It's a legal gray area in most countries. It can be pursued civilly as fraud or unfair competition, as in Uber's litigation and Google's $90 million settlement with Lane's Gifts, but standalone criminal prosecutions are rare.
What is click fraud? Definition, types & prevention
Click fraud is the deliberate generation of fake or invalid clicks on pay-per-click (PPC) ads, with no genuine buying interest, to drain a competitor's budget, inflate publisher revenue, or distort campaign data.
It's a form of ad fraud that directly costs advertisers money, since PPC platforms charge per click regardless of whether that click was real.
Quick answer: What is click fraud?
Click fraud is the intentional generation of fake ad clicks to waste advertising budgets, manipulate campaign data, or earn fraudulent ad revenue. It's one form of invalid traffic and can involve bots, click farms, competitors, residential proxies, or malware.
Unprotected PPC campaigns typically see 10–20% invalid click rates, and global ad fraud losses are estimated at $84 billion (2023), projected to reach $172 billion by 2028.
How has click fraud evolved?
Year | Milestone |
2002 | Google moves AdWords to a true cost-per-click (CPC) auction model, and early PPC fraud concerns emerge alongside it. |
2006 | Google discovers Clickbot. A, one of the first documented click fraud botnets (about 100,000 infected machines responsible for roughly $50,000 in fraudulent clicks). The company also settles Lane's Gifts and Collectibles v. Google for $90 million. |
2015–2017 | Methbot operates from approximately 1,900 rented data center servers, generating fraudulent ad traffic across more than 5,000 spoofed publisher domains. |
2017 | Uber sues ad agency Fetch Media over alleged click fraud and fake app installs. Thai police raid a major click farm, seizing 350,000 SIM cards. |
2018 | 3ve, which infected roughly 1.7 million PCs and impersonated 5,000 counterfeit publisher sites, was dismantled in an FBI-led operation that also resulted in indictments related to Methbot. |
2026 | Click fraud is increasingly shifting toward residential proxy networks and human-operated click farms, making detection significantly more difficult than with earlier bot-only tactics. |
What's the difference between click fraud, invalid clicks, and ad fraud?
Click fraud is a deliberate subset of a wider problem; invalid clicks are the broader, intent-neutral term Google itself uses.
Term | What it means | Intentional? |
Click fraud | The intentional generation of fake ad clicks to waste advertising budgets, manipulate campaign data, or generate advertising revenue. | Yes |
Invalid clicks | Any clicks that an ad platform determines to be non-genuine, including accidental, duplicate, bot, or fraudulent clicks. | Sometimes |
Ad fraud | A broader category covering click fraud, impression fraud, install fraud, domain spoofing, ad stacking, and related schemes. | Usually |
What are the main types of click fraud?
Click fraud generally falls into three main categories, depending on the goal behind the activity:
Competitive click fraud: A competitor repeatedly clicks your ads to exhaust your budget and reduce your visibility in search results.
Inflationary click fraud: Publishers, website owners, or fraudsters generate fake clicks on ads displayed on their own properties to earn more advertising revenue.
Click farms: Organized groups of paid workers use real devices and varied browsing behaviour to generate fake clicks that are harder to detect than automated bots.
Who commits click fraud, and why?
Four groups account for most click fraud: direct competitors (cheaply exhausting a rival's daily budget), dishonest publishers and ad networks (earning per-click or per-install revenue regardless of authenticity), organized fraud rings (running click farms or botnets as a commercial business), and malware operators (monetizing infected devices).
Which ad platforms are most affected by click fraud?
Click fraud can affect any platform that charges advertisers for clicks, but some are targeted more frequently because of their size, popularity, or high-value keywords.
Google Ads: The most common target for paid search fraud due to its large search network and competitive cost-per-click (CPC) auctions.
Microsoft Advertising (Bing Ads): Also vulnerable, particularly in industries such as legal, finance, and home services.
Meta Ads (Facebook and Instagram): Can be subject to fraudulent clicks and fake engagement, especially in display and social advertising campaigns.
LinkedIn Ads: Higher CPCs in B2B industries make it an attractive target for click fraud and fake lead generation.
Display advertising networks: Publisher networks can be affected by invalid clicks and broader ad fraud schemes designed to generate advertising revenue.
Real-world case study of click fraud
Uber v. Fetch Media
In 2017, Uber sued its ad agency, Fetch Media, alleging it had been billed for fake clicks and app installs. Uber later sued several ad networks directly over tens of millions in allegedly fraudulent inventory.
A former Uber executive later said that pausing roughly $100 million in ad spend barely changed app install numbers, evidence that much of that growth was never real.
The 2017 Thailand Click Farm Raid
Police seized nearly 350,000 SIM cards and hundreds of iPhones, arresting three operators who paid roughly $4,400/month to generate fake engagement.
They were charged with immigration and equipment violations, not fraud. Most countries have no law directly banning click farms.
How much does click fraud cost advertisers?
Estimates vary by methodology, but recurring figures include a global ad fraud loss of $84 billion in 2023, projected to reach $172 billion by 2028, and average invalid-click rates of 10–20% across unprotected PPC campaigns, higher in high-CPC verticals like legal and insurance.
Most published statistics come from fraud-detection vendors, so treat exact figures as directional and benchmark against your own account data where possible.
Which industries are most vulnerable to click fraud?
Exposure isn't evenly distributed; industries with high cost-per-click, aggressive competitors, or easily automated conversion paths see disproportionately more fraud.
