Ad fraud

Click fraud terms explained: false clicks, fake clicks, click spamming and forced clicks

By the ROAS365 team·11 min read

Talk about click fraud for ten minutes and the same thing will pick up four or five names: false clicks, invalid clicks, click spamming, click injection, forced clicks, bot clicks. Nobody is being deliberately obscure. These terms come from four different industries — ad platform billing systems, mobile measurement vendors, affiliate networks, and the security and anti-bot world — each of which named what it could see, and the names have since been mixed together and overlap badly. The cost of using the wrong one is real: when you file a platform dispute, challenge a partner, or simply try to get a team aligned, a term that points at a mechanism can be checked, while a generic accusation cannot. This article takes the vocabulary apart: what each term actually describes, where it came from, what it looks like in reporting, and when the distinction changes what you do next.

TL;DR
  • The vocabulary is fragmented because it comes from four systems that never shared a dictionary: platform billing filters, mobile attribution, affiliate settlement disputes, and bot detection.
  • "False clicks" and "fake clicks" are informal near-synonyms and are not a formal category anywhere. "Click spamming", "click injection" and "forced clicks" each name a specific, distinguishable mechanism.
  • Platform reporting mostly uses the neutral word "invalid", because filtering does not require establishing intent, and the word fraud does.
  • The practical payoff of getting the word right shows up when you need someone else to act: a named mechanism can be verified, a vague claim gets answered with "filtering already ran".

Why the vocabulary is a mess

Each term was coined by a system describing what it could observe, and those systems observe completely different slices. An ad platform sees billing logs: repeated clicks from one device, requests originating in data centres, obviously automated behaviour. It needs a word that can go on an invoice, so it says invalid clicks. Mobile measurement vendors see the relationship between a click timestamp and an install timestamp, which produced terms named after time distributions — click spamming and click injection. Affiliate networks see settlement disputes, where a partner's click volume does not reconcile with the conversions behind it, producing language about stolen credit and hijacked attribution. Security vendors work purely from traffic characteristics and say bot and automated traffic, deliberately never touching commercial intent.

The result is that one suspicious visit can carry four different names in four reports, none of them wrong. The trouble starts when the four languages get mixed in a single conversation. You believe you are describing one thing, the other side hears another, and neither notices the mismatch.

Key point

There is a simple test for whether a term is useful: does it point to a mechanism that can be observed and reproduced? "Invalid clicks" points to a platform's filtering outcome and can be looked up. "Click injection" points to a specific time distribution and can be measured. "Fake clicks" points at nothing; it expresses a suspicion.

The two umbrella terms: click fraud and invalid traffic

Sort the top two out first, because everything else hangs beneath them. Invalid traffic is the wider, neutral one: every click and impression in platform reporting that should not be billed, covering coordinated automation, an accidental double tap on a mobile banner, and an ordinary crawler alike. It makes no claim about motive. Click fraud is the subset somebody generated on purpose.

The industry cuts invalid traffic once more, into general and sophisticated categories — the first removable with known lists and simple rules, the second deliberately imitating human behaviour and identifiable only through behavioural analysis. That layer is covered in more detail in the difference between GIVT and SIVT. The thing worth carrying forward is that platform billing language nearly always stops at "invalid", because removing a click does not require establishing who was behind it or why, whereas calling it fraud does.

Term by term

The table below covers the terms most likely to come up in practice. The third column matters more than it looks: knowing which system a term came from usually tells you which data the other person is arguing from.

Term What it actually describes Where it comes from What it looks like in reporting
False clicks / fake clicks Informal shorthand for "this click does not represent genuine interest". Names no mechanism and implies nothing about intent. No formal source; it is how advertisers talk to each other. Appears in no report field. It shows up in your own suspicion, or in an email to support.
Invalid clicks Clicks the platform itself judged unbillable and already credited back. It is an outcome, not a technique. Ad platform billing and filtering systems. A real, queryable field by date and campaign. See how Google Ads reports invalid clicks.
Bot clicks / automated clicks Clicks produced by scripts, headless browsers or automated device farms, with no human decision behind them. Security and anti-bot vendors, describing traffic characteristics only. Near-zero dwell time, missing interaction events, concentrated network ownership. See detecting bot traffic.
Click spamming (click flooding) Reporting clicks in volume for devices that were never shown an ad, betting that some will install anyway and the credit will land. Mobile measurement vendors, named after click-to-install time distributions. A wide, flat click-to-install window, an unusually low conversion rate, and click volume far beyond a source's real reach.
Click injection Detecting an install already under way on the device and firing a click moments before it completes, capturing the attribution. Mobile measurement vendors again — same family, far more targeted. An unnaturally short click-to-install gap, clustered inside a few seconds. The exact opposite shape to click spamming.
Forced clicks A click recorded without any intent to click: full-screen overlays, close buttons that are themselves the ad, deliberately oversized mis-tap zones. Publisher-side and monetisation language, common in traffic quality reviews. An implausibly high click rate paired with almost no time on the landing page, near-total bounce, and a handful of placements carrying it.
Competitor clicks Rivals clicking your ads repeatedly, manually or semi-automatically, to consume budget. Usually low volume but pointed. Search advertiser vernacular; no platform category corresponds to it. Narrow and repetitive: a few keywords, a stable location, working hours, no downstream activity. See identifying competitor clicks.
Affiliate click hijacking A partner appending clicks, overwriting parameters or inserting its identifier on the last hop, to claim conversions it did not drive. Affiliate network settlement disputes. One partner's last-click share out of proportion to its real traffic, often with an extra hop in the redirect chain. See detecting affiliate click fraud.

