How to handle a review crisis: a 72-hour playbook
Jul 15, 2026 · 14 min read
The most expensive review-crisis mistake I’ve watched a business owner make happened at hour two. Not day two. Hour two. A gym owner in Sacramento woke up to nine 1-star reviews, decided the fastest way to fight back was a long Facebook post calling out the “coordinated attack,” and by lunch the screenshot of his post had traveled further than the reviews ever would have. The reviews were the spark. His response was the gasoline.
Here’s the thesis: a review crisis is decided by the sequence of your actions, not the quality of any single response. The first 72 hours have a correct order of operations, most owners run it backwards, and almost all of the permanent damage in a review crisis is self-inflicted between hour one and hour six.
This is the hour-by-hour playbook. It assumes nothing about your industry - the clock runs the same for a med spa, a moving company, or a law firm.
Hour 0-1: figure out which crisis you have
Before you type a single word anywhere, diagnose. There are three species of review crisis, and they need different playbooks. Treating one like another is how owners turn a bad week into a bad quarter.
Type 1: one real review going viral. A genuine customer had a genuinely bad experience, wrote it up vividly, and now it’s getting shared - maybe a local Facebook group, maybe TikTok. The review is true, or true enough. Your enemy here is your own defensiveness.
Type 2: review bombing. A flood of 1-stars from accounts that never bought anything - usually 10 to 25 reviews inside 48 hours, often triggered by a news story, a viral post, or a political flashpoint. The reviews are fake in the literal sense: no transaction behind them. Your enemy here is the urge to answer each one.
Type 3: extortion. The bombing arrives with an invoice. A WhatsApp or email message tells you the reviews will stop for a fee, usually in crypto. This became a global pattern in 2025, and it’s common enough now that Google built a dedicated reporting flow for it. We wrote a separate breakdown of the review extortion scam and why paying never works; the short version for this playbook is: it’s a Type 2 crisis plus a criminal, and the criminal changes nothing about your first 24 hours except that you also preserve the ransom message.
The diagnostic takes ten minutes. Open the reviewer profiles. Real customers have review histories - restaurants, a hardware store, their dentist. Bombing accounts have one review (yours) or a string of recent 1-stars across businesses that have nothing in common. Check your CRM or booking system for the names. Note the timing: real complaints trickle, attacks cluster.
Write down which type you have. Literally write it down. Every decision for the next three days branches off this answer, and at hour 14, tired and rattled, you’ll want the note.
Hour 1-6: document everything, publish nothing
This window is where the Sacramento gym owner blew it, and it’s where most owners blow it, because hour 1-6 is when the adrenaline peaks and the available actions all feel too slow.
The work of this window is evidence, not communication:
- Full-page screenshots of every suspect review - the review text, the star rating, the reviewer name, and the timestamp visible in one capture.
- The URL of each reviewer’s profile, saved in a spreadsheet with the date. Profiles get deleted; your screenshots are the record that they existed.
- A timeline: when each review landed, in order. Clustering is your strongest evidence when you flag, and it evaporates if Google removes some reviews before you’ve recorded the pattern.
- For Type 3: the ransom message, the sender’s number or address, and any payment details they sent. Don’t reply. Don’t block yet either - you may need the thread.
And two things you do not do in this window. You don’t respond to any review, even the real one - a response drafted in hour three reads exactly like a response drafted in hour three. And you don’t post about the situation on social media. The instinct to “get ahead of it” with a public statement is almost always wrong at this stage, because a statement converts a review problem (seen by people actively researching you) into a content problem (pushed to people who’d never have looked). The gym owner’s nine reviews had maybe a few hundred eventual readers. His Facebook post reached twelve thousand people in a day.
One more hour-one task if you have staff: appoint a single owner of the crisis. Not a committee - a name. When three people can all see the reviews and nobody officially holds the pen, you get the worst outcome available: the most anxious person in the building responds first. The owner of the crisis is the only person who posts, flags, or speaks about it anywhere, and everyone else forwards what they see to that person and otherwise sits on their hands. This takes one Slack message to establish and prevents the most common multi-person failure I’ve seen: two well-meaning replies to the same review, in different tones, an hour apart.
