South Africa


Spotting disinformation in the wild: What’s the harm in a hashtag?

Spotting disinformation in the wild: What’s the harm in a hashtag?
(Illustrative image | Sources: Rawpixel | Twitter / ulerato_pillay | EPA-EFE / David Maxwell)

Unlike the spreaders of misinformation, disinformation actors knowingly cause damage to people, social groups, organisations and even countries. In the second of a three-part series examining falsehoods on Twitter, DFRLab sorts misinformation from disinformation in three popular hashtags.

  1. #RamaphosaResigns: Parody turns political 

When a young comedian from Sebokeng tweeted about giving people “mini heart attacks” with the hashtag #RamaphosaResigns, he might not have set out to cause harm.  

But the viral hashtag was co-opted by anonymous accounts to drive a false, politically motivated narrative that President Cyril Ramaphosa had resigned – and misinformation turned into disinformation.

Missed Part One in the series? Read it here. 

Chief among the agitators was @Advovolicious, an anonymous Twitter account that was spun off the @AdvBarryRoux account. @Advovolicious falsely claimed that Ramaphosa would announce his resignation during a public address that evening, in July 2020. In reality, Ramaphosa would give a briefing on the government’s Covid-19 relief efforts. 

The @Advovolicious account repeatedly tweeted the falsehood that President Cyril Ramaphosa would resign.

The initial tongue-in-cheek jab from the Jan Van Potgieter (@SciTheComedist) parody account was lost in the resulting noise.

A social network graph of the original tongue-in-cheek tweet about Ramaphosa’s resignation, indicating how small it was compared with the larger conversation.

In a strange twist, the same @SciTheComedist account started the #VoetsekANC hashtag, apparently in response to an #ANCFriday campaign by ANC supporters.

  1. #VoetsekANC: The campaign that wasn’t

Like clockwork, #VoetsekANC surged on Fridays, as the regular spikes in mentions show. (“Voetsek” can be roughly translated as “piss off”.) On the surface, it appeared to be a coordinated campaign targeting the ANC.

Social media listening tools like Meltwater Explore show regular spikes in mentions of #VoetsekANC.

High-follower Twitter accounts engaged with the hashtag weekly, usually around service delivery or government-linked corruption.

But a deeper dive shows that the traffic is organic. 

The #VoetsekANC hashtag found traction across the political spectrum.

The hashtag has been used by leaders in the EFF and DA, as well as accounts from conservative, libertarian, liberal and nationalist groups. The diverse nature of these accounts, spanning the political and ideological spectrum, makes it unlikely that it is a coordinated and inauthentic disinformation operation. 

A snapshot of the use of #VoetsekANC on 6 December 2020 makes this clear.

Several communities, indicated in different colours, have actively engaged with the #VoetsekANC hashtag for their own reasons. They represent a broad spectrum of political ideologies.

  1. #PutSouthAfricansFirst: A wide-ranging disinformation campaign

The #PutSouthAfricansFirst hashtag was used 945,000 times by slightly more than 115,000 individual users, and at times trended many times per week in 2020. (Note: The numbers have declined since the beginning of December, when there were 144,000 accounts and 1.15 million mentions. It appears Twitter has taken action against several of these accounts.)

The phrase “Put South Africans First” was used by the African Transformation Movement during its campaign ahead of the 2019 national election. But the hashtag became prominent in April 2020, when the @ulerato_pillay Twitter account used it to take a swipe at EFF leader Julius Malema.

The tweet that put #PutSouthAfricansFirst on the map.

The account was deactivated after the DFRLab identified its owner as Sifiso Gwala, a dismissed South African National Defence Force member from Richards Bay in KwaZulu-Natal. It has since been replaced with the @lerato_pillay account. It is likely this was done to erase the account’s history and associated evidence.

Gwala failed to respond to a request for comment by the time of publication.

The network consists of a core of accounts aggressively retweeting and engaging with narratives that tap into South Africans’ discontent with crime, unemployment and poor service delivery.

The largest share of this traffic consists of retweets (65%) and quote tweets (21%) with only 6% of tweets using the hashtag being original. This low share could indicate that a small number of accounts are coordinating original tweets, while the rest simply amplify their message. 

The bulk of #PutSouthAfricansFirst content on Twitter is retweets.

Real issues, false content

The narratives spread by the proponents of the hashtag touch on real issues such as unemployment, crime and lack of service delivery.

What makes it disinformation is the disproportionate blame these tweets place on foreigners – in some cases based on made-up “facts”.

For example, on 14 August 2020 the @uLerato_pillay account posted a photo of a crowded hospital with patients sleeping on the floor. The tweet claimed that South African patients were suffering because foreigners were taking up hospital beds. A reverse image search revealed that the photo was taken at a Nigerian hospital in April 2019 – almost 16 months before Gwala’s tweet.

An example of false context – one of seven types of mis- and disinformation identified by anti-misinformation organisation First Draft. The photo is genuine, but it is shared with false contextual information.

Several #PutSouthAfricansFirst tweets that used made-up statistics have since been deleted. For example, in September 2020 Gwala claimed that 70% of the University of South Africa’s employees were foreigners. But Unisa says 97% of its full-time and fixed-term staff are South Africans.