There is a parallel set of terms on the impression side — ad stacking, pixel stuffing, forced refresh — which inflate impressions rather than clicks. Different mechanisms, same way of reading them; those sit under types of ad fraud.

Which terms are actually saying the same thing

Three groups are effectively interchangeable in everyday conversation, and knowing it saves a lot of pointless argument. First, "false clicks", "fake clicks" and "invalid clicks": the first two are colloquial, the third is the platform's own accounting. When someone says one of the first two, they usually mean the third and have not checked the report yet. Second, "bot clicks", "automated traffic" and "crawler traffic": one class of source described from the behaviour, the technology and the identity angle respectively. Third, "click fraud" and "ad fraud": the latter is broader and covers the impression and conversion sides too, but when a conversation is only about clicks the two get used as one.

What cannot be swapped are the mechanism-level terms. Calling click injection "click spamming" reverses the time distribution you should be looking for. Calling forced clicks "bot clicks" sends you to check network ownership when the problem is a placement's layout. Calling competitor clicks "bot traffic" sends you to tune filtering rules against a human. Each of those three mix-ups points the investigation the wrong way entirely.

What each mechanism leaves behind in the data

A term earns its keep by telling you which report to open. The list below doubles as an order of investigation.

One lesson recurs: look at how much the platform already filtered before deciding to dig further. A lot of "this traffic looks wrong" intuition explains itself once the actual invalid-click figure is on screen, and only what remains deserves the time. The broader defensive approach is laid out in click fraud protection.

Which word to use in a dispute

Once you need cooperation from someone else, phrasing decides the quality of the reply. Telling platform support that your traffic has a lot of fake clicks reliably returns "invalid traffic is filtered automatically", because nothing verifiable was offered. Rewriting it as "between 3 and 9 July, 40% of clicks on campaign X came from one ASN, average landing-page dwell was under two seconds, and interaction events were absent" gives the recipient something to look up — and even if the answer is still that filtering handled it, this time it was actually checked.

The same applies to partners, with a more asymmetric risk. A mechanism-level challenge reads: "your last-click share does not match your impression volume, there is an extra hop in the chain, please explain who added it." A vague one reads: "your traffic is fake." The first can be explained or fixed. The second triggers a defensive response, and if your read was wrong, the damage to the relationship is not recoverable. The rule follows from that: verify first, name the mechanism second, and characterise intent last, if at all.

Key point

Only a claim that can be checked has any force. Precision here is not pedantry; it is the only route from "something feels wrong" to "here is a pattern someone can go and verify".

Frequently asked questions

Is click fraud the same thing as invalid traffic?

Not quite. Invalid traffic is the wider, neutral category used in platform reporting: every click or impression that should not be billed, whether it came from a data-centre crawler, a double tap on a mobile banner, or a coordinated scheme. Click fraud is the subset where someone generated the activity deliberately. Platforms mostly report the neutral term because filtering does not require proving intent, while the word fraud does.

What is the difference between click spamming and click injection?

Both are mobile attribution terms and both aim to claim credit for an install the actor did not drive. Click spamming fires large volumes of click reports for devices that were never shown an ad, hoping some of them install the app anyway. Click injection is narrower and better targeted: it detects an install already in progress on the device and fires a click a moment before it completes. Click spamming looks like a wide, flat click-to-install window; click injection looks like an unnaturally short one.

Are false clicks and fake clicks different things?

In practice they are used as synonyms, and neither is a formal category in any platform's documentation. Both are informal ways of saying a click was recorded that does not represent genuine interest. If someone uses one of them with you, it is worth asking which mechanism they mean, because the response differs completely between an automated script, a competitor clicking manually, and a partner misfiring click reports.

Do clicks from a competitor count as click fraud?

They fall inside the invalid category and get filtered like anything else if the pattern is detectable, but they are usually low volume and much harder to evidence than automated activity. The signature is narrow rather than large: repeat clicks on a small set of keywords, from a stable location, during working hours, with no downstream activity.

Does the terminology matter, or is it all the same problem?

It matters exactly when you need someone else to act. A support ticket or a partner dispute that names a mechanism and shows the matching pattern can be checked. A ticket that says the traffic is fake gives the recipient nothing to verify, and the usual reply is that filtering already ran.

Want a checkable record of every visit?

ROAS365 provides visitor routing with a per-visit record of what happened. Every visitor is served the same landing-page URL, and each arrival can be checked by device, region and source.

← Back to all articles