Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

The case files

Documented click fraud, search hijacking and feed abuse, newest first. Scale figures are as reported by the investigators at the time.

Presented byClearTrust· Traffic-quality scoring and ad-fraud prevention.
2025 · SEARCH · found by Infoblox (reported by KrebsOnSecurity)

Malicious "direct search" redirects on parked domains

Zero-click parking abuse: visitors to parked and typo domains sold on to scams and malware · In Infoblox's tests, over 90% of visits to parked domains led to scams, scareware, unwanted subscriptions or malware, against under 5% in a 2014 study; one actor held about 3,000 look-alike domains (Infoblox, 2025)

How it worked. With zero-click parking the visitor never sees a page of links. The parking system instantly sells the visit to the highest bidder and forwards the browser there. Infoblox found the system profiled each visitor first: people on home connections were passed down a chain of redirects to harmful pages, while visitors on VPNs or data-centre addresses were shown a harmless parking page, which hides the problem from investigators.

What happened. Published in December 2025. The researchers linked the shift to Google making parked-domain ads opt-in for advertisers during 2025, which pushed domain owners from Google's ad feed towards less policed "direct search" buyers.

The lesson. When a policed feed shuts, traffic does not vanish; it moves to buyers with fewer rules, so sellers must vet who is buying their redirects.

2023 · SEARCH · found by Adalytics

Adalytics: Google Search Partner Network findings

Brand-safety and transparency research on where search-partner ads appear (not a fraud ring) · About 36,600 sites carrying Google's custom search engine with ads; roughly 390 adult sites, more than 2,200 domains with piracy takedown notices and at least 197 Iranian domains (Adalytics, 2023)

How it worked. Advertisers who tick "search partners" in Google Ads let their search ads run on other companies' sites that embed Google's search box. Adalytics crawled those sites and reported big-brand and US government ads beside search results on adult, pirated-content and sanctioned-country sites, places the advertisers could not see in their reports at the time.

What happened. Google called the report's claims wildly exaggerated but, in December 2023, let advertisers switch off search partners for every campaign type, including Performance Max, until 1 March 2024. Wider placement reporting for search partners followed later.

The lesson. What advertisers cannot see, they eventually refuse to pay for; partner-network traffic lives or dies on transparency.

2020 · MIXED · found by Facebook (now Meta)

Facebook v. LeadCloak

Cloaking software sold to advertisers to hide the real landing page from ad review · Software used to hide scams involving COVID-19, cryptocurrency, diet pills, pharmaceuticals and fake news pages; also aimed at Google, Oath, WordPress and Shopify (Facebook, 2020)

How it worked. Cloaking is a bait and switch. The ad platform's reviewers are shown a harmless page, for example a sweater for sale, while real users who click the same ad are sent to a different, deceptive page. Facebook said LeadCloak sold this as a service to advertisers who could not pass review honestly.

What happened. Facebook sued the operator, Basant Gajjar, in federal court in California in April 2020 and disabled accounts linked to the service and its customers.

The lesson. If an ad platform's reviewer and a real user see different pages, the account is one audit away from a permanent ban, and so is any feed attached to it.

2020 · SEARCH · found by Microsoft 365 Defender Research Team

Adrozek

Browser-modifying malware that injected extra ads into search results · More than 30,000 devices a day at its August 2020 peak, spread from 159 domains, across Edge, Chrome, Firefox and Yandex Browser (Microsoft, 2020)

How it worked. Adrozek added browser extensions and altered browser files so that, when the user searched, its own ads appeared on top of the search engine's real ones. Clicking them sent the user to affiliate pages, and the operators were paid for the referred traffic.

What happened. Microsoft published the campaign's details in December 2020 and added detection. Infections were concentrated in Europe, South Asia and South-east Asia.

The lesson. Ad injection steals the click at the last moment, on the user's own screen, so neither the search engine nor the advertiser sees anything odd in its own logs.

2018 · WEB · found by Google and White Ops (now HUMAN), with the FBI and US Department of Homeland Security

3ve ("Eve")

Ad fraud run through malware-infected home computers and hijacked IP addresses · More than 1.7 million unique IP addresses under its control over a 10-day window (DHS/FBI alert, 2018)

How it worked. 3ve built fake websites and fake visitors at the same time. Two malware families did the work: one made infected home PCs act as relays so that data-centre bots appeared to browse from household connections, the other ran hidden browsers on the infected machines themselves. Ad money for the fake visits flowed to the operators.

