I'm wondering how they found out it was someone from OpenTable.
Detecting someone using multiple fake accounts (maybe from the same IP) is one thing, but how to track its origin? Did they use approximate location of the IP and saw it's close to OpenTable offices?