- Rule out the boring explanations first. Rising spend is most often caused by auction shifts, broad match expansion, or crawler and bot traffic — competitor clicks come last on that list. Skipping the first three usually means fixing the wrong thing.
- Rival clicks look narrow and human: a few IPs or one local ISP, clustered in business hours, hitting only your most expensive commercial keywords, with near-zero time on page. Round-the-clock, globally spread, datacentre-IP traffic is a bot problem instead.
- Platforms already filter repeated clicks automatically; the filtered share shows up as invalid clicks in your reports and is not billed. You can submit an invalid click report with data attached, but that triggers an internal review — not a guaranteed refund, and not on a timetable you can plan around.
- A usable evidence file aligns five fields — timestamp, IP or ISP, keyword, device, time on page — and compares the suspect window against a clean baseline. A screenshot of rising spend on its own proves nothing.
- What you control is the account layer: IP exclusions, tighter geography, ad scheduling, bid caps on the affected keywords, negative keywords, and conversion-based bidding. None of it stops a determined person, but together they cap how much budget any single source can absorb.
What competitor click fraud actually is
Competitor click fraud means a rival repeatedly clicking your paid search ads, not to evaluate your product but to consume your daily budget. Once the budget is exhausted, your ads stop showing for the rest of the day and the auction position is left to someone else. It is the variety of click fraud with the clearest motive — and usually the smallest scale.
Keep it distinct from two neighbours. Bots and automated scripts generate invalid traffic: high volume, indiscriminate, frequently from datacentre ranges. Affiliate- or publisher-side ad fraud aims at conversion attribution and commission, not at draining you. The three leave different fingerprints and need different responses, and conflating them is the first step towards investigating the wrong thing.
Before attributing a spend anomaly to a rival, eliminate three things: whether broad match or a new automated campaign was recently added; whether the search terms report shows an influx of loose, unrelated queries; and whether CPC rose across the board over the same period, which points to the auction rather than to you specifically. These three explain most accounts that merely look targeted.
Signals that genuinely point to repeated human clicks
No single signal is conclusive. What matters is whether several appear together and all point at the same narrow window. The table separates what each signal supports from what it does not:
| Signal | Rival-click shape | What it does not prove |
|---|---|---|
| Source concentration | A handful of IPs, or one local consumer ISP, recurring across the clicks | Shared offices, corporate NAT and carrier-grade NAT put many legitimate users behind few IPs |
| Time distribution | Clustered in local business hours, especially soon after budget resets | Your actual buyers probably also search during business hours |
| Keyword selectivity | Only the highest-CPC commercial and brand terms; long-tail untouched | High-value terms carry more volume anyway, so higher absolute clicks are expected |
| On-page behaviour | Zero to three seconds, no scroll, no second page, bounce near 100% | Slow pages, load failures and message mismatch produce identical instant exits |
| Device and user agent | Real browser user agents and ordinary device fingerprints, repeating unusually often | Modern bots present real browser signatures too — a clean UA does not mean a human |
| Geography | Concentrated inside your own service area, where local rivals sit | If your targeting is already limited to that area, concentration is guaranteed |
A practical bar: four or more of the six hitting together inside the same time window is worth treating as a targeted pattern. One or two on their own are normal traffic noise.
If the traffic turns out to be round-the-clock, widely distributed, and carrying datacentre ranges or automation signatures, the problem is not a rival but the bot layer — see bot traffic detection and the tiering in general versus sophisticated invalid traffic.
How to build an evidence file that holds up
Platform reviews weigh how well the data lines up, not how strongly the case is described. A usable file needs four layers:
1. Define the suspect window and a baseline
Mark the suspect period first, usually a few days to two weeks, then pick a comparable clean period with similar seasonality. Every comparison runs between those two. Without a baseline, no number can establish that anything is abnormal.
2. Pull five aligned fields from platform reports
Timestamp, IP or ISP, the keyword and match type that triggered the click, device type, and time on page. The first two come from server logs or analytics, the last three from the ads platform. Align them into one row per click rather than separate screenshots. In Google Ads, also export the invalid clicks column, which shows how much has already been filtered on your behalf.
3. Quantify rather than characterise
Write "68% of clicks in the suspect window came from three IPs, against 4% in the baseline; those clicks averaged 1.8 seconds on page against 47 seconds" — not "there were many suspicious clicks". Only recomputable numbers survive a review.
4. Keep the raw exports
Keep the original CSVs, log excerpts and report exports, with the extraction time and the definitions used. If you are asked for more later, being able to reconcile with what you already submitted is the minimum bar.