Examples of fabricated content used in the #PutSouthAfricansFirst campaign.

Despite hashtag users’ claims that it is a “patriotic movement”, much of the content is openly xenophobic. Users have described foreigners as cockroaches – a term reminiscent of the Rwandan genocide.

Accounts that interacted with #PutSouthAfricansFirst content have called foreigners leeches, parasites and cockroaches.

All this had the effect of serving, for several months, as a dog whistle for people who buy into xenophobic narratives or become convinced that the “real problem” is foreigners. The result is clear: replies to Gwala’s tweets urge violence against foreigners.

Coordinated behaviour

The network consists of a core set of accounts that create and share xenophobic narratives. Other accounts, some operated by real individuals who buy into the narratives, then retweet and engage with the content. The disproportionate amount of traffic that comes from a small share of accounts points to coordination – and disinformation.

A representation of the number of original tweets versus the total number of tweets (including retweets and replies) using #PutSouthAfricansFirst. The total volume closely tracks the original tweets during large spikes, suggesting some level of coordination.

For example, in July 2020 #PutSouthAfricansFirst was mentioned 165,120 times by 32,044 authors. But the top 10 accounts that used the hashtag – only about 0.03% of the total accounts – were responsible for 1.25% of the tweets. The same disproportionate volumes were seen in November 2020, when the top 10 accounts were responsible for 5.6% of the tweets despite making up only 0.04% of the unique accounts that used the hashtag.

In November 2020, #PutSouthAfricansFirst was used in 122,000 tweets and by about 24,800 Twitter users. But the 10 most vocal accounts were responsible for a disproportionately high number of mentions.

A network graph using 3,200 recent tweets from each of the 10 most active users of #PutSouthAfricansFirst (as at 4 December 2020) shows who they interacted with most often.

A social network graph of the 10 most vocal accounts that used #PutSouthAfricansFirst (left) and the accounts they interact with the most (right), suggesting that the vocal accounts were propping up the accounts in the middle.

When you strip away some of the noise, it is clear that these 10 accounts engage with, retweet and reply to many of the accounts involved in the #PutSouthAfricansFirst network. In essence, this means a small cluster of accounts are aggressively engaging with the accounts in the centre and one another in an attempt to create the perception of a legitimate movement. 

Prolific retweeters

A closer look at the accounts engaging with and retweeting this content reveals suspicious behaviour such as a high volume of retweets on a single topic.

One of the most vocal accounts in November 2020 was @Hlabezulu3, created on 30 October 2020. Despite being a brand-new account, it tweeted 7,387 times, peaking at 380 tweets in a single day, 24 November 2020. That is an average of almost one tweet every four minutes. Most of these tweets were retweets from several #PutSouthAfricansFirst accounts.

Twitter has since suspended the account.

An analysis of the @HlabeZule3 Twitter account while it was still active. The account mainly retweeted accounts within the #PutSouthAfricansFirst network (right), and posted large volumes while doing so.

Another prominent account in this network, @bsfs1212, tweeted 578 times on 26 November and 564 times on 27 November 2020 alone.

Not even the departed were off limits in this campaign. The Twitter account of Faith Gwedashe-Ndamase, a former Mrs South Africa finalist and Alex FM radio host who died in a car accident in September 2017, was repurposed to target journalist and author Nechama Brodie* with anti-Semitic tweets. Gwedashe-Ndamase’s profile pictures and user handle were changed, her bio altered and her previous tweets deleted before rebranding as the @MProphet101 account.

Archived replies to Faith Gwedashe-Ndamase’s tweets show that @ndamsexf and @MProphet101 share the same Twitter user ID.

What these case studies show is that a small, coordinated group of individuals can take real issues, taint them with their own agendas and then spread the repurposed narrative with relative ease on social media. 

A joke quickly turned into a negative PR campaign against Ramaphosa based on the actions of one influential account that twisted the #RamaphosaResigns hashtag. A small, active and coordinated group of accounts distorted facts and maligned foreigners under the auspices of a “patriotic” #PutSouthAfricansFirst movement.

The success of such campaigns mainly hinges on tapping into existing prejudices against a political party, organisation or a group of people to exploit them for the disinformer’s agenda.  

By contrast, #VoetsekANC developed organically. It transcended political and ideological boundaries to become an event that was almost celebrated weekly. DM

* Brodie is a former head of Africa Check’s training and research arm, TRi Facts.

This is the second part in a three-part explainer about disinformation on Twitter – the result of a collaboration between fact-checking organisation Africa Check and the Atlantic Council’s Digital Forensic Research Lab (DFRLab). Part One covers disinformation actors, their behaviour and content. Part Three considers how individual social media users could respond.

Jean le Roux is a former forensic investigator, investigative journalist and disinformation researcher with DFRLab.


Comments - Please in order to comment.

Please peer review 3 community comments before your comment can be posted

We would like our readers to start paying for Daily Maverick...

…but we are not going to force you to. Over 10 million users come to us each month for the news. We have not put it behind a paywall because the truth should not be a luxury.

Instead we ask our readers who can afford to contribute, even a small amount each month, to do so.

If you appreciate it and want to see us keep going then please consider contributing whatever you can.

Support Daily Maverick→
Payment options