Digital fraud is a dark by-product of our modern lives, and ad fraud is a growing issue being tackled by the leading advertising and adtech companies.
In the UK the advertising and adtech sectors understand that the dark operators threatening their industry need to be addressed and dealt with.
So here, Dmitry Sverdlik, Founder and CEO of global martech and adtech firm, Xenoss, outlines what brands, agencies and publishers can do to combat ad fraud.

Programmatic ad serving is far from being a two-party interaction. Advertisers’ campaign money goes through multiple intermediaries (DSPs, ad networks, SSPs, agencies, inventory resellers, etc.) before reaching publishers.
The Society of British Advertisers, the Association of Online Publishers) and PwC discovered that only 65% of ad spend is effectively reaching publishers — the rest is lost to mediation.
On top of that, ad budgets can shrink further due to ad fraud.
Advertisers, one can argue, get an even shorter end of the stick — aside from taking direct financial losses (which are nearing $100 billion according to recent data), they miss out on market opportunities by not reaching shoppable audiences in time.
A rise of awareness and accountability is a broad-stroke trend I see across modern-day AdTech.
That’s good news because it pushes everyone in the ecosystem — agencies, vendors, and publishers — to be more open and transparent about operations and discover fraud threats before they do damage.
As a part of a tech team that’s been building fraud prevention platforms for a good number of years, I’d like to contribute to this discussion with a quick rundown of common fraud tactics and explore prevention mechanisms that are considered the industry’s best practices.

Ad fraud 101
When ad fraud comes to mind, we tend to think about bot traffic (to be clear, it’s part of a decent number of tactics), human traffic is also commonly used to tamper with data. Let’s examine both types and their respective differences.
Human traffic
Human traffic as the name suggests, this type of fraud relies on individuals who view or interact with ads on publisher platforms to generate fake engagement and illegitimate profits.
A classic case in point is a click farm, which looks a lot like what we saw in Silicon Valley: a room filled with desktops or smartphones and employees using them to click on ads and do other actions to trigger payouts from media buyers.
Bot traffic
Bot traffic uses bots for visiting websites, filling in forms, clicking on ads, installing apps, or subscribing to newsletters to create the illusion of genuine user engagement.
Almost half (47.4%) of all traffic was bot-generated (automated) in 2022, and the malicious bots we’re talking about accounted for 30.2% of that automated traffic.
There are three types of fraud depending on altered indicators:
- Click fraud — boosting the number of ad clicks.
- Impression fraud — inflating impressions, which is the number of times an ad is displayed to users.
- Conversion fraud — falsifying conversion data. It targets the desired outcomes or actions, such as purchases, sign-ups, or downloads.
Knowing how your ads can be affected is the first step towards protecting your business from possible financial and reputational losses connected with ad fraud. Below you’ll find some of the most common ad fraud techniques.
Main ad fraud techniques
Ad stacking occurs when multiple ads are layered on top of each other within a webpage or app, with only the topmost ad visible to the user. Advertisers are charged for each ad impression.
At scale, this tactic can be powerful. VASTFLUX, a major ad stacking sheme, used malicious JavaScript to sandwich up to video 25 ads together (obviously, out of those, only one was viewable). Some 120 publishers, 1,700 apps, and millions of devices fell prey to the strategy, so it’s well worth watching out for.
Pixel stuffing follows a similar approach, as the name suggests. The difference is that ads are placed not within an ad slot but in a pixel or a hidden part of a webpage.
With this technique, malicious actors can generate tons of impressions for non-viewable ads.

Ad injection entails placing ads on a website or app without the publisher’s consent or knowledge.
In extreme cases, injected ads can replace legitimate ads or appear next to them, diverting the audience’s attention and generating poor campaign performance.
Malware, compromised browser extensions, or plugins are generally used for this activity.
Click injection is a type of mobile ad fraud where malicious apps send fake clicks to claim attribution for app installations or updates. This way, fraudsters deceive ad networks and take credit for user engagement.
The PreAMo campaign discovered on Google Play in 2019 is a bright example of ad clicker fraud. The scheme involved distributing malware that imitated the user by clicking on banners. In total, users downloaded over 90 million times from six infected applications.
Fraudsters use domain spoofing to trick advertisers into believing their ads are displayed on reputable, high-traffic websites.
In reality, ads appear on low-quality or malicious websites with low domain authority and ratings, which can harm media buyers’ reputations, besides draining their budgets.
How can advertisers safeguard themselves from ad fraud?Â
Ad media buyers can leverage pre-bid and post-bid analysis techniques to combat ad fraud.
Partnering with a trusted publisher is a reliable way to protect your campaign from outside interference, but it’s not readily obvious how to go about filtering publishers.
Luckily, IAB has tackled the issue quite well by introducing stndards for both web and mobile inventory.
Ensure the publisher follows specifications by IAB Tech Lab to be confident you buy authentic inventory. These specs are:
- Ads.Txt, a list of authorised suppliers (ad networks, content syndication partners, etc.) allowed to sell a publisher’s inventory. This way, IAB increases the transparency of programmatic auctions and deals with the problem of misrepresented or counterfeit media buying.
- App-Ads.Txt, the extension to the original standard for owners of mobile app and CTV app inventory. App developers that adopt this standard provide a website URL in their app’s store metadata and publish an app.ads.txt file on the website that specifies authorised sellers of their app’s inventory.
In addition, check whether the publisher has integrated the Open Measurement Software Development Kit (OM SDK).
If yes, you should be able to integrate third-party solutions to verify the viewability and delivery of ads on the platform, reducing the likelihood of ad fraud.
Another way to guard against ad fraud is by adopting ad verification, ad measurement solutions, and bot mitigation solutions.
If you want to know what platforms are out there, here are some of the leaders in this space:
Bad actors always search for new methods to bypass fraud detection solutions, so relying on a system that continuously learns emerging threat patterns through real-time data analysis and swiftly adapts to them is crucial.
Custom ML-powered ad detection and prevention solution does just that, allowing advertisers to stay one step ahead of those who want to earn money at their expense.
A tech partner must have long-term expertise in building adtech solutions designed for high load (remember, velocity is king), be well-versed in fraud threats for various industry players and counter techniques, and know the current privacy landscape.
Building a custom ad fraud prevention platform comes with commitment and upfront investments.
At the same time, you will have the flexibility to build a tool that addresses the pain points of your campaigns and gives you more control over attribution campaign monitoring.
I’ve come to observe that custom tech pays itself off well for larger publishers and advertisers in the long run.
The good news is that all tiers of advertisers and publishers can find an ad fraud prevention system that would match their budget and available talent and help ensure that no losses slip through the cracks of the supply chain.



