Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Fake clicks

Click injection and click spam

Clicks are fired in the background by an app, script or hidden page, without the user seeing or choosing anything.

The short answer, from The Arbitrage Desk fraud map

How it works

With click spam, code on a device or page reports clicks that the user never made, sometimes thousands for every real one, hoping some will be credited. With click injection, software waits for a moment when a click would be valuable and inserts one just in time to claim the credit. Both terms come from mobile app advertising but the idea carries over to search feeds: a hidden frame or background process loads a feed page and triggers the ad click unseen.

The user is real, the device is real and the network is a home or mobile connection, which is why this is hard to filter by reputation alone. What is missing is any sign of a person: no visible page, no mouse or touch movement, no time spent reading.

Who pays for it

Advertisers pay for clicks nobody made. Traffic buyers pay too, because click spam also steals credit in their tracker: sales that would have happened anyway are attributed to the fraudulent source.

Who does it, and why

Makers of free apps, extensions and scripts who add a hidden revenue stream, and traffic networks that resell that activity as "pop" or "redirect" traffic.

Warning signs

  • Clicks with no matching page view, or page views that last a fraction of a second.
  • Click volumes far above what the visible audience of the app or site could produce.
  • No mouse, touch or scroll events before the click.
  • Conversions credited to a source seconds after the click, in implausibly consistent timing.

Defences

  • Require visible, user-started navigation for any source sending traffic to a feed page.
  • Measure engagement signals (scrolling, touch, time on page) before the ad click, not just the click.
  • Avoid buying from networks whose inventory is mostly background or pop traffic.
  • Reconcile tracker clicks against feed-reported clicks per Sub ID to spot inflation.

An example

Real case (alleged): in 2010 Microsoft sued over what it called click laundering, saying malware and scripts had produced ad clicks, some from users tricked into clicking without knowing, and then disguised where they came from. Microsoft said advertisers could have lost hundreds of thousands of dollars if it had gone unnoticed.

Documented cases

Sources