What it is
Ad fraud (aka invalid traffic) is when fake views, clicks, or installs make advertisers pay for attention that never came from real people. Think bots, hijacked devices, or shady sites simulating an audience.
How it happens
-
Bots & farms: scripts or low-paid crews auto-load pages and tap ads.
-
Injected ads: malware or rogue extensions swap or stack hidden ads.
-
Spoofed sources: traffic pretends to be from premium apps/sites.
Why it matters
-
Wasted budget and skewed reports
-
Lower ROI and bad targeting decisions
-
Funds flowing to criminal networks
Spot the signs
-
Sudden spikes from odd places (new sites, countries, devices)
-
High impressions with near-zero engagement or conversions
-
Identical click patterns and ultra-short “time on page”
Reduce the risk
-
Use allowlists of trusted sites/apps; block the rest
-
Require MFA/API keys for partners; rotate tokens
-
Enable fraud filters in your ad platform; review placement reports
-
Track post-click behavior (bounce, time, events), not just clicks
How to investigate suspicious traffic
- Compare placements, campaigns, countries, devices, and hours to find where the change began.
- Check post-click signals such as session duration, completed events, purchases, and refund rates instead of judging clicks alone.
- Preserve campaign IDs, click IDs, timestamps, user agents, referrers, and relevant server logs.
- Review the ad platform's invalid-traffic reports before assuming that every duplicate IP address is fraud.
- Report a documented pattern through the platform's investigation process and pause the affected placement if losses continue.
Invalid traffic can include bots, deliberate click fraud, duplicate events, and accidental clicks. A traffic spike or shared IP address is not proof by itself. Compromised devices in a botnet can also create realistic-looking activity, so use several independent signals before blocking a source.