Listed players
SST2.44▼ -7.58%TIG40.00▲ +3.90%TEAD0.56▲ +3.77%PERI8.50▼ -2.97%TBLA3.23▼ -2.71%INUV0.57▼ -1.74%AV10.06▼ -1.59%GOOGL343.50▲ +1.56%SNAP5.58▼ -1.24%PINS19.26▼ -1.03%MSFT517.53▲ +0.92%PPLI41.28▲ +0.81%IOS32.24▲ +0.44%META728.08▲ +0.30%GDDY97.21▲ +0.24%DV13.49▲ 0.00%MCHX1.29▲ 0.00%
Ticker byClearTrust

Fraud & invalid traffic

Click injection

Click injection is fraud in which software on a user's device inserts a fake ad click the user never made, usually to steal credit for an action already under way.

The short answer, from the The Arbitrage Desk glossary

Click injection began as a mobile app fraud: a malicious app notices that the user is installing another app and fires a fake ad click at the last second, so the fraudster is credited with causing the install.

The same idea appears around search feeds. Software on the device, such as adware or a rogue browser extension, generates a click or a search that the person did not choose. The user may be reading something else entirely while the program triggers a visit to a lander or a click on a sponsored listing. Because it happens on a real person's device, on a real network, it looks human.

The tell-tale signs are in timing and context: clicks with no page interaction before them, clicks arriving faster than a person could read, and referrer or Click ID data that does not fit a normal journey. Advertisers see visits that leave instantly.

Defences are conceptual here: measure the time and events between page load and click, compare claimed and observed device signals, and judge sources on advertiser conversion quality. It is a form of SIVT, closely related to click spam and search hijacking.

Think of it like this

It is a tout who slips his business card into your hand just as you walk into a shop you were already going to, then claims commission for bringing you.

Related terms

Sources: MRC Invalid Traffic Detection and Filtration Standards Addendum (June 2020 update), Google Ad Traffic Quality: invalid activity