What happened. In November 2018 US authorities announced indictments against eight people and seized the infrastructure, in a joint operation with industry.

The lesson. A home IP address proves nothing: it may be a relay for a server somewhere else, which is what a residential proxy is.

2017 · SEARCH · found by AdWords advertisers (class action, Northern District of California)

In re Google AdWords Litigation (parked domains and error pages)

Advertiser class action over undisclosed ad placement on parked domains and error pages · $22.5 million settlement covering 11 July 2004 to 31 March 2008 (announced 2017)

How it worked. Advertisers said Google had shown their ads on parked domains (addresses with little or no content) and on error pages reached by mistyped addresses, without telling them clearly, and had charged for the clicks. The claim was about disclosure and value, not about bots.

What happened. Judge Edward Davila gave preliminary approval on 9 March 2017. Class members were paid in proportion to what they had spent on those placements.

The lesson. Advertisers have objected to paying for parked-domain clicks for two decades, which helps explain why Google made parked domains opt-in for advertisers in 2025.

2017 · SEARCH · found by Check Point Research

Fireball

Browser hijacker bundled with free software to force searches through fake search engines · Check Point estimated more than 250 million infected computers, led by India (25.3 million) and Brazil (24.1 million) (Check Point, 2017)

How it worked. Fireball came bundled with free programs. It replaced the browser's home page and default search engine with look-alike search sites that passed each query on to Yahoo or Google, so the operator earned from the resulting ad traffic while tracking the user. Check Point attributed it to Rafotech, a Beijing digital marketing agency, and warned the same software could run any code on the machine.

What happened. Check Point published the findings in June 2017 with removal instructions. Its infection estimate was Check Point's own; treat the exact figure as one vendor's measurement.

The lesson. "Search traffic" from a bundled extension or installer is a red flag: ask every partner how the user came to have that search engine.

2016 · SEARCH · found by Bitdefender Labs

Redirector.Paco

Botnet that replaced real search results with a monetised custom search feed · More than 900,000 IP addresses infected since September 2014, mainly in India, Malaysia, Greece, the US, Italy, Pakistan, Brazil and Algeria (Bitdefender)

How it worked. The malware arrived inside tampered installers for popular free software and quietly changed the computer's proxy settings. From then on, when the victim used a popular search engine, the results page was swapped for one built on a custom search engine carrying AdSense for Search ads, so the operators collected a publisher's share of every sponsored click.

What happened. Bitdefender published its analysis and detection. The case is one of the clearest documented examples of a search feed itself being used as the cash-out point for malware.

The lesson. A feed partner whose "searches" come from users who never chose that search engine is running query fraud, however human the users are.

2013 · SEARCH · found by Microsoft Digital Crimes Unit and Symantec

Bamital

Search-hijacking and click-fraud botnet · More than 8 million computers attacked over two years (Microsoft, 2013)

How it worked. Bamital took over the search experience on infected machines. When people searched on Google, Bing or Yahoo and clicked a result, they could be diverted to sites the operators were paid to deliver traffic to; the malware could also produce ad clicks with no user involved at all.

What happened. Microsoft sued the unnamed operators on 31 January 2013 and, on 6 February, seized servers at hosting sites in Virginia and New Jersey with US Marshals. Victims who then searched were shown a page explaining how to clean their machine.

The lesson. Hijacked searches look like the best traffic there is (a real query from a real user), which is exactly why search hijacking pays.

2013 · SEARCH · found by Microsoft Digital Crimes Unit with Europol, the FBI and A10 Networks

ZeroAccess (Sirefef)

Peer-to-peer botnet for search hijacking and click fraud · Nearly 2 million infected computers, costing online advertisers upwards of $2.7 million a month (Microsoft, 2013)

How it worked. ZeroAccess infected PCs through booby-trapped downloads and fake software. It redirected people's search results on Google, Bing and Yahoo to sites of the operators' choosing and generated ad clicks in the background, billing advertisers for visits nobody intended to make.

What happened. In December 2013 Microsoft obtained a US court order to block 18 IP addresses and took over 49 domains, while Europol coordinated server seizures in Europe. Microsoft described the result as a disruption, not an elimination, because the botnet's machines could still talk to each other directly.

