Case Study
Ad Fraud Detection Case Study That Found Fake Spend
This ad fraud detection case study shows how geo-targeted testing, log analysis, and IP intelligence exposed invalid traffic before budgets were wasted.

A retail advertiser saw click volume rise 38% in three weeks while qualified sessions, add-to-cart events, and revenue stayed flat. The platform dashboard reported strong engagement. The analytics stack showed a different picture. This ad fraud detection case study breaks down how the team isolated invalid paid traffic, measured the financial exposure, and changed its monitoring process before the next budget cycle.
The campaign was not failing because of weak creative or an expensive product catalog. It was receiving traffic that looked valid at the ad-platform level but produced no commercial value after the click. That distinction matters. Fraud operators are built to satisfy basic delivery metrics. Your job is to measure whether traffic behaves like a real potential customer.
The Campaign: High Clicks, Low-Value Sessions
The advertiser sold consumer electronics in the United States through a direct-to-consumer storefront. It ran paid social, display retargeting, and mobile web placements across a mix of managed and programmatic inventory. Monthly media spend was $180,000, with optimization focused on cost per visit and product-page engagement.
The first alert came from a mismatch in channel performance. One display segment generated a click-through rate nearly four times higher than the account average. That would normally be good news. But its conversion rate was 91% below the average for comparable audiences, and its bounce rate rose after the campaign expanded.
The media team initially suspected landing-page speed, attribution gaps, or a bad placement mix. All were plausible. Fraud detection works best when it starts with that assumption: an anomaly is not proof. The objective is to test competing explanations with data, not label every underperforming source as fraudulent.
What the Investigation Found
The team pulled raw ad click logs, web analytics events, server-side request records, and order data for a 30-day period. It compared the questionable display segment with paid search and paid social traffic that targeted the same regions and devices.
Several patterns appeared together:
- More than 62% of suspect clicks came from IP ranges that generated repeat visits within unusually short intervals.
- Sessions often loaded one page and ended in less than two seconds, yet some reported scroll or engagement events.
- Device and browser signatures repeated at a rate far above the control channels.
- Click activity clustered overnight in regions where the campaign was intended to run during local daytime hours.
- A meaningful share of traffic arrived from locations outside the configured market, despite geo-targeting settings.
No single signal closed the case. A shared office network can create repeated IP activity. Fast exits can result from slow pages or accidental taps. However, the combination of repeated device patterns, impossible behavior sequences, abnormal timing, and location mismatches made the traffic hard to explain as normal user behavior.
The server logs added the clearest evidence. Many sessions triggered tracking tags but did not request the page assets that a standard browser would normally load. Others showed request sequences that were too consistent to reflect human navigation. The clicks were being counted, but the visitors were not interacting with the site like shoppers.
Ad Fraud Detection Case Study: Testing From Real Locations
The team needed to confirm whether the ads were appearing as intended and whether the suspect inventory differed by geography. Standard browser checks from the office network were not enough. They needed a controlled view from the markets where ads were supposedly served.
Using rotating residential proxy sessions, the verification team checked delivery across selected US cities, device profiles, and local time windows. The purpose was not to bypass controls. It was to validate campaign visibility and landing-page behavior from representative market locations without relying on a single corporate IP.
The tests revealed that ads were appearing on a set of low-quality pages not visible in the original placement reports. Some pages used aggressive refresh behavior and thin content. In several checks, the same ad unit reloaded after a brief interval, increasing the opportunity for repeat impressions and automated clicks.
Geo-based testing also showed inconsistent delivery. A campaign configured for priority US metro areas was observed on pages serving traffic that appeared to originate from unrelated regions. This did not prove every off-target impression was fraudulent, but it confirmed a control failure: the advertiser could not rely on platform-level location reporting alone.
For teams that run verification at scale, the proxy requirements are practical. You need broad country and city availability, session control where consistency matters, and enough IP capacity to avoid testing every location through the same address. FlameProxies can support this type of distributed validation with residential IP coverage across 180+ countries and immediate access for active monitoring workflows.
The Financial Impact Was Larger Than the Last-Click Report
The advertiser removed the suspect placements and excluded the associated inventory sources. It also submitted an invalid-traffic review to relevant partners. The immediate result was a 29% drop in reported display clicks. At first glance, that looked like lost reach.
The business result was the opposite. Within two weeks, the cost per qualified session fell 34%, product-page-to-cart rate increased 22%, and the paid media team shifted spend toward channels with verified post-click activity. Based on the confirmed invalid patterns and the spend assigned to affected inventory, the company estimated that $31,400 of the prior month's display budget had produced little or no real buying intent.
That figure was deliberately conservative. It did not claim that every short session was fraud. It counted only traffic tied to multiple validated indicators and known low-quality placements. This matters when reporting findings internally. Inflated fraud estimates damage credibility just as quickly as ignored fraud damages budget efficiency.
Build Detection Around Post-Click Evidence
Most ad platforms provide invalid-click filters, but their definition of invalid traffic may not match your commercial definition of waste. A platform can remove obvious bots while still billing for low-quality, manipulated, or misrepresented traffic that never had a realistic chance of converting.
The strongest detection process connects media data to post-click evidence. Track the click ID, campaign, placement, timestamp, IP-derived location where permitted, device characteristics, and downstream events. Then compare patterns across channels, regions, and cohorts rather than evaluating a single metric in isolation.
Start with a baseline. Know the normal range for session duration, pages per visit, conversion lag, repeat-IP frequency, and event order for legitimate traffic. An alert is more useful when it says a placement has five times the normal duplicate-device rate than when it simply says performance is poor.
Server-side event validation is equally valuable. Client-side tags can be triggered by scripts, blocked by privacy tools, or duplicated by implementation errors. A completed checkout, authenticated account action, or server-confirmed form submission carries more weight than a browser event alone. The right evidence depends on the funnel, but the principle is consistent: optimize toward actions that are costly to fake.
Where Teams Get It Wrong
The most common mistake is treating fraud detection as a monthly reporting task. By the time a month-end report identifies suspicious traffic, the budget has already moved. Monitor higher-risk campaigns weekly at minimum, and review major anomalies as soon as spend or click volume changes sharply.
Another mistake is blocking too broadly. A single IP range, device type, or country can contain both fraudulent and legitimate users. Exclude inventory sources when the evidence is strong, but test the impact of exclusions and keep a record of why each rule exists. Overblocking can reduce reach and distort future performance analysis.
Finally, do not confuse proxy use with a complete anti-fraud system. Proxies provide independent access points for ad verification, geo-validation, and competitive checks. They do not replace log analysis, fraud scoring, vendor controls, or a clean measurement architecture. They make your verification process more representative of the markets you buy, which is a meaningful but specific advantage.
A Faster Operating Model for Paid Media Teams
The advertiser now runs a simple control loop. It ranks traffic sources by spend and anomaly score, validates high-risk delivery from selected locations, reviews server-side behavior, and moves budget only after the source shows qualified activity. This creates a direct link between traffic acquisition and traffic quality.
The useful closing thought is not that every unusual click is fraud. It is that unexplained traffic should not earn more budget by default. When a source cannot demonstrate real users, credible locations, and meaningful post-click behavior, treat it as unproven inventory until the data says otherwise.