Lesson 8 of 8 · 9 min read · intermediate
Famous cases and what they teach
Documented cases of search click fraud and hijacking, from the 2006 class actions to botnet takedowns and the 2023 Search Partners report.
Everything in this track has happened in public, in court filings, security research and regulator press releases. This lesson collects the cases most relevant to search monetisation. Figures are given as reported by the named source. The aim is to see the patterns, because the same few patterns repeat across twenty years.
2006: the click fraud class actions
In the mid-2000s, advertisers began to argue that search engines were billing them for clicks that were not real, including clicks made on partner sites that shared in the revenue. The best-known suit, Lane's Gifts & Collectibles against Google and others, was settled in 2006 with Google agreeing to a fund of up to $90 million, largely in advertising credits. Yahoo settled a similar action the same year. The settlements led to more public reporting about how invalid clicks are filtered.
Lesson: the feed model has always depended on advertisers trusting that partner clicks are real. Every later tightening of rules traces back to that trust being tested.
2006: the FTC and search-hijacking spyware
The US Federal Trade Commission brought several cases in this period against distributors of software that changed browser settings and interfered with search. In November 2006 it announced settlements with Odysseus Marketing and its principal, and with a second operator. According to the FTC, the software in question intercepted and replaced the search results users received from popular search engines and barraged them with pop-up ads. The orders included monetary judgments, largely suspended, and bans on such conduct.
Lesson: changing someone's search behaviour without consent is a consumer-protection matter, not only a policy one. The FTC Act reaches it.
2011 to 2016: DNSChanger and Operation Ghost Click
A group operating from Estonia through companies including Rove Digital infected more than four million computers in over 100 countries with malware known as DNSChanger. It altered the settings that translate website names into addresses, so that when victims clicked search results or ads they were sent elsewhere, and so that ads on pages were swapped for ads the group was paid for. US prosecutors said the scheme produced about $14 million. The FBI and Estonian police dismantled it in 2011. The ringleader, Vladimir Tsastsin, was sentenced in New York in 2016 to more than seven years in prison.
Lesson: the operators presented themselves to ad brokers as ordinary publishers with traffic. The brokers saw clicks, not the malware behind them. Knowing your direct partner is not the same as knowing your traffic.
2013: Bamital and ZeroAccess
In February 2013 Microsoft and Symantec took down the Bamital botnet. Microsoft said more than eight million computers had been attacked over two years by malware that hijacked search results and committed click fraud, affecting users of Bing, Yahoo and Google alike. In December 2013 Microsoft, Europol and the FBI disrupted ZeroAccess, which Microsoft said had infected nearly two million computers, hijacked search results and cost online advertisers an estimated $2.7 million a month.
Lesson: Search hijacking at scale needs a way to cash out, and that way was always some advertising account paying for clicks. Follow the payout and you find the weak point.
2017: how hard prosecution is
US prosecutors charged an Italian national, Fabio Gasperini, with building a botnet from hacked servers and using it for click fraud. It was described as one of the first click-fraud cases to go to trial in the United States. In August 2017 the jury acquitted him of the felony charges and convicted him of a single misdemeanour count of computer intrusion.
Lesson: criminal law is a slow and uncertain remedy. In practice the industry polices itself through contracts, deductions and terminations, which need far less proof than a courtroom.
2020: Adrozek
As covered earlier, Microsoft reported a browser-modifying malware family that injected extra ads into search results across several browsers, seen on more than 30,000 devices a day at its peak. Lesson: Adware did not disappear with toolbars. It moved into browser internals and extensions.
2023: Adalytics and Google Search Partners
On 28 November 2023 the research firm Adalytics published a report on Google's search partner network. It said it had found tens of thousands of sites embedding Google search with ads enabled, and that search ads for major brands and US government bodies had appeared on sites including pornographic sites, piracy sites and sites in Iran and Russia, some of which appeared to be under US sanctions. At the time, Google Ads did not show advertisers which partner sites their search ads ran on.
Google disputed the report strongly. Its ads vice-president said Adalytics had a record of inaccurate reports and exaggerated claims, and that Google's analysis had not identified ad revenue being shared with a single sanctioned entity. In the days that followed, trade press reported that Google was allowing advertisers to opt out of search partners across all campaign types, including Performance Max.
This was a brand-safety and transparency dispute, not a proven fraud case. It matters here because of what followed: third-party pre-screening and site-level placement reporting for search partners in 2025, default opt-outs for parked domains from March 2025, and the removal of parked domains (AdSense for Domains) from the search partner network on 10 February 2026.
Lesson: when advertisers cannot see where their ads run, one credible report can change the rules for everyone. Transparency arrives eventually, and business models that depend on its absence do not survive it.
2026: search-hijacking extensions are still found
In June 2026 an extension-security research group, MalExt Sentry, published an analysis of 23 Chrome extensions with roughly 758,000 users in total. It reported that the extensions were presented as maps, productivity or news tools but overrode users' default search and routed queries through intermediaries to hosted search feeds. This is one researcher's report and we have not seen a platform response. Lesson: the old pattern persists, and researchers increasingly call for enforcement against the monetisation accounts, not just individual extensions.
The patterns that repeat
- The fraud is always upstream of someone honest. A broker, provider or buyer who saw only clicks.
- The cash-out point is the weak point. Every scheme needed a paying account, and losing it ended the scheme.
- Consent is the dividing line between a search product and a hijacker.
- Opacity invites both fraud and regulation. Each scandal has been followed by more reporting and more opt-outs for advertisers.
- Enforcement is mostly contractual. Deductions, caps and terminations arrive years before any court does.
Key takeaways
- Search click fraud has been litigated since 2006, when Google agreed to a settlement of up to $90 million over invalid clicks.
- DNSChanger, Bamital and ZeroAccess show that hijacked searches and fake clicks have been monetised through ordinary-looking ad accounts.
- The 2023 Adalytics report was disputed by Google but was followed by more advertiser transparency and opt-outs on search partners.
- Criminal prosecutions are rare and uncertain; the industry enforces mainly through contracts, deductions and terminations.
- Methbot and 3ve were display and video cases, relevant to search only as evidence of how well bots imitate people.
Questions people ask
What did the Adalytics report say about Google Search Partners?
Published on 28 November 2023, it alleged that Google search ads for major brands and government bodies had appeared on partner sites including pornographic, piracy and possibly sanctioned sites, and that advertisers could not see where ads ran. Google rejected the report as inaccurate and exaggerated, and said it had found no revenue shared with a sanctioned entity.
Has anyone gone to prison for click fraud?
Yes. Vladimir Tsastsin, who led the DNSChanger scheme that hijacked clicks and replaced ads on more than four million infected computers, was sentenced in the United States in 2016 to 87 months. Prosecutions remain rare, though. In a 2017 US trial over a click-fraud botnet, the defendant was acquitted of the felony charges and convicted only of a misdemeanour.
Was Methbot a search arbitrage fraud?
No. Methbot and the related 3ve operation faked video and display ad impressions sold through programmatic ad exchanges, using data-center servers and hijacked home computers. They did not target search feeds. They are often mentioned alongside search fraud because they show how convincingly automated traffic can imitate real people at very large scale.
Is click fraud illegal?
It can be. Depending on the country and the method, it may amount to wire fraud, computer intrusion or deceptive trade practice, and regulators such as the FTC have acted against software that hijacks searches. In practice most cases never reach court. They are handled under contract, through withheld payments, revenue deductions and closed accounts.