The lesson. Takedowns slow a botnet but rarely end it; buyers of search traffic need their own filtering.

2011 · SEARCH · found by FBI with Estonian police and industry partners

DNSChanger (Operation Ghost Click)

Malware that hijacked search-result clicks and swapped ads on infected computers · More than 4 million infected computers and at least $14 million in fraudulent advertising fees (US authorities, 2011)

How it worked. The malware changed a computer's DNS settings, the "phone book" that turns a site name into an address, to servers run by the gang. When a victim clicked a search result they could be taken to a different site that paid the gang for the visit, and ads on ordinary web pages were swapped for ads the gang was paid for.

What happened. Six Estonians were arrested and a Russian was charged in November 2011. The FBI kept clean replacement DNS servers running until 9 July 2012 so victims would not lose internet access, by which time about 300,000 machines were still infected.

The lesson. A real person on a real home computer can still be invalid traffic if malware, not the person, chose the destination.

2010 · SEARCH · found by Microsoft (adCenter)

Microsoft click-laundering lawsuit

Click laundering: invalid clicks disguised as coming from a legitimate publisher · Microsoft said advertisers could have lost hundreds of thousands of dollars had it gone undetected (Microsoft, 2010)

How it worked. Microsoft noticed unusual click patterns on two sites in its ad network. It alleged that clicks produced by malware and scripts, some from people tricked into clicking, were relabelled on the way so that they appeared to start on an approved site. Microsoft named a web publisher and its president as defendants alongside unidentified parties; these were allegations in a civil complaint.

What happened. Microsoft filed suit in the Western District of Washington in May 2010 and gave the technique the name "click laundering". We could not verify how the case ended.

The lesson. The label on a click (its referrer and publisher ID) can be forged, so quality checks have to test the visitor, not the paperwork.

2009 · SEARCH · found by Microsoft (adCenter)

Microsoft v. Lam (competitor click fraud)

Competitor click fraud on search ads to drain rivals' budgets, combined with lead selling · Microsoft sought $750,000 and said it had refunded about $1.5 million to affected advertisers (The Register, 2009)

How it worked. Microsoft alleged that three people in Vancouver repeatedly clicked rivals' search ads for car insurance and World of Warcraft terms through proxy servers that hid where the clicks came from. Once competitors' daily budgets ran out, the defendants' own ads moved up, and the visitors they captured were asked for contact details that were sold on as insurance leads.

What happened. Filed in Seattle federal court in June 2009, it was Microsoft's first click-fraud lawsuit. It was later reported settled on confidential terms.

The lesson. Click fraud is not always about earning from the click; exhausting a competitor's budget is a motive too, and lead generation gives it a pay-off.

2007 · SEARCH · found by Vulcan Golf and other trademark owners (lawsuit, Northern District of Illinois)

Vulcan Golf v. Google

Typosquatting lawsuit over ads on parked look-alike domains · A proposed nationwide class of trademark owners; class certification was denied in 2008

How it worked. The plaintiffs said that misspelt versions of their brand names had been registered, parked and filled with Google ads through AdSense for Domains, so that both the domain owner and Google earned when a lost visitor clicked. The legal question was whether the ad provider shares liability for typosquatting when it does not own the domain.

What happened. The court refused to certify a class in 2008, the parking companies named in the case settled, and in 2010 the court let the cybersquatting claim against Google itself go forward. We could not verify the final resolution.

The lesson. Monetising a domain that leans on someone else's trademark creates legal risk for everyone in the chain, including the feed.

2006 · SEARCH · found by Lane's Gifts & Collectibles, an Arkansas retailer, and other advertisers (class action)

Lane's Gifts & Collectibles v. Google

Advertiser class action over being billed for fraudulent clicks · A settlement fund of up to $90 million, including legal fees, paid to advertisers as advertising credits (reported 2006)

How it worked. Advertisers claimed that Google had charged them for clicks that were not from genuine prospective customers, and had not done enough to detect or refund them. The case was not about one fraud ring; it was about who should carry the cost of click fraud across the whole pay-per-click system.

What happened. Google agreed the settlement in March 2006 and a Miller County, Arkansas judge approved it in July 2006, calling it fair, reasonable and adequate despite objections that it was too small. Compensation came as advertising credits, not cash.

The lesson. The search engine, not the advertiser, is expected to filter and refund invalid clicks, and that expectation is why feeds now claw money back from partners who send bad traffic.

