Glossary
What is click spam?
Click spam is a form of ad fraud in which large volumes of fake or unseen clicks are generated, so that the fraudster can claim attribution credit for installs that would have happened anyway.
How it works
The fraudster fires clicks for users who never saw an ad — often in the background of an unrelated app, at scale, across many advertisers.
Most of those clicks lead nowhere. But if any of those users independently installs one of the advertised apps within the attribution window, the recorded click is there, and last-click attribution awards the credit.
It is a lottery played with someone else's money. The individual click costs nothing to fabricate, and the payout on a hit is a full attributed install.
Why it is hard to detect
The installs are real. The users are real. They open the app, they use it, they retain and monetise exactly like organic users — because that is what they are.
Every downstream quality check therefore passes. Retention looks fine, revenue looks fine, and the cohort is indistinguishable from good traffic, because it is good traffic that was going to arrive anyway.
What is being stolen is not the user but the attribution, and only the attribution data reveals it.
The signals
- [CTIT](/resources/glossary/click-to-install-time-ctit) distribution. Genuine clicks produce a tight distribution shortly after the click; click spam produces a long, flat tail because the install had nothing to do with the click.
- Enormous click volume with a tiny conversion rate, far outside normal ranges.
- Clicks with no corresponding impressions.
- Suspiciously wide device and geographic spread from a single source.
- Flat performance under a holdout, which is the definitive test — see incrementality.
The defence
CTIT analysis catches most of it, and an MMP will do this automatically. Beyond that, the structural defence is a holdout: a source that is genuinely driving installs will show lift when withheld, and a click spammer will show none.
This is the strongest argument for incrementality testing that has nothing to do with measurement philosophy — it is the only method that cannot be fooled by fabricated attribution evidence.
Common questions
How is click spam different from click injection?
Click injection is targeted — a malicious app detects a specific install in progress and fires a click just before it completes. Click spam is indiscriminate, firing volume and hoping to catch installs by coincidence.
Can I get refunded for click spam?
Depends entirely on your contract. Agreeing a fraud definition and clawback process before launch is far more effective than arguing about it afterwards.
More in fraud and validation
How invalid traffic is manufactured, and how it is caught.