Ad fraud – scams in performance marketing

Online fraud is usually associated with stealing credit card data, phishing for social media passwords and spam from alleged heirs of African dictators. Meanwhile, advertisers also fall victim to scams worth billions of dollars a year.

Ironically, these are usually companies using performance marketing (advertising billed by results) and making optimisation decisions based on strictly measurable effects in the form of visits, leads or sales.

Invalid clicks on search ads

One of the first associations with fraud in online advertising is “clicking out” Google Ads budgets – by competitors or other “dark forces”. The scale of the phenomenon is indeed considerable. Google Ads ads are also clicked by all kinds of bots, though not necessarily paid by someone who specifically wants to harm us in Google Ads (e.g. programs analysing web traffic, scraping content, or sending spam to contact forms).

Google tries to catch such activity and filters it out automatically, not charging for such clicks. In the reports – depending on the website – we see from a few up to about twenty percent of invalid clicks detected by Google in real time.

Invalid clicks caught in real time are not reported in clicks (in other words, the “Clicks” column no longer includes invalid clicks and they are not included in the cost). If an algorithm or manual verification later determines that there were more invalid clicks originally considered valid, they will remain in the click count, but a refund will appear on the invoice. So what we see on the invoice is only a small part of what Google actually filters.

Invalid clicks in a Google Ads account

You need to be aware that Google is not interested in tolerating this phenomenon. If clicks become less valuable on average, because part of the traffic is artificial with no chance of conversion – advertisers will not be willing to raise their bids. And any kind of support for such practices would – if revealed – risk a serious image crisis, loss of advertisers’ trust and multi-billion-dollar damages. So Google is rather an ally of advertisers here.

But what about the invalid clicks that Google does not spot? An advertiser continuously running campaigns in Google should not worry about them as much as it might seem either. In the medium and longer term, the higher the CTR, the lower the CPC. To put it simply – when pricing a click, Google converts clicks into impressions. Therefore, if an ad gets more clicks compared to the competition, its Quality Score will rise and the cost per click will fall. So this is a kind of cushion softening the effects of invalid clicks.

Click fraud protection software

This does not mean that the impact of invalid clicks is completely irrelevant. Additional software that detects potentially unwanted traffic (e.g. from bots) and blocks specific IP addresses or excludes specific audiences – can improve campaign efficiency by several or a dozen or so percent.

Whether the additional cost of such software is worth it can be determined by running an A/B experiment of campaigns with and without the additional protection, and then comparing the benefits and costs. If you need support in implementing click fraud protection, contact us.

Fake conversions

Fake conversions are a somewhat more advanced scam. Advertisers fight it by validating leads and transactions, yet dishonest affiliates still mass-generate worthless conversions, expecting to be paid for them. This happens in many ways:

  • leads contain fictitious data;
  • leads contain data of real people, used without their consent;
  • submissions come from people who share their identity for profit through various “make money online” schemes or in exchange for another benefit (e.g. access to content is conditional on subscribing or installing an app), and who are not actually interested in the offered product;
  • transactions are placed but never paid for, or are placed with the intention of cancelling and requesting a refund.

Fraud of this kind occurs mainly in ad networks billed in the CPA model (payment by results). In such networks the entry barrier for publishers is usually quite low. Among publishers there are many entities for whom reputation does not matter, and if “burned”, they simply dissolve, only to quickly return in another incarnation.

We also encounter such fraud in ads paid per click or impression. Although the publisher is not paid for the “generated” conversions, since most advertisers optimise their ads for conversions, if a given ad placement generates them, its publisher can count on interest and budget allocation.

Fake conversions are often generated in campaigns with a mobile app install goal, as this is a standard action that is easy for a machine to simulate. After clicking the right ads, fraudsters generate fake installs on mobile devices, and even in-app engagement. After such a “conversion”, the devices are reset, the IP is changed and the whole routine is repeated.

In Asia (and not only there), phone farms are created on a massive scale. The practice runs on thousands of devices and with an even greater number of SIM cards, bringing fraudsters huge profits. It is worth noting that awareness of the harmfulness of such activities is growing and they are increasingly treated as a crime.

Fake conversions are relatively easy to detect. Ultimately, we are always able to determine whether the money arrived in the account and whether the period during which the buyer could request a refund has passed. Proper transaction validation solves the problem.

Currently, most conversion tracking systems allow importing conversions from an external system (offline conversions) and linking them to individual traffic sources. A simple analysis will show which sources generate real transactions and which deliver zero-value “conversions”.

Attribution fraud

Fake clicks and conversions are quite primitive fraud, easy to detect, and after eliminating them advertisers have the illusion that they are effectively defending themselves against scams. Meanwhile, fraudsters make the biggest money on something completely different.

Attribution fraud is much more sophisticated. It concerns real conversions, completed by real users who pay for their purchases. However, the source of these conversions is completely different from the one we paid for, because fraudsters created the illusion that it was they who delivered the customer.

Sometimes the question comes up: since the transaction took place and the money is in the account, what’s the problem? Mainly that we have usually already paid for that transaction in another way, and the fraudster, who had no influence on the transaction or whose influence was minimal – demands payment. This means we pay double for such conversions, and the media investments that are actually the source of revenue suffer, which limits growth potential.

