A coordinated fake-review attack on your Google Business Profile needs a crisis response, not a single flag. Here's the reporting flow, the extortion route, and what actually works in India.
Quick answer
You can't delete reviews just for being negative, but Google will remove ones that break its policies. In a coordinated fake-review attack, flag each review as fake engagement, off-topic, conflict of interest, or harassment, then escalate through Google Business Profile support. Policy-violating reviews can be removed. Genuine-but-negative ones stay, so you dilute them with real reviews.

Is this a coordinated attack or just a run of bad reviews?
It's an attack when the reviews land faster than your real customers ever leave them, and the accounts behind them have no history with your business. One angry customer on a Tuesday is normal. Fifteen one-stars between midnight and 6 a.m., all from accounts you've never served, is not.
Before you report anything, confirm the pattern. Google's systems and its support staff respond far better to "here is a coordinated policy violation" than to "these reviews are unfair." So gather the evidence that separates a real attack from a bad week.
Look for these signals together, not in isolation:
- Velocity spike. A sudden burst of 1-star reviews in hours or a day, well outside your normal pace. A Jaipur boutique that gets two reviews a week does not organically get twenty overnight.
- No order or visit record. You check your bookings, invoices, or POS and none of these names match a real customer. For a clinic in Kochi or a cafe in Pune, that mismatch is your strongest proof.
- Copy-paste or templated text. The same phrases, the same misspellings, or near-identical wording across "different" reviewers.
- Brand-new or empty accounts. Reviewer profiles created recently, with a single review, no photo, or a history of reviewing unrelated businesses across far-flung cities.
- Off-topic or generic content. Rants that never mention a product, a staff member, or anything specific to what you actually do.
- Geographically impossible reviewers. Accounts reviewing your Delhi salon and a restaurant in another country within minutes, which no real walk-in customer would do.
When several of these stack up, treat it as an attack and document it. Screenshot each review with its username, star rating, date, and text. Save the reviewer profile URLs. This record is what you'll attach at every escalation stage, and it's the same evidence a lawyer or the police would ask for later. For the broader playbook beyond a single incident, our fake review removal guide for Indian businesses walks through the full process.
Flag every fake review, and name the exact policy it breaks
Flagging is your first move, it's free, and naming the right policy makes it far more likely to work. Google does not remove reviews because you dislike them. It removes reviews that violate its content rules, so your job is to match each fake review to the specific rule it breaks.
To flag a review, open your Google Business Profile, find the review, and use the three-dot menu next to it to report it as inappropriate. You can do this from Google Search or Maps while signed in to the account that manages the profile. Google's own guidance for this lives on the Google Business Profile Help page, Remove reviews from your Business Profile on Google.
The rules you're matching against sit in Google's contributed content policy (the Maps user-contributed content policy), published at Google's prohibited and restricted content policy. Read it once so you use Google's own language when you report. Here's how the common attack types map to it:
- Fake engagement / spam. Reviews from accounts with no genuine interaction with your business, bulk or automated posting, and content meant to manipulate your rating. This is the core violation in most review-bombing.
- Off-topic. Reviews that aren't based on a real experience at your business, or that rant about a political or personal issue unrelated to your service.
- Conflict of interest. Reviews left by a competitor, a former employee, or someone with a stake in harming you rather than an honest customer.
- Harassment. Reviews that target a specific staff member or the owner with personal attacks, threats, or abuse.
- Restricted or prohibited content. Profanity, hate speech, sexually explicit material, or anything illegal.
Flag each review under the closest matching category and, where the tool allows a note, state plainly that this is part of a coordinated attack with no record of these people as customers. Report every fake review, not just the harshest one. Consistent, specific flags across the whole batch read as a pattern to Google's reviewers, which is exactly what you want them to see.
What do you do when flagging does nothing?
Escalate, because a single automated flag is only the first door. Many owners flag once, hear nothing for days, and give up. The attack survives on that silence. Google offers three further routes, and using them in order gives you the best shot.
First, use the policy-violation reporting form. Inside your Google Business Profile dashboard there's a path to report a review that violates policy and to check the status of reviews you've already reported. This "report a new policy violation" flow is separate from the quick flag, and it lets you make the case in writing. Attach your evidence: the review URLs, your screenshots, and a short, factual summary of the velocity spike and the missing customer records.
Second, contact Google Business Profile support directly. From the dashboard you can request help through chat or a callback. A live agent can log a coordinated-attack case and, in genuine spam situations, push a batch for human review far faster than repeated silent flags. Be calm, be specific, and give them the pattern, not just your frustration.
Third, post in the Google Business Profile Community. Product experts and Google staff monitor it, and a clearly documented review-bombing thread sometimes gets attention that a form does not. It's not guaranteed, but it costs nothing and adds another record of the attack.
Track everything as you escalate. Note the date of each flag, each support ticket number, and each reply. If this ends up with a lawyer or the police, that timeline matters. Keeping an eye on incoming reviews during a live attack is easier with proper monitoring in place, which is where review monitoring and ORM tools earn their keep.
"Pay us or we post more 1-stars." What do you do now?
