of one at a time between customers. At Lizard Reviews we removed 1,427 reviews between January and May 2026, a 100% success rate on every one that had actual text attached (rating-only reviews, a star with no comment, sit outside anyone's reach, ours included). Median turnaround once we accept a case is 4 days, range 3 to 7, and we tell you within 24 hours whether we're taking it. Pricing runs $450 per review, billed only after Google confirms removal, and every review we take down carries a lifetime re-removal warranty: zero of those 1,427 have come back. For a bombing case running into dozens of reviews, that per-review structure still applies, so reach out and we'll talk through the numbers on your specific cluster before you commit to anything.

The businesses that recover fastest from a bombing attack skip the public meltdown and go straight to the boring work: screenshot, flag, log, repeat. It's not satisfying in the moment. It's also the only sequence that actually gets the rating back.

Frequently asked questions

A coordinated flood of fake or exaggerated negative reviews posted within hours or days, usually with no payment demand attached. Often tied to a viral incident, a competitor, an ex-employee, or an organized pile-on rather than actual customers.
Extortion comes with a direct demand for money attached to the reviews. Review bombing usually has no ask at all, it's about volume and speed, not a ransom. If a payment demand does appear alongside the flood, treat it as extortion instead.
Check the timing: a spike in 1-star reviews with no matching rise in real customer volume. Then check the text: repeated phrasing across different accounts and vague complaints with no transaction details. Screenshot everything with timestamps first.
Sometimes. Google's systems can detect an abnormal spike and temporarily pause new review submissions, showing visitors a notice explaining why. It's automated protection, not something a business can request or control directly.
Flagging individually can clear some of an attack on its own. For a full cluster, Lizard Reviews confirms acceptance within 24 hours and removes accepted cases in a median of 4 days (range 3-7), at $450 per review, billed after Google confirms removal.