What Is Ad Fraud and How to Avoid It

What Is Ad Fraud and How to Avoid It

Ad fraud is any activity that generates ad impressions, clicks, or conversions that don't come from a real, interested person — usually created by bots, hijacked devices, or manipulated apps to collect ad spend that was never earned. It costs advertisers money for attention that was never paid, and it costs honest publishers reputation and revenue when fraud on other sites drags down trust in the whole market. If you buy or sell programmatic inventory, understanding what ad fraud looks like and how it works is the first step to keeping it out of your numbers.

The scale is not a rounding error. Juniper Research estimated advertisers would lose $84 billion to ad fraud in 2023, and the trend has kept climbing as fraud tactics get more automated. This guide covers what ad fraud actually is, how the main schemes work, how to spot it in your own data, and what practical steps reduce your exposure.

The fundamentals of ad fraud

At its core, ad fraud exploits how programmatic advertising pays for outcomes: an impression served, a click registered, an install recorded, a lead submitted. Every one of those events is worth money to someone, and the auction that decides who gets paid runs in milliseconds with limited ability to verify, in real time, that a human being actually did the thing being paid for. Fraud fills that gap.

It helps to separate two categories that get lumped together. Invalid traffic (IVT) is the broader term — any traffic that doesn't represent genuine user interest, whether or not anyone intended fraud. The Media Rating Council splits this into General Invalid Traffic (GIVT — known bots, crawlers, spiders that are relatively easy to filter with published lists) and Sophisticated Invalid Traffic (SIVT — traffic deliberately built to look human, which requires behavioral analysis to catch). Ad fraud, strictly speaking, is the intentional subset of SIVT: someone built or bought traffic specifically to collect ad revenue or burn a competitor's budget.

That distinction matters because it tells you where the money goes. A misconfigured crawler hitting your site isn't fraud, just noise to filter. A network of infected devices programmed to load ads in the background, generating billable impressions no one sees, is fraud — and it's designed to look exactly like a normal visitor in your logs.

How ad fraud works in practice

Most ad fraud schemes follow the same basic shape: generate traffic or interactions that resemble genuine user behavior closely enough to pass automated checks, then route the resulting ad spend to the fraudster. The mechanics differ by where in the funnel the fraud happens.

Bot traffic is the base layer. Fraudsters run scripts or botnets — networks of hijacked devices, often infected via malware without the owner's knowledge — that visit sites, load ad tags, and simulate scrolling, mouse movement, or clicks. Modern bots are built to defeat basic detection: they rotate IP addresses, spoof device and browser fingerprints, and mimic human timing patterns rather than firing requests at machine speed. This is what separates today's fraud traffic from the easily-filtered crawlers of a decade ago.

Click farms replace bots with real but cheap human labor — rooms of workers, often paid very little, tapping through ads or app installs on physical devices all day. Because the devices and IP addresses are real, click-farm traffic can pass checks that only look for automation signatures, which is why some verification vendors also track behavioral patterns like unnaturally short session lengths or immediate bounces.

Domain spoofing targets the supply side of programmatic buying. A fraudster runs a low-quality or fabricated site but sends bid requests that claim to originate from a premium, well-known domain, so advertisers believe they're buying reach on a trusted property and pay premium rates for it. The IAB Tech Lab's ads.txt and app-ads.txt standards exist specifically to counter this, by letting a domain publish which sellers are authorized to sell its inventory.

Ad stacking and pixel stuffing manipulate placement rather than the visitor. Ad stacking layers multiple ads on top of each other in a single slot so only the top one is visible, but every layer gets billed as an impression. Pixel stuffing shrinks an ad down to a 1x1 pixel — technically "served," never actually seen, and billed all the same.

SDK spoofing and click injection are mobile-specific. Spoofing fabricates install and event data from an app that never actually ran the ad, entirely server-side. Click injection detects a genuine app install in progress and fires a fraudulent click microseconds before it completes, so the fraudster's source gets credited for an install someone else's ad actually drove.

Who ad fraud hurts, and how

Advertisers lose the most obvious way: budget spent on impressions, clicks, or installs that never had a chance to convert, because there was no real person on the other end. That's direct, quantifiable waste, and it compounds — a campaign optimizing toward fraud-inflated engagement metrics ends up allocating more budget toward the fraudulent sources, not less.