Do not pay, because paying marks you as a target and funds the next attack. Review extortion is a growing racket: someone posts a wave of fake 1-stars, then messages you on WhatsApp, email, or Instagram demanding money, often a UPI transfer, to take them down. Paying does not buy safety. It buys a repeat visit.
This is a crime in India, not just a policy problem. Extortion and criminal intimidation are offences under Indian criminal law, and misusing a platform to threaten a business can also fall under the Information Technology Act, 2000. This is general information, not legal advice. For your specific situation, speak to a lawyer.
Handle it in this order:
- Preserve every demand as evidence. Screenshot the messages with visible timestamps, phone numbers, usernames, email headers, and any UPI ID or bank details they send. Do not delete the chat. Do not pay to "test" whether they'll stop.
- Report it to Google as extortion. When you flag the reviews and contact support, state clearly that you're being extorted for their removal. Google treats threats and extortion attempts more seriously than ordinary review disputes.
- File a complaint with the police. Report it on the National Cyber Crime Reporting Portal at cybercrime.gov.in, or at your local cyber cell. This is the official government channel for cyber-enabled crimes, and a filed complaint gives you a reference number, an investigative route, and a paper trail Google and your lawyer can use.
The extortionist is betting you'll quietly pay to make it stop. Refusing, documenting, and reporting flips that. The same evidence discipline helps if the harasser also runs fake social accounts against you, which is a related problem we cover in our guide on Instagram impersonation and fake account removal in India.
How do you protect the profile while the attack is live?
Keep serving real customers and reply to the fakes calmly, because the public reply is written for future readers, not for the troll. Someone scrolling your reviews next month will see the attack and your response side by side. A composed, factual reply tells that reader everything the fake review does not.
Reply to each fake review in one or two lines. State that you have no record of this person as a customer, that you've reported the review, and that you welcome any genuine customer to contact you directly. Do not argue. Do not get sarcastic. Do not reveal private customer details to "prove" they never visited. A steady tone under attack reads as confidence.
Meanwhile, rebuild the true picture. A cluster of fake 1-stars only sticks out because it sits against a thin review base. Ask your genuine, happy customers to share an honest review, without incentives and without scripting what they say. A steady flow of real reviews does two things: it pulls your average back toward reality, and it signals a healthy, active profile to Google. Reviews increasingly feed the answers shown in AI-powered search too, so a truthful, well-tended profile protects you across more surfaces than the map pack alone, a point we expand on in our piece on reputation management for AI search.
What usually doesn't work (and why)
The tactics that feel fastest in a panic are the ones that backfire. Knowing them saves you money and saves your profile.
- Paying "guaranteed removal" vendors. No one can guarantee Google removes a specific review, because only Google decides, using its own policy. Anyone promising 100% deletion is selling you a story, and some simply post fake positive reviews on your behalf, which puts your profile at risk (see below).
- Mass-flagging from friends' and family accounts. Google detects coordinated flagging the same way it detects coordinated reviewing. A flood of flags from linked accounts can be discounted or can flag your own profile for scrutiny. Quality of evidence beats quantity of clicks.
- Posting fake 5-star reviews of yourself. This violates the fake engagement rule as clearly as the attack against you does. It can get reviews stripped and, in serious cases, get your Google Business Profile suspended. Fighting fakes with fakes hands Google a reason to penalise you.
- Arguing in the replies. Long, defensive, emotional replies make the attack more visible and make you look rattled. The troll wants the argument. Denying it is part of the response.
- Buying reviews to "balance it out." Incentivised and purchased reviews breach policy and consumer-protection norms, and they read as fake to customers anyway. They add legal and platform risk on top of the attack you already have.
The honest pattern here: shortcuts that involve deception or bulk manipulation tend to violate the same rules you're trying to enforce against your attacker.
Removal versus suppression: the honest ceiling
Google removes reviews that break its policies, not reviews that are merely negative or even unfair-but-genuine. This is the line that decides your whole strategy, so be clear-eyed about it. A fake review from a non-customer that breaks the fake-engagement or off-topic rule is a removal candidate. A real customer's harsh, one-sided, even exaggerated account of a genuine visit usually is not, however much it stings.
That gives you two different goals for two different problems. For the fakes, you pursue removal through flagging and escalation. For the negatives that are genuine and stay up, deletion isn't the realistic play. Suppression is.
Suppression means changing the overall impression rather than erasing a single line. You dilute a handful of stubborn reviews under a larger body of honest, recent ones, and you pair each difficult review with a measured public response. The bad review still exists, but it stops defining the profile because a truthful average and a professional voice now sit around it. That distinction, removal where policy allows it and suppression where it doesn't, is the difference between a plan that works and a promise that can't be kept.
Removal is a policy outcome you request and Google grants or refuses. Suppression is a reputation outcome you build over weeks with real customers. Chase the first for the fakes, invest in the second for everything that survives.
A coordinated fake-review attack feels personal, and it's meant to. The response that works is unglamorous: document the pattern, flag each review against the exact policy it breaks, escalate with evidence, refuse to pay anyone, and rebuild your true rating with real customers. Removal where Google's rules allow it, suppression where they don't, and no shortcuts that put your own profile at risk.

