The $100 billion ad fraud problem marketers and businesses aren’t being told about

John Wanamaker opened his first store, a men’s clothing shop called Oak Hall, in Philadelphia in 1861. By the time he died in 1922, he had built one of the country’s first modern department stores, invented the price tag and dreamed up the money-back guarantee, ideas so ordinary now that it’s easy to forget someone had to think of them first.

He is also credited, though the record is thin, with a line that has haunted advertising ever since: that half the money he spent on it was wasted, and he could never determine which half.

John Wanamaker's flagship department store in Philadelphia, the building that grew out of his original 1861 shop, Oak Hall.

For 100 years, nobody could answer him. Then digital advertising arrived, and it made a very grand promise. It would count every eye that ever looked at an ad. It would follow every dollar. It would, at long last, tell us which half.

It has not told us. What it has done, instead, is get remarkably good at pretending that it has.

That is the uncomfortable finding at the center of a growing body of research. The industry that promised to finally solve Wanamaker’s riddle has instead built a system where roughly one in five ad impressions goes to a bot or a click farm rather than a person, where a gender-neutral job ad can reach men at twice the rate of women because the algorithm found their attention cheaper to buy and where the platforms selling both the audience and the fraud protection have little financial incentive to fix either. Most marketers have no idea how deep the problem runs, because nearly everything they’re told about it comes from companies with a financial stake in the answer.

Start with the fraud, because the numbers alone tell a strange story. Vendors that sell fraud-detection software put global losses from digital ad fraud somewhere north of $100 billion in 2026, with some estimates running as high as $250 billion.

One dataset built from more than 105 billion ad impressions found roughly one in five came from a bot, a spoofed device or a click farm rather than a real person. A click farm is a warehouse of low-wage workers or automated devices paid to fake clicks and views on demand, harder to catch than a bot because a real person is behind it, just one with no genuine interest in the ad.

Those figures aren’t new territory for the industry. Adobe reported in 2018 that bots made up about 28% of all website traffic. The IAB Tech Lab, an industry standards body, reported around the same time that only 59.8% of clicks could be confirmed as human traffic.

Pixalate, a fraud-detection firm, put invalid traffic on desktop programmatic advertising at 10% to 15% that year. Programmatic advertising is the automated buying and selling of ad space through real-time software auctions, rather than a person negotiating a deal directly with a publisher, which is what makes it fast and scalable but also what gives fraud so many places to hide between the buyer and the actual website.

Those figures sound exact; they aren’t. A 2020 review of digital advertising markets, co-written by economists at Northwestern, Columbia, Berkeley, Stanford, Yale and UC San Diego, points out that fraud is defined by intent, and intent can’t be measured directly.

Every fraud number in circulation is an inference, not a count. The same paper notes that in 2019, industry estimates put annual losses closer to $6.5 billion to $19 billion. Six years and a factor of 10 later, the number says as much about who’s doing the counting as it does about the underlying fraud. Fraud-detection firms have an obvious incentive to find more of it. Advertising platforms have the opposite incentive, since fraud that isn’t caught still generates revenue for them.

Kenneth Wilbur and Yi Zhu worked out the math behind that incentive in a 2009 paper in the journal Marketing Science. Under ordinary market conditions, they found, a platform can come out ahead financially by failing to catch fraud, even after advertisers raise their bids to account for the fraud they expect to eat.

The platform gets paid regardless of who’s looking at the ad. It is a credibility problem with no easy fix: small advertisers are left trusting that their partners’ fraud-detection systems work, even though those same partners get paid every time the systems fail.

The fraud itself has gotten harder to see. In 2018, federal prosecutors filed the first criminal ad fraud charges in the United States after uncovering a botnet known as 3ve, which used more than 1.7 million infected computers to fake human browsing behavior at scale, complete with simulated mouse movement, fake browser sessions and falsified Facebook logins designed to make datacenter traffic look residential.

Vinton Cerf, one of the engineers who helped build the internet’s core protocols, has since said the people who designed it didn’t build enough defense against this kind of abuse into the system from the start.

“I didn’t pay enough attention to security,” Cerf told IEEE Spectrum, reflecting on the internet’s early design. 

Ad delivery was built to trust that a request for a webpage came from a person, because verifying humanity, the way a website might require solving a CAPTCHA, was never part of the design.

Publishers have found the fraud aimed at their own names just as unsettling. The Financial Times discovered its own domain being impersonated across 25 ad exchanges, with counterfeit video inventory that outnumbered the paper’s real supply by a factor of 30. The Guardian bought its own supposed ad inventory on the open market and found that 72% of what it purchased wasn’t running on Guardian.com at all.

The industry has tried to respond with transparency standards rather than just detection software. The IAB Tech Lab introduced a standard called ads.txt in 2017, letting publishers publicly list which sellers are authorized to offer their inventory, so buyers can check a file before assuming an offer is legitimate.

The Trustworthy Accountability Group, an industry coalition, maintains a running Data Center IP List meant to flag traffic originating from server farms where no real human would be browsing. Adoption of these standards has been widespread, and anecdotal reports suggest they’ve meaningfully reduced fraud within the supply chain. But they only address fraud between advertising businesses. They do little to help an advertiser know, in the moment, whether the person looking at an ad is a person at all.