Hour 6-24: run the branch for your crisis type
Type 1 - the real review
You respond once, publicly, and you write it for the audience that matters: the prospects who’ll read this exchange for the next two years, not the angry customer and not the pile-on commenters. ReviewTrackers’ consumer data (2025) found 94% of consumers say a negative review has convinced them to avoid a business - and the variable you still control is what sits underneath that review.
The craft of that response is its own discipline - own the specific failure, skip the excuse, make one concrete offer - and we’ve covered it at length in the negative review response playbook. For crisis purposes, the addition is restraint: one response, then stop. If the review is getting shared with commentary, do not chase the commentary. You can’t win an argument with an audience; you can only show the audience one composed reply and let it sit there outlasting the outrage. If you’re struggling to apologize for the experience without conceding a legal claim - relevant if there’s an injury or a billing dispute in the mix - there’s a template for exactly that wording problem.
Type 2 - the bombing
Counterintuitive but firm: do not reply to fake reviews individually. Replying does three bad things at once. It signals to Google that a business engaged with the review as legitimate. It doubles the text on your profile devoted to the attack. And it shows the attackers - who are often watching - that you’re rattled, which in pile-on dynamics invites more.
Instead, flag every fake review through Google Business Profile, one by one, with your documentation ready. Be precise about which policy each review violates - “fake engagement” and “off-topic” are the usual fits. Precision matters more than most owners realize: if Google’s first reviewer decides there’s no violation, you get exactly one appeal per review, and a vague flag wastes it. Google removed 292 million policy-violating reviews in 2025, so the system does work - but it works on the quality of the flag, not the sincerity of the flagger. The mechanics, with the actual policy text, are in our walkthrough of what to do when a review violates Google’s policies.
If you want a single public signal for prospects who land on your profile mid-bombing, pick the one fake review with the most engagement and post one calm reply noting you have no record of this person as a customer and have reported the review. One. The fake-review response wording is a solved problem - the mistake isn’t the words, it’s the quantity.
Type 3 - the extortion
Everything in Type 2, plus: report through Google’s dedicated extortion reporting form, which launched in November 2025 and handles these cases far faster than the standard flag queue - removals sometimes land overnight. And do not pay. Not as a stalling tactic, not as a “cheap at $200” calculation. Paying marks you as a business that pays, and the going rate for another batch of reviews is lunch money. The economics are the whole story, and they’re covered in the dedicated post.
Hour 24-48: the holding pattern
Day two is quieter and more dangerous, because the urgent tasks are done and the crisis isn’t. What day two is for:
Close the loop with the real customer, if there is one. In Type 1 crises, the original reviewer often holds the off-ramp. A direct, non-public follow-up - a call beats an email - that fixes the actual problem converts a meaningful share of viral reviews into edited or deleted ones. Don’t ask for the edit. Fix the thing and let them decide.
Brief your team. Whoever answers your phone is about to field questions. Give them one approved sentence - something like “we’re aware of the fake reviews and Google is removing them” - and explicit instructions not to improvise beyond it. Staff freelancing on a live crisis is an underrated source of round two.
Watch the spread, don’t feed it. Search your business name on the platforms where your customers actually are. If a local Facebook group is discussing it, read and don’t post. The exception: a factual correction from your account is warranted when something concretely false is spreading - a health-code claim, a criminal accusation - and even then, two sentences, no heat.
Hour 48-72: the escalation decision
By day three you know what Google’s flag queue is doing, the bombing has either stopped or kept coming, and you can make the legal call with information instead of fear.
A lawyer is worth engaging when at least one of these is true: you can identify who’s behind a fake campaign (an ex-employee, a competitor, a specific person with a grudge); the reviews make provably false factual claims rather than expressing opinion; or the attack is ongoing and platform reporting hasn’t stopped it. An Ohio appeals court ruled in September 2024 that a coordinated batch of 60+ negative reviews against a law firm could be defamatory precisely because the claims were factual and checkable - coordinated plus false plus identifiable is the pattern that wins.