2006 · SEARCH · found by Checkmate Strategic Group and other advertisers (class action)

Checkmate Strategic Group v. Yahoo

Advertiser class action over click fraud on Yahoo (Overture) search ads · $4.95 million in plaintiffs' legal fees, plus uncapped refunds for proven fraudulent clicks back to January 2004 (reported June 2006)

How it worked. Advertisers alleged that Yahoo billed them for clicks produced by fraud. Under the settlement Yahoo agreed to look again at old complaints, stretching the window for reporting suspect clicks from 60 days to more than two years.

What happened. A federal judge in Los Angeles gave preliminary approval in June 2006. Yahoo paid the lawyers' fees, promised full refunds or credits for clicks it found to be fraudulent, put a retired judge in charge of reviewing claims and committed to work with the industry on a shared definition of click fraud.

The lesson. Refund rights only help if the advertiser can see and question the clicks, so transparency about where search ads ran matters as much as filtering.

2006 · SEARCH · found by Ben Edelman (independent researcher, then at Harvard)

Spyware clicks inside Yahoo's syndication chain

Syndication fraud: adware generating paid clicks through layers of search partners · Many dozens of documented examples; adware pop-ups bought for about 1.5 cents were turned into search clicks billed at 10 cents or more (Edelman, 2006)

How it worked. Yahoo's pay-per-click ads were passed to partners, who passed them to their own partners, and at the end of some chains sat adware on people's computers. The adware opened advertisers' pages by itself, so the advertiser was billed for a "click" although the person at the keyboard had clicked nothing. One documented chain ran from advertisers to Yahoo Overture to two intermediaries and then to the adware vendor 180solutions.

What happened. Edelman published screen recordings and packet logs of each chain. The findings fed the wider debate that produced the 2006 click-fraud settlements and pushed search engines to police who their partners' partners were.

The lesson. Every extra hop in a search syndication chain is a place where the true source of a click can be hidden; know every hop or do not buy the traffic.

2006 · SEARCH · found by Google click-quality and security engineers (published at USENIX HotBots, 2007)

Clickbot.A

Botnet click fraud aimed at syndicated search engines · More than 100,000 infected machines by mid-June 2006; Google put an upper bound of roughly $50,000 on the possible damage to its own advertisers (Daswani and Stoppelman, 2007)

How it worked. Infected home PCs were told to visit small "doorway" search sites run by the operator, who had signed up as a publisher with syndicated search engines. The bots then followed links that led, through several redirects, to real sponsored listings. Each machine clicked only a little, so no single computer looked unusual.

What happened. Google identified the pattern and marked the matching clicks as invalid so advertisers were not charged. The paper became a standard reference on "low-noise" click fraud.

The lesson. A botnet spreads fake clicks so thinly across real home computers that per-device limits will not catch it; the publisher account earning the money is the place to look.

2006 · WEB · found by US Federal Trade Commission

FTC v. Zango (formerly 180solutions)

Adware installed without proper consent to show ads and track browsing · More than 70 million installations and more than 6.9 billion pop-up ads; $3 million surrendered (FTC, 2006)

How it worked. Zango's software reached people's computers bundled with free games and screensavers, or through security holes, often without a clear explanation. It then watched what people browsed and showed pop-up ads, and it was built to be hard to remove.

What happened. In November 2006 Zango agreed to give up $3 million, to obtain express consent before any future install, to provide a working uninstall and to police its distributors.

The lesson. Traffic that comes from software the user never knowingly installed is not consenting traffic, and regulators treat the company that profits as responsible for its distributors.

2004 · WEB · found by Google

Google v. Auctions Expert International

Publisher click fraud: a site owner paying people to click the ads on its own pages · At least $50,000 in advertiser charges alleged; Google won a $75,000 judgment (MediaPost, 2005)

How it worked. A Houston-based AdSense publisher was accused of building a site mainly to carry Google ads and then hiring dozens of people to click them. Every click billed an advertiser and paid the publisher a share, although nobody clicking had any interest in the advertised products.

What happened. Google sued in November 2004, its first lawsuit over click fraud by a publisher. A California court (Santa Clara County Superior Court) awarded Google $75,000 against the company and its two founders in May 2005.

The lesson. The oldest trick in the book is Self-clicking by the party that earns from the click, which is why every feed contract bans it outright.