Not every corner of digital advertising carries the same exposure. Search advertising on a closed platform such as Google Ads sits at the cleaner end of the spectrum, largely because it doesn’t rely on the same web of third-party exchanges and resellers that let fraud hide in the gaps between buyer and seller.

Independent trackers put average invalid-click rates on Google Search campaigns at roughly 11%, well below the high-teens-to-20%-plus rates common on open programmatic display and video inventory. The difference is structural rather than reassuring: a search ad is shown against a query the user typed, a real declaration of intent, while a display ad is served into passive inventory that anyone, including a bot, can be made to load.

That distinction is also why the Financial Times and Guardian cases happened on the open exchange side of the business rather than inside a closed search platform. It doesn’t make Google’s own reporting neutral. Google defines what counts as invalid traffic on its own platform, detects it with its own tools and reports back a number nobody outside the company can audit, the same conflict of interest Wilbur and Zhu identified in ad platforms generally: whoever profits from the traffic is also the one certifying it’s clean.

Fraud isn’t even the biggest problem. Catherine Tucker, a professor at MIT Sloan who has spent years testing whether targeted advertising really hits its targets, published a study with Anja Lambrecht of London Business School examining ads for STEM careers. The ad was built to reach men and women equally. It reached men far more often. That’s because advertising space aimed at women costs more, because more advertisers want it, so an algorithm told to maximize reach for the lowest price will quietly drift toward cheaper, male audiences even when nobody instructed it to.

“Women have more expensive eyeballs than men,” Tucker said in an interview.

Nobody broke the law. Nobody stole a dollar. A cost-minimizing machine did exactly what it was told, and the result looked like bias from the outside.

In a separate study with Nico Neumann and Timothy Whitfield, Tucker tested how accurately the data brokers behind those targeting decisions could identify a stranger’s age and gender online.

“The process which underlies the creation of user profiles and segments for targeting is a ‘black box,’” Tucker said, noting that advertisers buying these profiles have little way to check whether the data is even accurate. The advertiser pays for precision it has no way to verify, from a vendor whose methods it isn’t allowed to see.

Fraud isn’t confined to display and search advertising, either. Affiliate marketing, where publishers earn a commission for referrals that convert into sales, has its own version of the problem.

Benjamin Edelman and Wesley Brandi studied how advertisers monitor affiliate partners for rule violations and found an uneven pattern: outside specialists hired to police affiliate fraud were more effective at catching clear-cut violations, while a company’s own internal marketing staff did better at catching the murkier, borderline cases.

Neither approach caught everything. The 2016 investigation firm K2 Intelligence, hired by advertisers to examine the broader programmatic supply chain, documented widespread and largely hidden markups by agencies buying guaranteed ad inventory on their clients’ behalf, arbitrage that the advertisers footing the bill had no way to see.

Academic research specifically on fraud remains thinner than the volume of vendor reports would suggest. A search of peer-reviewed journals turns up a handful of theoretical papers on the incentives to commit fraud, some computer science research proposing detection algorithms, and very little empirical work tying fraud to real market outcomes.

Most of what passes for settled knowledge about digital ad fraud comes from companies that sell the fix, which makes the two forensic examples from the Financial Times and the Guardian more valuable than most industry white papers combined.

Marketers looking for a practical defense have a few real options, though the same skepticism that applies to the fraud statistics applies to the companies selling the fix. Three verification vendors, DoubleVerify, IAS and HUMAN Security, hold accreditation from the Media Rating Council, an independent audit body, which sets them apart from vendors making unaudited claims about their own detection rates.

HUMAN Security, formerly known as White Ops, was one of the firms that helped law enforcement dismantle the 3ve botnet in 2018. Smaller, self-serve tools aimed at Google Ads and Meta accounts exist for advertisers without an enterprise budget, though their own published fraud percentages deserve the same scrutiny as any other vendor’s.

The more useful question, in either case, is whether a tool filters fraud before the bid is placed or only refunds the advertiser after the money is already spent. Pre-bid filtering stops the fraudulent impression from being paid for at all. Post-bid detection catches it after the fact, which helps the ledger but does nothing to stop it from happening again.

None of this means digital advertising doesn’t work, or that every dollar spent on it vanishes into a botnet. It means an industry has spent 25 years selling a level of certainty it has never been able to back up, and marketers have mostly gone along with it, because auditing the real number is expensive, the tools to do it thoroughly are limited, and the answer rarely flatters the platform selling the ad.

The honest position, for a marketer trying to spend a budget wisely in 2026, is closer to skepticism than despair: treat any round fraud number as an estimate built by someone with something to sell, ask a platform what its contract says about refunding fraud rather than what its marketing page promises, and remember that “invalid traffic” and “poor targeting” are not the same failure, even though they often get blamed on each other.

Wanamaker, who couldn’t say which half of his budget was wasted, was in his own way more honest than most of what gets published about digital advertising today. At least he admitted he didn’t know.

Previous
Previous

Wally’s, Wawa and Buc-ee’s are all building along Indiana’s I-65, and Sheetz says it’s next

Next
Next

Substack’s new AI detector is solving the wrong problem