Click fraud is what happens when someone clicks a pay-per-click advert with no intention of ever becoming a customer. The advertiser is charged anyway. The industry now files it under the broader heading of invalid traffic, which covers everything from a bot farm to an honest double-click, and the distinction matters because the two are handled very differently.
Two motives, two very different attacks
Almost all deliberate click fraud comes from one of two places, and they behave nothing alike.
| Publisher fraud | Competitor fraud | |
|---|---|---|
| Who benefits | The site showing the ads, which earns per click | A rival, who gains nothing directly |
| Goal | Revenue | Draining your daily budget so your ads stop showing |
| Pattern | Spread across many advertisers, steady over time | Concentrated on your highest-value keywords, often early in the day |
| Where it shows | One placement with odd engagement | Budget exhausted by mid-morning with no conversions |
The second is the one that hurts a small advertiser most, because it does not need to be sophisticated. A modest budget on expensive keywords can be exhausted before lunch by a person with a phone, and the effect is not a wasted click here and there — it is your competitor having the afternoon’s auctions to themselves.
How it is actually done
Bots and botnets. The largest-scale version. Software imitates browsing on compromised machines, which spreads the activity across thousands of ordinary residential addresses and makes it hard to filter by IP alone.
Click farms. Real people paid to click, usually on real devices. Because the behaviour is genuinely human, this is the hardest kind to detect from signals alone.
Ad stacking and hidden placements. Several adverts layered in the same space, or ads rendered in a pixel-sized frame. Every one records an impression and only the top is visible — fraud against the impression rather than the click.
In-app fraud. Adverts requested and clicked by an app in the background while the user does something else entirely.
What the ad platforms already do
Detection is largely automated and happens before you are billed. Platforms discard clicks that match known invalid patterns — repeat clicks from one source in quick succession, traffic from data centres rather than consumer connections, engagement that ends the instant the page loads — and these are filtered out silently. Anything caught after billing is normally returned as a credit rather than a cash refund.
This is why the raw number in your reporting is not the number you paid for. Comparing clicks against charges is the first sanity check worth doing, because the platform has usually removed the crude attacks already.
Signs worth investigating
None of these proves fraud on its own; together they justify a closer look. Click-through rate rising while conversions stay flat. Bounce rate close to total on paid traffic but normal on organic. Budget consistently exhausted at the same early hour. A sudden concentration of clicks from one region you do not sell to. Sessions lasting a second or two with no scroll. And the clearest of all: cost per conversion climbing steadily while cost per click stays the same.
What you can actually do
Start by narrowing where the ads appear. Search campaigns that opt into display partners are exposed to far more low-quality inventory than search alone, and turning that off is often the single biggest improvement. Review placement reports and exclude sites that generate clicks and nothing else. Add IP exclusions where you can identify a persistent source, accepting that this is a blunt instrument against botnets.
Then change what you are optimising for. Bidding towards conversions rather than clicks makes fraudulent traffic actively self-defeating, because clicks that never convert teach the system to stop chasing that audience. Tighten geographic and scheduling targeting to the hours and places you genuinely sell in.
Finally, keep evidence. If you intend to raise a case with the platform, dated reports showing the pattern and the corresponding lack of conversions are what the argument rests on — not the impression that something felt wrong.
Frequently asked questions
What is click fraud?
Clicking a pay-per-click advert with no genuine interest, in order to earn revenue as a publisher or to drain a competitor’s budget. The advertiser pays for the click either way.
Do ad platforms refund fraudulent clicks?
Much invalid traffic is filtered before billing. Anything identified afterwards is typically returned as account credit rather than money back.
Can a competitor click my ads to waste my budget?
Yes, and on a small budget it is effective. Repeated clicks from one source are usually filtered, but a determined person using ordinary devices is harder to catch.
How do I know if I am a victim?
Look for clicks rising while conversions do not, near-total bounce on paid traffic only, budgets exhausted unusually early, or clicks concentrated in places you do not sell to.
Is click fraud illegal?
It breaches every major ad platform’s terms, and deliberately draining a competitor’s budget can amount to fraud or unfair competition depending on the jurisdiction. Enforcement is mostly contractual rather than criminal.
Does clicking my own ads count?
Yes. Clicking your own adverts, or asking others to, violates platform policy and can result in the account being suspended.
Related reading
For the wider context see how digital marketing can boost your business.


