Home
» News
»
What Is Ad Fraud? How It Works and How to Spot It
What Is Ad Fraud? How It Works and How to Spot It
Ad fraud is deliberate activity that makes digital advertising look more valuable or more legitimate than it really is. It can create fake impressions, fake clicks, fake conversions, or counterfeit ad inventory so that money is spent on activity that did not come from a genuine potential customer. The most important practical point is that not every suspicious click or impression is fraud: platforms use the broader term invalid traffic for activity that does not reflect genuine interest, and that category can include accidental clicks as well as intentional manipulation. Google, for example, explicitly says invalid traffic includes non-human traffic, accidental clicks, and fraudulent placements such as clickjacking or ad stacking. See Google Ads' definition of invalid traffic and Google AdSense's invalid traffic guidance.
An analyst compares traffic spikes, click-through rate, conversions, and supply-chain warning signs before deciding whether unusual ad activity needs investigation.
How ad fraud works
Digital advertising often involves several parties between an advertiser and the site, app, or connected-TV service where an ad appears. That complexity creates opportunities for bad actors to imitate real users, disguise low-quality inventory, or misrepresent who is selling an impression.
In a simple legitimate transaction, a real person visits a real publisher, an ad opportunity is offered through authorized systems, an advertiser bids, the ad appears, and any click or conversion reflects genuine user behavior. Ad fraud breaks one or more parts of that chain.
Bots and automated traffic
Software can load pages, trigger ad impressions, click ads, or imitate browsing behavior without a real customer behind the activity. Some automation is harmless and identifiable, such as legitimate search-engine crawling. Fraudulent automation is designed to look valuable to advertising systems or to create revenue for the party generating the traffic. Google lists automated clicking tools, robots, and deceptive software among examples of invalid traffic.
Click fraud
Click fraud occurs when clicks are generated without genuine buying intent. The source could be automated software, coordinated human click activity, or a publisher manipulating users into clicking. A sudden rise in click-through rate is not proof by itself. A promotional event, a new creative, or highly relevant targeting can also increase clicks. The warning becomes stronger when high click volume arrives with weak engagement, no downstream conversions, repetitive behavior, or an implausible traffic source.
Ad stacking and clickjacking
In ad stacking, multiple ads can be layered in the same visual space so that only one is actually visible while more than one impression may be counted. Clickjacking uses hidden or deceptive elements to cause a user to click something they did not intend to click. These are examples of fraudulent placement patterns Google identifies in its invalid-traffic documentation.
Domain spoofing and counterfeit inventory
A fraudster may make ad inventory appear to come from a legitimate publisher when it actually comes from another site, app, or unauthorized seller. This matters most in programmatic buying, where advertisers may be purchasing impressions through automated exchanges rather than negotiating directly with a publisher.
IAB Tech Lab created ads.txt and app-ads.txt so publishers and app developers can publicly list the companies authorized to sell their inventory. IAB Tech Lab says the goal is to improve supply-chain transparency and make counterfeit inventory harder to sell. It also maintains sellers.json and the OpenRTB SupplyChain object, which help buyers identify sellers and intermediaries involved in programmatic transactions.
Fake or manipulated conversions
Some schemes go beyond impressions and clicks. Fraudulent systems may fabricate installs, registrations, purchases, lead submissions, or other conversion events. This is especially relevant when advertisers pay partners based on an action rather than an impression. A conversion count that rises sharply while revenue quality, retention, payment success, or customer verification collapses deserves closer inspection.
Ad fraud vs. invalid traffic: why the distinction matters
For advertisers and publishers, the terms are related but not identical. Invalid traffic is the broader operational category. It can include intentional fraud, but it can also include accidental clicks, repeated interactions, or other activity a platform decides should not be billed or monetized.
This distinction prevents a common mistake: treating every anomaly as evidence of criminal or malicious behavior. A badly placed mobile ad can cause accidental taps. An internal QA team can accidentally generate test traffic. A monitoring service can repeatedly load pages. Those events can still be invalid for advertising measurement, but intent must be established before calling them fraud.
Common warning signs of possible ad fraud
Signal
Why it may matter
What else could explain it
Sudden traffic spike
Automated or purchased traffic can arrive in concentrated bursts.
A viral post, press coverage, seasonality, or a successful campaign.
Very high click-through rate
Repeated or automated clicking can inflate clicks.
Better creative, tighter targeting, or a high-intent audience.
Clicks rise but conversions do not
The clicks may not come from genuine prospects.
Landing-page problems, pricing changes, broken tracking, or poor offer fit.
