Paper Mills Have Become a Due Diligence Problem
New evidence on authorship-for-sale networks shows why journals need due diligence workflows that start before publication and continue after exposure.
The uncomfortable lesson from the latest paper-mill evidence is not only that fraudulent authorship is available for purchase. It is that the damage can keep moving after the sale is exposed. Questionable papers may be cited, used in policy documents, pulled into patent filings, relied on by clinical guidance, and carried on author CVs long after editors first learn that a network exists.
A preprint posted on August 31, 2026 traced a known authorship-for-sale network and reported that, among nearly 2,000 publications in the dataset, 57 were cited in policy documents, 12 in clinical guidelines, and 480 in patents: https://arxiv.org/abs/2608.30613. The authors also report that more than 90 percent of the traced authors continued publishing after the network was publicly exposed in 2022, and 23 percent were linked to a grant.
Those figures should be read with the caution due to a preprint and a specific case study. They should also change the operational question for journals. Paper-mill risk is not a single manuscript-screening problem. It is a due diligence problem that connects submission checks, authorship changes, reviewer selection, special issue oversight, post-publication investigation, corrections, retractions, indexing feeds, and communication with institutions and funders.
Start Before the Allegation
Many journal workflows still behave as if the serious integrity work begins only when a reader, reviewer, sleuth, publisher staff member, or indexer raises a concern. That is too late for a market designed to exploit predictable editorial routines. By the time a concern arrives, the paper may already have passed through peer review, generated metadata, appeared in indexes, gained citations, and been presented as career evidence by the listed authors.
The 2026 BuyTheBy preprint assembled 18,710 text-based paper-mill advertisements and 51,812 timestamped prices from seven businesses operating across several countries: https://arxiv.org/html/2604.24576v1. Retraction Watch summarized the dataset in April, noting reported first-author slot prices ranging from $56 to $5,631 and advertisements collected from social platforms and paper-mill websites: https://retractionwatch.com/2026/04/23/paper-mill-authorship-cost-advertisements-buytheby-dataset/.
The exact prices are less important for journal leaders than the market signal. These are products with sales copy, changing inventory, geography, price discrimination, and tactics for avoiding detection. A workflow that depends only on a vigilant handling editor seeing something odd in one manuscript will miss the commercial structure behind the submission.
Separate Three Questions
When a suspect submission appears, editorial teams often collapse three questions into one: is the paper fraudulent, should the journal act, and what should the journal do about the people involved? Treating those as one decision creates paralysis. Evidence can be strong enough to warrant an editorial hold before it is strong enough for a public accusation. A publication record can require correction even when the journal cannot prove every detail of the transaction. A reviewer or editor may need removal from future assignments while an institution investigates the broader conduct question.
- Manuscript question: does this article carry signals that make the research record unreliable or unverifiable?
- Process question: did the submission, authorship, review, or editorial handling path show manipulation, concealment, or unmanaged conflicts?
- Participant question: do named authors, reviewers, editors, or third parties require role restrictions, institutional referral, or future monitoring?
Separating the questions helps journals move at the right speed. The manuscript question may need immediate action to protect readers. The process question may reveal weaknesses in guest editor supervision, author contribution checks, or late-stage authorship changes. The participant question may require careful evidence handling, privacy discipline, and communication outside the journal office.
Retraction Is Not the Whole Remedy
Retraction remains essential when the literature is unreliable, but it is not a complete containment strategy. A retracted article can remain in reference lists, institutional reports, author profiles, grant narratives, patent citations, and training datasets. A notice can explain what is wrong without reaching every downstream system that already consumed the record.
COPE and STM have warned for years that paper mills require changes to investigation and retraction practice, including faster coordinated handling and recognition that these cases differ from ordinary one-paper disputes: https://publicationethics.org/guidance/research-and-reports/paper-mills-research. STM also reported in January 2026 that publishers are investing in dedicated integrity teams, screening protocols, shared tools, and coordination because threats have scaled and industrialized: https://stm-assoc.org/new-report-documents-publisher-investment-in-research-integrity-infrastructure/.
For a journal, the practical implication is blunt: the post-publication file needs to be designed for follow-through. That file should hold the concern history, author responses, reviewer and editor assignment records, contribution statements, image or data checks, institutional correspondence, decision rationale, notice text, metadata-update evidence, and index notifications. Without that file, each new question reopens the same hunt for context.
Watch the Middle of the Workflow
Paper-mill defenses often concentrate at submission screening and final retraction. The middle of the workflow deserves more attention. Fraudulent or purchased manuscripts can exploit the points where journals are trying to be efficient: special issue intake, suggested reviewers, major revisions, changes to corresponding author details, added coauthors, rushed acceptance after a narrow revision, and production queries that seem administrative rather than editorial.
The most useful controls are not theatrical. They are boring in the way strong operations are boring. Require contribution changes to be explained and approved before acceptance. Keep reviewer identity and conflict checks visible to editors. Compare author affiliations, email domains, ORCID records, funding statements, ethics approvals, and data availability claims for internal consistency. Give production staff an escalation route when a late authorship or metadata change feels wrong. Monitor guest-edited collections for acceptance patterns, reviewer reuse, topic drift, and unexplained speed.
None of this proves misconduct by itself. That is the point. Due diligence is not a machine that labels people guilty. It is a set of records and decisions that allows a journal to notice when several weak signals point in the same direction and to act proportionately before publication hardens the record.
Funders and Institutions Are Part of the Case
The August 2026 due-diligence preprint matters because it follows questionable research into places journals do not control. If a suspect network can still shape grants, policy references, patents, or clinical guidance, then the journal response cannot end at the publisher boundary. Editors need a documented route for institutional notification, funder contact where appropriate, and updates to third-party systems when the article record changes.
That does not mean journals should behave like investigative agencies. It means they should make their own evidence portable and precise. A vague email saying a paper is under concern is far less useful than a concise chronology: submission date, author changes, reviewer anomalies, image or data issues, correspondence attempts, editorial decisions, and the current publication status. Institutions and funders cannot assess patterns if every journal sends a different kind of fragment.
Practical Takeaway for Journal Leaders
Run a paper-mill due-diligence audit on the parts of the workflow where accountability thins out. Pick one special issue, ten accepted articles with late authorship changes, ten papers with suggested-reviewer-heavy histories, and any article already tied to a post-publication concern. For each, ask whether the journal can reconstruct who made each decision, what evidence they saw, which integrity signals were checked, and where the final article metadata went.
If the answer depends on memory, inbox searches, or one staff member who knows the story, the workflow is not ready for industrialized fraud. Paper mills operate as markets. Journals do not need to respond with suspicion toward every author, but they do need market-aware records: consistent checks, clear escalation, repeatable evidence files, and post-publication metadata discipline. The goal is not perfect detection. The goal is to make manipulation harder, response faster, and the published record less hospitable to fraud after it has been noticed.