Ad stacking

A primitive and fairly easy-to-detect attribution fraud is ad stacking, whose purpose is to charge multiple commissions for a given click – from the same or different advertisers.

The user clicks an ad, but in fact generates multiple ad clicks across different ad and affiliate networks. The clicks often happen invisibly to the user. Pages are displayed at the size of one pixel or visited for a fraction of a second in successive redirects, before the user finally lands on the destination page. The technique doesn’t matter; in the end it is only about leaving a cookie.

It happens that such multiple clicks concern ads of the same website or app, but published through different networks. If the user converts, the transaction will be reported as a conversion in each of these networks. If the advertiser does not deduplicate, it may turn out that they pay several times for one conversion – whether in the CPA model or indirectly in the CPC model.

Ad stacking is quite easy to detect. It manifests itself in visits from several sources at very short intervals (usually milliseconds) from the same user. Such publishers can be eliminated very quickly at the ad network level, or by an advertiser using several networks simultaneously.

Cookie spam

Also known as click flooding or click spam. This technique consists in triggering a very large number of clicks on a given ad among a very large number of users, counting on some of them converting by chance. Such clicks enter the conversion path. Even if they are not last on the path, they will appear as assist clicks.

With CPA billing, settlement is based on the ad network’s own system anyway, which does not register interactions other than its own, so such a click will be credited with the conversion even if interactions with other ads occur before and/or after it. In this way the fraudster takes credit for a conversion generated by other sources.

One of the easiest and most profitable victims of click flooding for a spammer is organic traffic. For users who are loyal customers, come from referrals or from other offline sources, such a (often unconscious) click is the only visible interaction on the path. Regardless of the attribution model used, the conversion is then attributed to that click, even though it had no influence on it whatsoever.

For this reason, spammers usually target large, well-known brands that run intensive marketing campaigns themselves and have significant organic traffic as well as traffic from other advertising channels. 

It is all based on the law of large numbers: if an advertiser has a significant market share, with some probability one can expect that a random Internet user “gifted” with a cookie by the spammer will make a purchase in the near future. Using ad stacking, the spammer can “sow” ad cookies of many competing companies, giving themselves a good chance that one of them will convert.

The illustration above is purely conceptual and is not based on real data. The names of well-known brands were chosen randomly and without connection to any real situation.

The condition for the profitability of such a scheme is, of course, acquiring the click cheaply enough. To make this possible, such clicks are usually forced. Often they are outright invisible to the user and have no influence on the purchase decision. Examples of such activities:

  • Clicks without user participation performed by adware or in the form of pop-ups or pop-unders, also using ad stacking;
  • Clicks extorted through ads covering the content, which you first have to click to close, or other ads deceptively encouraging a click;
  • Accidental clicks on ads imitating navigation buttons on a page or unexpectedly appearing in clickable areas, especially in mobile app games;
  • Social media spam (e.g. a sensational article headline which, when clicked, turns out to lead to a page with nothing actually on it, requiring various buttons to be clicked before the content can be seen);
  • Email spam, e.g. an offer to receive a free smartphone or another offer you can’t refuse, which doesn’t actually exist but provokes a click;
  • Automatic opening of a page in frames or ad creatives, invisible to the user;
  • Break-ins into website servers, redirecting their traffic to the advertiser’s website;
  • Domains that are typos of well-known brands or popular websites, redirecting to the advertiser’s website (example below).

Even if the advertiser deduplicates transactions and analyses multi-channel paths, in many cases it may happen that such a click will be the last, or even the only, non-direct visit before the customer’s transaction.

Click spam is much harder to detect. One of the symptoms is a high CTR on ads, many visits but few conversions. The time from click to conversion is usually evenly distributed across the conversion window.

Spammers sometimes try to hide a low conversion rate by “topping up” with fake conversions, which is why the conversion rate should be analysed after validating them.

Click spam also has a milder form (called “affiliate spam” by Google). Affiliates create Google Ads ads for keywords that are admittedly not brand-related, but overlap with the keywords in the SEM PPC campaigns run by the advertiser themselves. Such a click enters the conversion path and entitles the affiliate to a commission. The problem is that if a conversion is on average preceded by e.g. 5 Google Ads clicks, the other four are already provided by the advertiser. A fair remuneration for such a partner would therefore be closer to 1/5 of the CPA value. Many affiliates deliberately block further ad impressions for a user who has already clicked once. After all, one click is enough to leave a cookie, and the rest of the work will be done by others.

Conversion hijacking

This is one of the more sophisticated fraud methods in performance marketing. It consists in forcing an interaction just before a purchase is made.

