CTV & video · also called Connected TV fraud, OTT fraud
CTV fraud
CTV fraud is ad fraud targeting connected TV and streaming inventory, such as spoofed apps, fake devices, SSAI spoofing and infected streaming boxes, exploiting CTV's high prices and harder verification.
CTV ads are expensive, which makes them attractive to fraudsters, and several features of CTV make fraud easier. TVs do not run full web browsers, so JavaScript verification is limited; many ads are inserted server-side via SSAI, so ad systems see servers rather than devices; and supply chains around streaming apps and FAST channels can be long and opaque.
Main schemes include SSAI spoofing, where fake servers claim to request ads for millions of viewers; app spoofing, where junk inventory is labelled as popular streaming apps; device spoofing, where servers or phones pretend to be TVs; and infected devices, such as cheap Android-based TV boxes with preinstalled malware. HUMAN has documented operations such as ICEBUCKET (2021), involving SSAI spoofing, and BADBOX 2.0 (2025), involving infected off-brand streaming devices, and the FBI warned the public about the latter in 2025.
Defences include app-ads.txt and sellers.json checks, verifying SSAI servers against known vendors, IAB Tech Lab guidelines for forwarding device information, the Open Measurement SDK for CTV, device farm and anomaly detection, and buying direct from streaming publishers. Under the MRC IVT guidelines, these schemes are SIVT.
Think of it like this
CTV fraud is like selling fake tickets to a sold-out concert: the event is premium and hard to check at the door, so forgers flock to it.
An example
A buyer notices one app claiming 400 million CTV impressions a month through 15 resellers, while the app's app-ads.txt lists two sellers and its known audience is a fraction of that; most impressions are spoofed.
Related terms
SSAI spoofing
SSAI spoofing is CTV and video fraud in which fraudsters imitate a server-side ad insertion system, sending fake ad requests that appear to come from real viewers watching real streams.
App spoofing
App spoofing is misrepresenting which mobile or CTV app an ad slot belongs to, typically by faking the app's bundle ID, so cheap or fake inventory is sold as a popular app.
Device spoofing
Device spoofing is faking the identity or type of device requesting an ad, such as a server posing as a smart TV or iPhone, to earn higher prices or dodge detection.
CTV (connected TV)
CTV (connected TV) is any television connected to the internet, such as a smart TV, streaming stick, games console or set-top box, and the advertising shown in streaming apps on it.
SIVT (sophisticated invalid traffic)
SIVT (sophisticated invalid traffic) is invalid traffic designed to look human or legitimate, which can only be found through advanced analytics, multi-point corroboration and often human review.
app-ads.txt
app-ads.txt is the version of ads.txt for mobile and CTV apps, a file on the app developer's website that lists which sellers are authorised to sell the app's ad inventory.
Sources: MRC Invalid Traffic Detection and Filtration Guidelines Addendum (2020 update), IAB Tech Lab CTV standards, IAB Tech Lab ads.txt and app-ads.txt