Many visits with nearly identical behavior
Bots often repeat timing, page paths, or device patterns.
Kiosks, enterprise networks, QA systems, or legitimate automation.
Traffic from an unfamiliar source
Low-quality traffic sellers can introduce invalid activity.
A new referral, partner, syndication deal, or regional campaign.
Inventory seller does not match authorization records
The impression may be misrepresented or sold through an unauthorized path.
Outdated configuration or a legitimate relationship not yet reflected in public records.
How advertisers can spot suspicious activity
Start by comparing ad-platform data with independent business outcomes. If clicks increase 300% but qualified leads, product views, checkout starts, or revenue remain flat, investigate the source rather than assuming the campaign suddenly became more efficient. The exact metrics depend on the business: an ecommerce advertiser should care about purchases and revenue quality, while a B2B advertiser may care more about verified leads and sales acceptance.
Segment the data. Compare campaign, placement, site or app, device, geography, hour of day, audience, and referral source. A blended account average can hide a single problematic placement. Google recommends traffic segmentation because it helps publishers understand sources and identify anomalies; the same analytical principle is useful to advertisers reviewing campaign quality. See Google's traffic segmentation guidance.
Then check whether the supply path makes sense. For web inventory, compare sellers with the publisher's ads.txt entries when that standard is available. For app inventory, check app-ads.txt. For deeper programmatic analysis, sellers.json and SupplyChain data can help identify intermediaries. These standards do not guarantee that every impression is genuine, but they make certain forms of misrepresentation easier to detect.
How publishers can spot and reduce invalid traffic
Publishers should watch traffic sources, ad units, pages, and unusual user behavior instead of monitoring only total revenue. Google advises publishers to understand where visitors come from, separate traffic sources, identify bot activity, and use trusted traffic partners. Its guidance also warns that paid-to-click, paid-to-surf, auto-surf, and click-exchange programs can generate prohibited invalid activity. See Google's clean-traffic guidance and its guidance on traffic exchange programs.
Testing practices matter too. Publishers should not click their own live ads to make sure they work. Google specifically warns against self-clicking and recommends test-ad mechanisms for AdMob development rather than interacting with live ads. More broadly, QA teams should separate testing from production advertising whenever the platform provides a supported method.
What to do when you suspect ad fraud
Do not block or accuse a partner based on one metric. First confirm that tracking is working correctly. A broken conversion tag, consent change, app release, checkout error, or analytics migration can create patterns that look like fraud.
Next, isolate the suspicious slice of traffic. Save timestamps, placement IDs, campaign IDs, referral sources, device information, server logs, and downstream conversion outcomes where available. If the issue appears tied to a specific traffic seller, exchange, placement, app, or publisher, reduce or pause that source while the investigation continues. For publishers using Google monetization, Google recommends reviewing site logs when unusual traffic appears; see Google's invalid-traffic FAQ.
Finally, report the activity through the platform's supported process and preserve evidence. Avoid trying to reverse-engineer anti-fraud filters or assuming you can identify every invalid event yourself. Google notes that user identity and intent cannot always be determined and that not all invalid traffic can necessarily be excluded proactively. That limitation is one reason multi-signal analysis is more reliable than a single threshold.
A practical example
Suppose a small online retailer normally gets 8,000 paid-ad clicks a week with a 2.5% purchase rate. One week, clicks jump to 20,000 but purchases barely change. That alone does not prove fraud. The retailer should first check whether conversion tracking broke, whether a new campaign launched, and whether the landing page changed.
If tracking is healthy, the retailer can segment the extra clicks. Imagine most of the increase comes from one unfamiliar placement, during a narrow overnight window, with repetitive device characteristics and almost no product-page activity. That combination is much more suspicious than the headline click spike. The appropriate response is to isolate or pause the source, compare platform data with server and commerce records, and ask the ad platform or media partner to investigate.
Bottom line
Ad fraud is intentional manipulation of digital advertising activity or inventory for financial gain or advantage. Bots, click fraud, deceptive placements, counterfeit inventory, and fake conversions are common mechanisms. The strongest way to spot it is not to hunt for one magic metric, but to compare multiple signals: traffic source, behavior, click quality, conversion quality, supply-chain authorization, and business outcomes.
For advertisers, that means measuring what happens after the click and validating where inventory came from. For publishers, it means monitoring traffic sources, avoiding questionable traffic-acquisition schemes, using supported testing methods, and keeping authorized-seller records accurate. Most importantly, treat anomalies as a reason to investigate—not as automatic proof of fraud.