Spot the fraud
Ten real-world style scenarios. Read the clues, then decide what is really going on, and whether it is fraud at all. intermediate · 10 questions
Question 1 of 10Score 0
A campaign shows a 40% CTR from one data-center IP range, mostly around 3am local time. What is it most likely?
All questions with answers
- A campaign shows a 40% CTR from one data-center IP range, mostly around 3am local time. What is it most likely?
Answer: Bot click fraud from data-center servers. Typical display CTRs are well under 1%, and real people are not concentrated in one hosting range at 3am. This is textbook click fraud from data center traffic; a great creative would show a lift from diverse, residential audiences. - A small site's traffic jumps fivefold overnight after it buys 'traffic packages'. Sessions last 2 seconds, and each page carries 15 ads. What is going on?
Answer: Sourced-traffic arbitrage typical of MFA sites, likely mixed with bots. Buying cheap traffic to resell as ad impressions is traffic arbitrage, the model behind made-for-advertising sites. The clues are purchased traffic, tiny sessions and ad-cluttered pages, not organic interest. See sourced traffic. - Bid requests claim a major newspaper's domain, but the SSP seller ID in them is not listed in that newspaper's ads.txt. What should you suspect?
Answer: Domain spoofing or unauthorised reselling. If a seller is not authorised in the publisher's ads.txt, the request may be domain spoofing cheap inventory as premium. It does not prove fraud by itself, since files can be stale, but buyers should not bid. - Your verification tag reports that a 300×250 ad was served into a frame only 1×1 pixel in size. What is this?
Answer: Pixel stuffing. Pixel stuffing hides a full ad in a tiny frame to register impressions no human can see. A tracking pixel is a legitimate 1×1 measurement call, not an ad being billed. - A CTV app the publisher says does not use SSAI sends millions of 'SSAI' requests, and device IDs never repeat. What is most likely?
Answer: SSAI spoofing: fake servers inventing devices. SSAI spoofing impersonates SSAI servers and fabricates device details. Real audiences reuse devices across sessions; endlessly fresh IDs and an app that does not use SSAI are strong red flags. - An ad network delivers 20 million clicks for an iOS app but only a handful of installs, and those installs are spread evenly across days after the clicks. What does it look like?
Answer: Click spamming. Enormous clicks, tiny conversion and flat, long click-to-install timing are the signature of click spamming, which steals credit for organic installs. Click injection shows the opposite, installs seconds after the click. - A lead-gen campaign delivers 500 leads. Many share the same phone pattern, emails use sequential numbers and each form was completed in about one second. What is it?
Answer: Lead generation fraud by bots or scripts. Humans cannot type a full form in a second, and real people do not have sequential emails. This is lead generation fraud: paying per lead rewards fabricating leads, just as CPA models can reward faking conversions. - Your viewability vendor finds several ads reported from the same slot at the same moment with identical coordinates; only the top one is visible. What is this?
Answer: Ad stacking. Ad stacking layers ads on top of each other so every one counts an impression while only one can be seen. Ad refresh shows ads one after another over time, not simultaneously. - Traffic arrives from ordinary home ISPs, but the same device fingerprint appears on 40 different IP addresses in an hour and its timezone keeps changing. What is most likely?
Answer: Bots rotating through residential proxies (SIVT). Rotating residential proxy exits give one bot many clean-looking IPs, but its fingerprint stays the same. That inconsistency is SIVT; a declared crawler would be simple GIVT. - A news site's traffic spikes tenfold within an hour of a major breaking story. Visitors come from many ISPs and devices, read for minutes and click at normal rates. What is most likely?
Answer: Genuine human traffic reacting to the news. Not every spike is fraud: diverse sources, long engagement and normal CTR are what real people look like. Good fraud detection avoids false positives that would wrongly defund a publisher's best day.