Performance fraud is not exotic. Six patterns account for the overwhelming majority of what we reject, and every one of them leaves a signature in data the advertiser already has. The difficulty is that nobody looks until an invoice arrives and someone asks why the numbers moved.
1. Click injection
A malicious app on the device detects an install broadcast and fires a click microseconds before the app opens, stealing attribution from whoever actually earned it.
Signature: a click-to-install-time distribution with an unnatural spike under ten seconds. Real installs take time — download, unpack, open.
Control: CTIT distribution monitoring per sub-publisher, with automatic rejection under a floor agreed with the advertiser. Your MMP reports this; the fix is acting on it weekly rather than quarterly.
2. Click flooding
Enormous volumes of clicks are fired for users who never saw an ad, on the chance that some of them install organically and get attributed to the fraudster.
Signature: a huge click count with a microscopic conversion rate, and a CTIT distribution stretched over days rather than minutes.
Control: conversion-rate floors per sub-publisher, and treating an unusually long attribution window as a red flag rather than as patience.
3. Device farms and emulators
Physical racks of phones, or emulators pretending to be phones, generating installs and registrations at volume.
Signature: new device identifiers at an impossible rate, identical device models and OS versions clustered together, datacentre IP ranges, and post-install behaviour that stops dead after the payable event.
Control: device and IP intelligence at ingestion, plus — the reliable one — post-conversion behavioural comparison. Farms can fake an install. Faking thirty days of realistic usage costs more than the payout.
4. Lead recycling
The same lead sold repeatedly, either to several advertisers or to the same advertiser across different campaigns and time windows.
Signature: contact rates that hold up while conversion rates collapse, and sales teams reporting that the prospect has already been called by three competitors.
Control: de-duplication across the entire network rather than within one campaign, a de-dupe window measured in months, and consent records with source URL and timestamp so a recycled lead can be traced to its origin.
5. Cookie stuffing and forced clicks
Affiliate cookies dropped without any user interaction — hidden iframes, invisible pixels, auto-redirects — so the affiliate is credited for purchases they had no part in.
Signature: conversion rates far above category norms with negligible engaged traffic, and a suspicious share of conversions from returning customers.
Control: server-side attribution with a click ID, engagement thresholds before a click is valid, and periodic manual review of publisher placements. This one still needs human eyes.
6. Brand bidding
Publishers buying the advertiser’s own brand keywords, intercepting users who were already on their way to purchase, and charging a commission for the interception.
Signature: conversion rates dramatically above the campaign average and a customer base that skews heavily to returning buyers.
Control: automated SERP monitoring in priority geos, a prohibition written into the offer terms rather than the FAQ, and enforcement by removal plus payout reversal. Detection without enforcement changes nothing.
The control that matters more than any tool
Screening before billing rather than after complaints. Once a fraudulent conversion has been invoiced and the publisher paid, recovering it requires goodwill from someone who has already been paid for fraud. Catching it in a quarantine queue costs a review and a reason code.
That is a process decision, not a technology purchase. It requires the network to accept a slightly lower billable volume this month in exchange for a client relationship next year — which is exactly the trade a lot of networks decline to make.
What advertisers should insist on
- Mandatory sub-publisher IDs. Without them, your only fraud control is switching off the entire campaign.
- Raw log access. Summary reporting cannot be audited. Click ID, timestamp, device, geo and status, exportable — the way it works on our own tracking stack.
- A written rejection window. Thirty days is a reasonable norm, with the mechanism and the reason codes stated.
- Your MMP or CRM as the source of truth. Reconciliation between two independent systems catches things neither one flags alone.
None of this eliminates fraud. It moves the cost of fraud onto the party who can actually control it, which is the only version of the problem that stays solved.
Written by the Performetra campaign team. If you want this applied to a live campaign rather than read about, tell us what you are running.