Documentation records what happened. It should not extend to naming a specific company publicly. IP ownership can point at an organisation, but shared networks, proxies and dynamic allocation keep it well short of identification. Supply the data and leave the conclusion to the platform.
How the platforms actually handle it
This is where expectations most often go wrong. Three facts:
- Filtering is automatic and happens upstream. Repeated clicks from the same device or network in a short span are mostly classified as invalid and discarded before billing. What you see in reports is an invalid clicks count, and that portion is not charged.
- There is no case-by-case refund channel. You can file an invalid click report with data attached and the platform will review it internally; where invalid activity is found after billing, the adjustment comes back as an account credit. It is not a process you can schedule around, and no outcome is promised.
- Review outcomes are usually opaque. You will rarely receive a click-by-click explanation. Betting the whole response on the appeal is therefore a poor allocation — account-side adjustments typically act faster.
For how the invalid clicks column is defined and why it differs from your own counts, see invalid clicks in Google Ads.
The account settings you actually control
None of the following stops a determined person. Together they reduce the share of budget any single source can absorb:
- IP exclusions. Exclude confirmed IPs only, and review the list periodically. Over-broad exclusions, especially whole ISP ranges, block real customers too.
- Tighter geography. Limit targeting to the areas you actually sell into, and set location options to presence rather than interest, which removes out-of-area probing.
- Ad scheduling. Schedule ads around the hours when conversions actually occur instead of running flat all day.
- Bid caps. Cap bids on the affected high-cost terms so that any one click costs less.
- Negative keywords. Add negatives to clear low-intent queries pulled in by broad match, which also narrows the surface being hit.
- Conversion bidding. Bid to conversions rather than clicks so budget follows outcomes rather than raw traffic.
- Budget spread. Avoid concentrating a day's budget on one campaign and one expensive term — that structure is the easiest to exhaust.
- Ongoing baselines. Track invalid click share, source concentration and average time on page as a weekly baseline, so anomalies have something to be measured against.
Exposure varies sharply by vertical — local services, legal, insurance and other high-CPC categories see it most. For those differences see click fraud protection by industry, and for the overall framework see the click fraud protection guide.
When it turns out not to be a rival
Most accounts that suspect targeted clicking end up in one of these:
- Match types loosened. Broad match or an automated campaign pulled in unrelated queries; clicks rose while intent fell, which reads as targeting. The search terms report settles it.
- The auction changed. A new entrant or a seasonal peak lifted CPC across the category. Check the trend at category level, not only inside your account.
- Crawlers and monitoring tools. Rank trackers, price scrapers and security scanners hit ad links continuously — low volume but persistent.
- The landing page broke. Slow loads or message mismatch produce instant exits that look identical in the data. Measure speed and message match first — see improving landing page conversion rate.
Only a narrow, concentrated pattern that survives all four is worth treating as targeted. For the wider efficiency picture, see how to improve ROAS.
Frequently asked questions
Can a competitor drain my Google Ads budget by clicking my ads?
Repeated manual clicks do happen, but at a much smaller scale than most advertisers assume. Traffic quality systems filter a large share of repeated clicks from the same device or network before they are billed, and those appear as invalid clicks in your reports. A sustained spend increase is far more often caused by auction changes, broad match expansion or automated crawler traffic.
How can I tell competitor clicks apart from ordinary invalid traffic?
Look for a narrow, human-shaped pattern: a few IPs or one local ISP, clicks in business hours rather than around the clock, entry on your highest-cost commercial keywords only, near-zero time on page, ordinary browser user agents. Broad, round-the-clock, globally distributed traffic from datacentre IPs is a bot problem with different remedies.
Does Google refund clicks from competitors?
There is no case-by-case refund process for suspected rivals. Invalid clicks are detected and discarded automatically and are not charged; where invalid activity is found after billing, credits are issued to the account. You can submit an invalid click report with supporting data, but the outcome is an internal review, not a guaranteed refund, and not on a timetable you can rely on.
What can I actually change in my account to reduce the damage?
The controls that matter are IP exclusions for confirmed sources, tighter geographic targeting, ad scheduling matched to when real buyers convert, bid caps on the affected keywords, negative keywords to remove low-intent matches, and conversion-based bidding. None stops a determined person, but together they reduce how much budget any single source can absorb.
Want visibility into what each click was served?
Every visitor hits the same landing-page URL — invalid-traffic filtering, in-page A/B testing and audience-aware content, with every served result inspectable in the dashboard. No hidden content, no sneaky redirects.