Glossary Term

Click Fraud

glossary click fraud featured

Click fraud is the deliberate or automated clicking of pay-per-click ads by someone with no genuine interest in the advertiser’s offer. The clicks are charged as real traffic, so the advertiser pays for visits that can never convert. Motives split into two: draining a competitor’s budget, or generating fraudulent revenue for the site or app showing the ad.

Why Click Fraud Matters

Click fraud takes money directly out of a working campaign and corrupts the data used to manage it. A fraudulent click costs the same as a real one, but produces no revenue.

The damage compounds beyond the wasted spend. Fake clicks inflate click volume and depress conversion rate, so a campaign that is performing well looks like it is failing. Automated bidding makes this worse. Google Ads Smart Bidding and Meta Advantage+ optimize toward conversion signals, so a channel poisoned by fraudulent clicks trains the algorithm to bid on the wrong audiences.

Juniper Research estimated advertisers lost $84 billion to ad fraud in 2023 and projected that figure to reach $172 billion by 2028. Click fraud is one component of that total, alongside impression and attribution fraud.

Smaller advertisers feel it hardest. A budget of $100 a day exhausts quickly under sustained fraudulent clicking, and daily caps mean the real audience never sees the ad.

Types of Click Fraud

  • Competitor click fraud. A rival clicks your ads repeatedly to exhaust the daily budget and remove you from the auction. This violates Google Ads policy and is traceable through IP and device patterns.
  • Publisher fraud. A site or app owner in a display or affiliate network clicks the ads they host, or pays others to, because they earn per click. Also called network click fraud.
  • Click farms. Groups of paid workers manually click ads on banks of real devices. Because the clicks come from genuine hardware and human behavior, they are harder to filter than bot traffic.
  • Botnets. Networks of malware-infected machines click ads in the background without the owner’s knowledge. Distributed residential IP addresses make the traffic look organic.
  • Click injection. A mobile-specific attack. A malicious Android app detects an install in progress and fires a fake click just before it completes, claiming the install attribution and the payout.
  • Click spamming. Also called click flooding. Fake clicks are fired at scale on behalf of users who never saw an ad, so the fraudster wins last-click credit for organic installs.

Click Fraud vs Invalid Traffic

Invalid traffic is the broader category. Click fraud is the subset that is deliberate.

Google uses “invalid clicks” to describe any click it does not consider legitimate, including accidental double clicks, advertiser test clicks, and clicks from known crawlers. Most of these carry no malicious intent.

The Media Rating Council and IAB split invalid traffic into two tiers:

  • GIVT (General Invalid Traffic) is caught by routine filtration. It covers declared bots and spiders on the IAB/ABC International Spiders and Bots List, data center IP addresses, and known browser pre-rendering.
  • SIVT (Sophisticated Invalid Traffic) requires advanced analytics to detect. It covers hijacked devices, malware-driven clicks, domain spoofing, ad stacking, and click injection.

Click fraud lives almost entirely in the SIVT tier. Google filters invalid clicks before billing and refunds ones detected after the fact as invalid activity credits, but the platform’s own filtering is tuned for GIVT and the SIVT patterns it recognizes. Novel fraud gets through.

How to Detect Click Fraud

  1. Check the invalid click columns in Google Ads. Add “Invalid clicks” and “Invalid click rate” to your campaign column set. These show what Google already filtered, not what it missed, so a high number signals you are being targeted.
  2. Look for a CTR spike with no matching conversion lift. A sharp rise in clicks while conversions stay flat is the clearest single signal.
  3. Segment traffic by IP address and network in your server logs or analytics. Repeat clicks from one address, or from a range belonging to a hosting provider rather than a consumer ISP, indicate automation.
  4. Check session behavior on the landing page. Sessions with zero seconds of engagement, no scroll, and a single pageview at high volume are not human.
  5. Compare geography against targeting. Clicks from regions the campaign does not target, or heavy volume from a country where you sell nothing, point at click farms.
  6. Look at timing patterns. Human clicking is irregular. Clicks at near-identical intervals, or a flat volume across overnight hours, indicate a script.

Link-level data helps here because it sits between the ad and the site. Bot filtering on tracked links screens automated clicks before they register as campaign traffic, so the click counts you report on stay closer to the real audience.

How to Prevent Click Fraud

Start with the platform controls, since they are free and immediate.

Exclude offending IP addresses in Google Ads at the campaign level. The limit is 500 IP addresses or ranges per campaign, so use it on repeat offenders rather than one-off clicks. Tighten geographic targeting to the regions you actually sell in, and set location options to “presence” rather than “presence or interest” so you exclude people merely searching about a location.

On the Display Network, review the placement report regularly and exclude low-quality sites and apps. Mobile app inventory is where most display click fraud concentrates. Excluding the entire app category is a legitimate move if you have no reason to advertise there.

Beyond platform settings:

  • File invalid click reports with Google Ads support when you have evidence. Credits are issued retroactively.
  • Adopt ads.txt if you also sell inventory, which limits domain spoofing.
  • Set realistic daily budgets and use bid caps so a single day of attack cannot drain a month of spend.
  • Use a dedicated fraud detection service for high-spend accounts, but read their methodology. Vendor estimates of fraud rates come from companies selling the fix.

Frequently Asked Questions

What is click fraud?

Click fraud is the practice of clicking pay-per-click ads with no genuine interest in the product, either to waste a competitor’s advertising budget or to earn per-click revenue as a publisher. The clicks bill at the normal cost per click, so the advertiser pays for traffic that cannot convert. It is a deliberate act, which separates it from accidental invalid clicks.

Is click fraud illegal?

It depends on jurisdiction and scale. Click fraud always violates the terms of service of Google Ads, Microsoft Advertising, and Meta, which is grounds for account termination. Large-scale operations have been prosecuted under computer fraud and wire fraud statutes in the US, and the US Department of Justice has charged botnet operators running ad fraud schemes. Individual competitors clicking a few ads are rarely prosecuted but are detectable.

Does Google refund click fraud?

Google filters clicks it identifies as invalid before they are billed, and issues credits for invalid activity detected after charging. Those credits appear as a line item in the billing summary. Google does not refund fraudulent clicks its systems fail to detect, which is why independent monitoring matters for large accounts.

How do you detect click fraud?

Watch for a rise in clicks without a matching rise in conversions, then segment the traffic by IP address, network, geography, and session duration. Repeat clicks from one address, traffic from data center IP ranges, and sessions with zero engagement are the strongest signals. Google Ads also reports invalid clicks and invalid click rate as columns, which show the volume the platform has already filtered.

What is the difference between click fraud and invalid traffic?

Invalid traffic covers every click a platform will not bill for, including accidental double clicks, advertiser test clicks, and known crawlers. Click fraud is the deliberate subset, carried out to waste budget or earn payouts. Most invalid traffic is harmless and automatically filtered; click fraud is adversarial and adapts to detection.

To keep bot clicks out of your campaign reporting, enable link protection on your tracked links at linkutm.