Has it ever happened to you while shopping in a clothing store that after you picked a product, a sales assistant suddenly appeared (though they had ignored you before) and offered to take your chosen item to the till? That assistant marked the product as sold by them, which will be the basis for calculating their bonus. Your behaviour indicated that you were just about to make a purchase, and the observant assistant decided to take the credit, although there was none to take. Without blaming such an assistant (in the incentive system they found themselves in, they are acting rationally), let’s look at the methods used online:

  • Brand bidding. A user looking for a store types its name into the search engine. In the search results they click a Google Ads ad with the store’s name, which redirects to the store’s website via an affiliate network. For the user everything checks out (they got where they wanted to make the transaction), but the store pays a commission for its own customers, because the ad link planted an affiliate cookie in the redirect. To mask this practice, some fraudsters use tags like utm_medium=display in the destination link or perform multiple redirects to hide the actual source of the page;
  • Discount codes. A user seeing a “discount code” box in the cart decides to use the search engine, where they find a well-ranked page or a sponsored link leading to a page with the discount, and from there to the advertiser’s website. It doesn’t matter whether there actually is any discount or not – the user will be redirected from the fake ad, which will turn out to be the last interaction before the transaction;
  • In the case of ads promoting mobile app installs, malware (being part of another app on the mobile phone, e.g. a free game or tool) analyses the user’s behaviour in real time. If it detects the intention to download an app, just before it is installed it generates ad clicks invisible to the user:

Hijacking is characterised by:

  • a high conversion rate, often similar to or even higher than direct visits or brand searches;
  • a short time between click and conversion.

Fraudsters may use camouflage, mixing such traffic with lower-converting traffic, e.g. cookie spam, which can make some metrics look perfectly normal at first glance.

Code on your website as a backdoor

JavaScript code placed on a website can do a great deal. It can act as a container (like Google Tag Manager) that calls other, nested codes. In particular, such a script can trigger the opening of a third-party site (e.g. in a one-pixel frame), which will generate a visit to our site through an affiliate link with the right UTMs.

To make such an event harder to detect and replicate, this kind of action can happen randomly, on a few percent of visits, with higher probability e.g. after adding a product to the cart or starting the payment.

How can such code end up on a website? Sometimes it is the result of a hacking attack exploiting CMS vulnerabilities or using a password obtained in a phishing attack. Such code usually does not disturb the website’s operation and can go unnoticed.

Such code can also be smuggled in e.g. through a plugin from an unverified source, or another code that we install ourselves, unaware of the consequences of its operation.

There are known cases where such code was triggered by the remarketing network’s own tracking code, placed on every page of the website to build audience lists and – as it turns out – sometimes not only for that purpose. The blame is usually shifted – as is customary in affiliation – to the network’s dishonest partners and subcontractors.

One way to detect such activity is to look for conversions whose last-click source differs from the source of the session in which the conversion occurred (see the article on attribution in Google Analytics). A significant share of such transactions may indicate the likelihood of this kind of conversion hijacking. Only raw data analysis, e.g. via BigQuery, will provide proof.

How to protect yourself against fraud?

Above all, do not give in to the temptation of easy profits. If results come too easily, it should immediately raise suspicion. The ad space market is very competitive and largely efficient, which means we pay a price for traffic close to its value. That is why all kinds of bargains are rare and usually small-scale.

The first safety fuse is conversion validation. Are the achieved results real or only apparent? Make sure the leads are genuine and translate into transactions, taking returns and complaints into account. The ultimate conversion is money in the bank at the end of the year. If such a conversion tracking and validation system is in place, you will easily detect all kinds of fake conversions and, pulling the thread, eliminate dishonest publishers.

However, when conversions are real and end with payment, this should not lull your vigilance. Attribution fraud often has a much larger scale than primitive fraud based on fabricated leads. Here it is necessary to analyse the entire conversion path, also on the time scale and across many dimensions, combined with the analysis of suspicious events.

It is worth using analysis-supporting tools that include modules helping to detect suspicious interactions and building their own blacklists. At the same time, remember that they can only help detect certain symptoms.

Fraud is not a coincidence. If a given publisher has several times performed a manipulation that you managed to detect, it almost certainly means the activity is planned. Cooperation with such “partners” should be terminated immediately, and their sites and apps – excluded from ad targeting.

 Fraud is not a coincidence but a planned activity. Cooperation with publishers caught manipulating should be terminated immediately.

Completely eliminating fraud is probably impossible. A large part of the responsibility for traffic quality rests with the ad networks. They have full information about where the traffic is acquired from, and they also have much more data about the traffic generated by publishers, which should allow much faster detection of suspicious behaviour and cutting fraudsters off from the possibility of extracting money from advertisers.

It appears that reputable networks such as Facebook and Google take effective anti-fraud measures (see also: case study: Mobile app fraud).

Unfortunately, the situation looks much worse for many other ad and affiliate networks. Partner verification procedures and oversight of their activities often seem insufficient. In some cases one can get the impression that despite official bans, they turn a blind eye to dishonest practices, which are also a source of income for them.

For this reason, when selecting traffic sources, especially in affiliate programmes, you should verify and accept affiliates yourself, monitor how they deliver traffic, and not rely solely on the network’s own measures in this regard. Otherwise, we will become easy victims of fraudsters.

Thanks to Konrad Zach of thinkHUB and to Marcin Wsół for consulting on this article. 

Author

Date

Let's talk about your business.

Porozmawiajmy o Twoim biznesie