Ad fraud (also referred to as Click Fraud or PPC Fraud) is concerned with the practice of fraudulently representing online advertisement impressions, clicks, conversion or data events in order to generate revenue. Ad-frauds are particularly popular among cybercriminals.[1] [2]
While ad fraud is frequently associated with banner ads, video ads and in-app ads, click fraud has been associated with search marketing, mobile advertising and conversion fraud with affiliate marketing. AppsFlyer estimates financial exposure to app install fraud in Q1 of 2018 was as much as $800 million.[3]
Ad fraud is the categorical term inclusive of all forms of online advertising fraud. A successful ad-fraud campaign generally involves a sophisticated combination of Identity fraud and attribution fraud: for instance, sending fake traffic through bots using fake social accounts and falsified cookies; bots will click on the ads available on a scam page that is faking a famous brand.[4] In 2004 Google's CFO George Reyes said that fraud is the biggest threat to internet economy[5] with the first research paper covering the topic in 1999[6] or earlier. In 2016 World Federation of Advertisers published its first guidance on Ad fraud[7] to advise its members on how to counter the problem allegedly eating close to US$20 billion of its members ad budgets in 2015.[8]
Recent research has revealed new insights into ad fraud within search engine marketing. A study[9] conducted in 2023 found that the average rate of fraudulent activities in search engine advertisements is approximately 11.5%. This statistic highlights the growing importance of implementing effective fraud protection measures in search engine marketing to combat ad fraud.[10]
In a 2017 report Juniper Research estimates ad fraud to be worth US$19 billion[11] equivalent to $51 million per day. This figure, representing advertising on online and mobile devices, will continue to rise, reaching $44 billion by 2022. Ad fraud is the #1 cybercrime in terms of revenue, ahead of Tax-refund fraud.[12] HP Enterprise in its Business of Hacking report highlighted ad fraud as the easiest and the most lucrative form of Cybercrime.
Source:[14]
In 2017, P&G and Chase suspended their digital ad budget of $200 million dollars and reduced their ad shares from 400 thousand to 5 thousand in an attempt to reduce their exposure to ad fraud.[15]
Online advertising fraud is a leading concern amongst almost 50% of mobile marketers according to a report from iotec.[17] Ad measurement and verification vendor TrafficGuard reports 7 different types of mobile ad fraud across 2 different categories:[18]
Attribution Fraud[19] | Attribution fraud is when a real user downloads an app and a fraudster attempts to claim attribution for that install. Attribution fraud sees the advertiser pay for a user it attracted through other channels. | Types of attribution fraud:
| |
Install fraud[20] | Install fraud is when app installs are not from genuine app users. These installs may be from bots or from people that are not its intended users. These installs don't deliver return on ad spend (ROAS). | Types of install fraud:
|
In a recent publication by Association of National Advertisers sourced traffic was reported as a notable form of ad fraud,[21] a practice where companies partaking in the formal online advertising market buy fraudulent traffic to resell it as legitimate. Sourced traffic has been mistakenly referred to as arbitrage, because buying Sourced traffic does not have any potential for return where as in financial markets arbitrage refers to "risk-free" trading of legitimate assets. While there is no evidence to support the claim, and such evidence would be impossible to conclusively gather, it may be that Sourced Traffic represents lion's share of the Ad fraud market due to the ease and popularity of acquiring and reselling it. The only evidence-based study to Sourced Traffic found in 2016 that around 50% of the acquired traffic was originating from data center IP addresses[22] and that selected Ad Fraud verification vendors Integral Ad Science and Moat largely failed to detect it as ad fraud. The report also showed how easy it is to acquired Sourced traffic as low as $0.001 per click, a price in stark contrast to the going price for click in the formal market which is typically $1 or more.[23]
In 2016 there were four notable non-profit organizations focused on creating awareness and availability of resources for countering ad fraud: Botlab, JiCWEBS, Media Rating Council (MRC), and Trustworthy Accountability Group (TAG). Each have published various guidelines and commentaries on ad fraud, most notable of which is the Media Rating Council's Invalid Traffic Detection Guidelines.[24]
__FORCETOC__