Publishers carry a less visible cost. Legitimate publishers compete in the same auctions as fraudulent ones, and every dollar an advertiser loses to fraud is a dollar of trust the whole channel has to earn back — often through lower bids, stricter buyer requirements, or exclusion lists that catch honest sites along with bad ones. A publisher whose own traffic gets contaminated with bot visits (through a compromised plugin, incentivized traffic, or a bad traffic-exchange scheme) can also see accounts suspended by ad networks, even if the fraud wasn't intentional.

Ad networks and exchanges sit in the middle and absorb reputational risk. Chronic fraud on a platform pushes advertisers toward walled gardens or direct deals they can verify more easily, which shrinks the open market everyone depends on.

What Is Ad Fraud and How to Avoid It

Common mistakes to avoid

Treating high CTR as automatically good. An unusually high click-through rate, especially with low downstream conversion, is one of the more reliable fraud signals — not a campaign win. Compare CTR against conversion rate and session quality before congratulating yourself on the number.

Relying only on IP blocklists. Blocklists catch known data-center and proxy traffic, but sophisticated fraud increasingly runs through residential proxies and real, if compromised, consumer devices. IP filtering is necessary, not sufficient.

Ignoring traffic source concentration. A campaign where a small number of sites, apps, or supply sources account for a disproportionate share of clicks or installs deserves a manual look, particularly if those sources weren't specifically targeted.

Skipping ads.txt / app-ads.txt verification. Buying inventory without checking that the seller is authorized on the publisher's ads.txt file leaves the door open to domain spoofing — a check that costs almost nothing to automate on the buy side.

Not using third-party verification. Verification vendors such as DoubleVerify, Integral Ad Science, and HUMAN Security specialize in detecting sophisticated invalid traffic that in-house checks typically miss, and most large exchanges support their measurement tags natively.

Setting fraud filters once and forgetting them. Fraud tactics evolve constantly to get around whatever's currently blocking them. Filters and blocklists need periodic review, not a one-time setup.

Fraud type Where it happens Typical signal
Bot traffic Site or app visits Non-human timing, fingerprint anomalies
Click farms Clicks, app installs Real devices, abnormally short sessions
Domain spoofing Programmatic bid requests Missing/mismatched ads.txt entry
Ad stacking / pixel stuffing Ad rendering High impression count, near-zero viewability
SDK spoofing / click injection Mobile installs Install credited with no real engagement

FAQ

Is ad fraud illegal?

In most jurisdictions, deliberately fabricating ad traffic to collect payment is a form of fraud and can be prosecuted as such — the 3ve and Methbot cases resulted in criminal charges in the US. Enforcement is difficult, though, because operations are often run across borders through infrastructure that's hard to trace.

How much of my traffic is likely fraudulent?

It varies widely by traffic source, vertical, and how the traffic was acquired; there's no single reliable industry-wide number to quote for every site. The more useful exercise is measuring your own traffic with a verification tool rather than assuming an industry average applies to you.

Can small publishers and advertisers do anything without expensive tools?

Yes. Publishing and checking ads.txt/app-ads.txt, watching for anomalies in CTR-versus-conversion and session length, and using an exchange's built-in invalid-traffic filtering cover a meaningful share of common fraud without a dedicated budget.

Does ad fraud only affect display ads?

No. It shows up in mobile app install campaigns, video, native, and connected TV inventory as well — the mechanics shift (click injection is mobile-specific, for example), but the underlying incentive to fake engagement for a payout exists across every paid format.

What's the difference between invalid traffic and ad fraud?

Invalid traffic is the broader category — any non-genuine traffic, including harmless bots and crawlers. Ad fraud is the subset that's deliberately engineered to extract ad revenue or waste a competitor's budget.

Conclusion

Ad fraud is traffic and interactions manufactured to look like real user demand so someone can collect ad spend that was never actually earned by reaching a real person. It ranges from crude bot visits to sophisticated schemes like domain spoofing and click injection that are built specifically to defeat detection, and it costs both advertisers and honest publishers real money and trust. No single filter stops all of it, but ads.txt verification, behavioral monitoring beyond raw click counts, and periodic review of traffic sources catch a meaningful share of it.

Key takeaways

  • Ad fraud is the intentional subset of invalid traffic, built specifically to collect ad spend without a real person behind the impression, click, or install.
  • Common schemes include bot traffic, click farms, domain spoofing, ad stacking/pixel stuffing, and mobile SDK spoofing or click injection.
  • High CTR with weak conversion, and traffic concentrated in a few unexpected sources, are practical warning signs worth investigating.
  • ads.txt and app-ads.txt verification is a low-cost check against domain spoofing that any buyer can automate.
  • Fraud tactics evolve, so filters and blocklists need regular review rather than a one-time setup.

Share this article

Related articles