Legal services: competitive keywords can run $50 to $200+ per click, and one click-fraud monitoring estimate puts the legal industry's invalid traffic rate at closer to 25%, compared with an 11.5% Google Ads average, meaning a firm can lose roughly one in four clicks to non-genuine traffic.
Finance and insurance: high CPAs, combined with naturally high search volume, make fraud both costly and difficult to distinguish from genuine traffic spikes.
SaaS: free-trial signups are a common bot target because automated traffic can trigger conversion-adjacent actions (form fills, trial starts) without genuine buying intent.
E-commerce and retail: high competitor density and frequent comparison shopping make brand-name searches an easy, repeatable target for rivals.
Travel: seasonal demand spikes make unusual click patterns easy to miss, particularly around peak booking periods when traffic volume is already erratic.
How do you detect click fraud?
Click fraud is best detected by looking for unusual traffic patterns rather than relying on a single metric. Common warning signs include:
High click-through rates with few conversions
Repeated clicks from the same IP addresses, devices, or locations
Sudden spikes in traffic from regions you don't target
High bounce rates or near-identical session durations
Fake or low-quality leads with suspicious contact details
Unexpected increases in cost per acquisition (CPA) or drops in return on ad spend (ROAS)
How does Google detect invalid clicks?
Because Google Ads fraud is the most heavily litigated and best-documented form of click fraud, its detection systems are worth understanding in detail.
Google uses a layered approach that combines automated filtering, machine learning, and manual review rather than relying on a single detection method.
Automated filtering: Google filters many invalid clicks before advertisers are charged by evaluating signals such as click patterns, IP addresses, device information, and other indicators of suspicious activity.
Machine learning: Machine learning models continuously analyze behavioral signals, click timing, session patterns, and traffic anomalies to identify more sophisticated invalid activity that rule-based systems may miss.
Invalid clicks reporting: The Invalid Clicks column in Google Ads reports shows clicks that Google has already identified and filtered. A higher number often indicates Google's systems are detecting and excluding more invalid traffic, although it can also reflect increased fraudulent activity.
Invalid Activity credits: If invalid activity is detected after billing, Google may automatically issue Invalid Activity credits, which appear as negative adjustments on a future invoice.
Manual investigations: Advertisers who believe fraudulent clicks have been missed can submit a request through Google's Invalid Clicks Contact Form. Google reviews the evidence provided, such as GCLIDs, timestamps, and traffic patterns, though review times vary with case complexity.
How do you prevent click fraud?
Preventing click fraud requires a combination of good campaign management, invalid traffic detection, and ongoing monitoring. While no method can eliminate it, these best practices can significantly reduce your risk.
Monitor campaign performance for unusual spikes in clicks, declining conversion rates, or sudden increases in cost per acquisition (CPA)
Review traffic sources regularly by location, device, IP address, and placement to identify suspicious patterns.
Refine targeting to exclude locations, audiences, or placements that consistently generate low-quality or fraudulent traffic.
Use IP exclusions where appropriate: block known sources of fraudulent activity, keeping in mind that sophisticated fraudsters often rotate IP addresses.
Track conversion quality: Focus on lead quality and return on ad spend (ROAS), not just clicks or click-through rate (CTR), to avoid optimizing for non-genuine engagement.
Use dedicated invalid-click protection: click-fraud software can continuously monitor campaigns, identify suspicious activity, and automatically block invalid traffic that may bypass standard platform protections.
What should you do after discovering click fraud?
Once you've spotted signs of fraud, the response shifts from ongoing prevention to isolating the source, documenting it, and reclaiming what you can.
Review your analytics and cross-check the affected campaign's clicks against Google Analytics sessions for the same period.
Identify and cluster the suspicious IPs, devices, or locations driving the anomaly.
Exclude those locations or IPs immediately to stop the ongoing bleed
Update your targeting to reflect what you've learned about where the fraud originated
Report the invalid clicks through Google's Invalid Clicks Contact Form, with evidence like GCLIDs, timestamps, and traffic patterns
Keep monitoring conversions closely in the weeks after; fraud often recurs from the same source once an exclusion expires or is worked around
If this is a repeat pattern, that's the signal to move from manual response to dedicated third-party protection software
How to stay protected from click fraud in 2026
What's changed since click fraud's early days isn't the core tactic, a click with no real intent behind it, but how organized and hard to detect that tactic has become.
Industry standards and litigation have genuinely raised the cost of running fraud at scale. Still, progress is uneven across platforms, and even strong filtering has mostly pushed fraud toward harder-to-catch tactics like residential proxies and human-operated click farms rather than eliminating it.
For advertisers, that means click fraud protection isn't a one-time setup; it's ongoing vigilance, layered on top of whatever the platform already provides.
Frequently Asked Questions
Is click fraud illegal?
Are click farms illegal?
Usually not directly. Enforcement typically comes from adjacent violations, such as immigration status or unregistered equipment, not from the clicking itself.
How can I tell if Google refunded invalid clicks?
You can check for refunds by reviewing the Invalid Activity section of your Google Ads billing or invoices. If Google detects invalid clicks after you've been charged, it may automatically issue a credit, which appears as a negative adjustment on a future invoice.
Can click fraud affect Smart Bidding?
Yes. Click fraud can distort the signals Smart Bidding uses to optimize campaigns. If fraudulent clicks generate fake engagement or low-quality conversions, automated bidding strategies may increase bids for traffic that is unlikely to convert, leading to higher costs and poorer campaign performance.
What industries are most vulnerable to click fraud?
Click fraud is most common in industries with high cost-per-click (CPC) keywords and valuable conversions. These include legal services, finance, insurance, real estate, healthcare, home services, SaaS, and ecommerce.