Is your ad reaching a human?

A taxonomy of theft

According to Spider Labs, global ad fraud cost $32.6 billion last year. Fraudlogix, analysing 105.7 billion impressions, found a global invalid traffic rate of 20.64 per cent. For a mid-sized advertiser with a $500 000 digital budget, as much as $150 000 may be flowing to bots and spoofed inventory, year after year, entirely undetected.

How do fraudsters operate? Commonly used tactics include:

Click fraud

The broadest category. Automated bots or paid human “click farms” repeatedly click pay-per-click ads to drain a competitor’s budget or generate fraudulent revenue for the hosting site. Beyond the direct waste, inflated click signals corrupt bidding algorithms, quietly pushing future spend towards lower-quality placements.

Affiliate fraud and cookie stuffing

Fraudsters secretly drop tracking cookies onto users’ browsers so that when a purchase is made later (through an entirely unrelated route), they claim the commission. A related tactic, ad hijacking, redirects a brand’s own paid search traffic through fraudulent affiliate links, charging the advertiser to acquire its own customers.

Made-for-advertising (MFA) sites

Sites built not to serve readers but to host ads: AI-generated content stuffed with ad units, monetised by buying cheap traffic and reselling it as premium inventory. MFA sites now represent around 21 per cent of all programmatic impressions, delivering far less genuine human attention than they bill for.

SDK spoofing

Prevalent in mobile advertising. Fraudsters exploit the software development kits embedded in apps to generate fake signals mimicking real installs, clicks, and in-app events without any genuine user interaction. A single infected device can simulate thousands of installs per day.

Pixel stuffing

An ad served in a 1×1-pixel frame is invisible to the human eye, but the ad server records an “ad served”, and you receive the bill.

Ad stacking

Dozens of ads are layered in a single slot. Only the top creative is seen, but every advertiser in the stack is charged for the impression.

Domain spoofing

Low-quality, largely unvisited sites masquerade as premium publishers (such as the BBC, the Financial Times, or the Guardian) within automated buying systems. This means brands pay premium prices to reach audiences that do not exist.

Click injection

Malicious apps (particularly prevalent on Android devices) fire fake clicks in the milliseconds before an app installation completes, stealing attribution credit for customers the advertiser was about to acquire. Industry data suggests this accounts for a significant share of global invalid traffic.

Hidden ads

Ads served as impressions never intended to be viewed by humans, especially when apps load web pages.

Why the ‘safety nets’ are tearing

Most marketing departments find solace in having purchased ‘ad verification’ or ‘brand safety’ tools. Most of these tools operate on a negative model, blocking known bad actors from a list. But fraudsters innovate faster than lists can be updated.

Stop paying for ghosts. Start demanding proof of real people.

Let’s stop the ad fraud together. Please InMail me if you would like a demo of our platform or proprietary systems that will help you get your marketing budget back.