A lawyer is a mistake when the review is one angry real customer stating opinions. Defamation suits over reviews run five figures before trial, take a year or more, and routinely collide with anti-SLAPP statutes in states like California and Texas. The honest math - costs, timelines, Streisand risk - is laid out in our piece on whether you can sue over a false review . Read it before the consultation, not after.
Also in this window: if Google declined any of your flags, spend your one appeal per review carefully. Rewrite the flag around the specific policy language, attach the documentation from hour two, and submit. This is exactly why the hour-two evidence work mattered - appeals built on screenshots and timelines clear at a visibly higher rate than appeals built on indignation.
If the crisis is on Yelp or Facebook instead
The clock is the same; the mechanics differ enough to trip people up.
On Yelp, a bombing partly solves itself: most attack accounts are brand-new with empty profiles, which is precisely what Yelp’s recommendation software buries automatically. Check the not-recommended section before you panic - half the attack may already be invisible. (We’ve written up how the Yelp filter actually works separately.) For reviews that survive the filter, Yelp’s report function responds well to terms-of-service framing - no consumer experience, harassment - and badly to “this hurts my business.” Yelp also activates an Unusual Activity Alert on pages getting media-driven pile-ons, which freezes the damage better than anything you could post.
On Facebook, you have an option Google never gives you: turning Reviews off entirely. For a Type 2 bombing it’s a legitimate circuit breaker - flip it off, let the attack exhaust itself against a wall for a week, flip it back. The trade is that your existing recommendations disappear from view while it’s off, so it’s a tourniquet, not a strategy. Use it when the inflow rate is beating the removal rate and nowhere else.
What stays constant across all three platforms: document first, respond once at most, and never argue in comment threads, which Facebook in particular serves up as engagement bait. The algorithm rewards exactly the behavior that hurts you.
A worked example, start to finish
Caldera Hot Yoga, a two-studio operation in Boise, hit the full sequence last spring. A member was charged a $40 late-cancellation fee, argued with the front desk, filmed the argument, and posted it. The video did modest numbers - 80,000 views - but enough. Within 48 hours: her real 1-star review, plus 14 more 1-stars from accounts with no booking history, several referencing “how they treat people” in nearly identical phrasing. Rating: 4.8 to 3.9.
The owner ran the playbook. Hour one: diagnosed a Type 1 with a Type 2 riding on it. Hours two through five: screenshots, profile URLs, timeline. Hour 20, one public response on the real review:
“Dana, the fee is real but the way the conversation went wasn’t okay, and that’s on us - I’ve watched the video too. I’ve refunded the $40 and we’re changing how we handle fee disputes at the desk: staff can now waive a first late-cancel without calling a manager. If you’re open to it, I’d like to hear the rest directly. - Priya, owner.”
The 14 fake reviews got flagged with documentation, not responses. Eleven came down within nine days, two more on appeal, one stuck. Dana didn’t delete her review - but she edited it to mention the refund and the policy change, which honestly reads better for Caldera than a deletion would have. Ninety days out the studio sat at 4.6, and the response had been screenshotted into the same local Facebook group that spread the original video, this time approvingly.
Note what the owner never did: no statement post, no replies to the pile-on, no lawyer. The crisis got 72 hours of disciplined sequence and then it got starved.
The part nobody tells you
Most review crises aren’t crises. Three bad reviews in a week feels like an emergency from inside the business and reads as noise from outside it. Before you run any of this playbook, ask one calibration question: would a stranger scrolling your profile cold notice anything wrong? If the answer is no - if your rating moved a tenth of a point - then what you have is a bad week, and the correct playbook is the ordinary one: respond well, respond once, move on.
The other thing: the playbook ends at hour 72, but the profile doesn’t reset. Removed reviews leave no scar, but the surviving real ones sit in your recent-review window for months, and the only thing that moves them down is fresh review velocity. The businesses that recover fastest from a crisis are the ones that were already asking happy customers for reviews every week before it hit - not because the old reviews dilute the bad ones mathematically, but because a profile with steady recent activity makes a 72-hour anomaly look like exactly that.
So the real first step of crisis response happens months before the crisis: build the review pipeline now, while nothing is wrong. Sandbags are cheap until it’s raining.