NEW New report: We analyzed 200 million ad clicksSee results
NEW New report: We analyzed 200M ad clicks

The Ad Fraud Brief (Q2 2026): Schemes Designed to Self-Propagate

Ad fraud has always been complex, but in Q2, we saw schemes that were self-sufficient and prolific enough to exploit the biggest ad platforms in the industry, including Google and Meta.

Here’s what the quarter looked like and what it means for your ad budget.

1. Pushpaganda

Scale: 240 million fraudulent bid requests in a seven-day window

Pushpaganda is unlike many ad fraud cases we’ve seen because it didn’t rely on hijacked devices or malware. Instead, it tricked unsuspecting users into generating fraudulent traffic.

Here’s how Pushpaganda worked:

Bad actors used AI-generated content and SEO manipulation to push fake news stories onto Google Discover on mobile. When users clicked those stories, they were taken to completely fake sites and prompted to turn on push notifications.

Next, they received a stream of scareware, including fake legal threats, urgent financial warnings, and alarming health claims. Clicking on these push notifications led to a site running programmatic ads, and every visit counted as an impression advertisers paid for.

Pushpaganda was very effective because the invalid traffic was from real users, removing the need to program complex bots to evade filters. It took advantage of real people on real devices making real clicks.

Source: Hacker News

2. Ad fraud inner circle

Scale: 14.8 million monthly invalid clicksfrom repeat actors recorded in 2026

A fraud analysis published in April suggested that 64.9% of all invalid traffic came from the same repeat actors. This was across all major ad networks, including Google Search, Display, PMax, TikTok, and Instagram.

We’ve seen ad fraud schemes increase in sophistication over the past few years, and platform filters now struggle to catch all invalid clicks. This increased sophistication has sometimes been attributed to Fraud-as-a-Service and the use of AI and machine learning in ad fraud.

But this report highlights something even more significant: The same group of bad actors is responsible for most invalid traffic, consistently building on their methods as they develop more sophisticated schemes.

Source: Yahoo News

3. Meta's ad fraud problem

Scale: $16 Billion in ad revenue to Meta from scam ads

Many ad fraud stories are about bad actors building botnets or hijacking users’ devices. But this one is about how Meta itself has created an environment for ad fraud to thrive.

The story broke in November 2025, when Reuters obtained leaked internal Meta documents. According to reports, Meta projected that roughly 10% of its 2024 revenue ($16 billion) came from scam ads, illegal gambling, and prohibited products. The platform only banned advertisers when the systems determined a fraud certainty of 95% or higher. Anything below was allowed to stay on, despite users submitting around 100,000 fraud reports weekly.

By April 2026, Santa Clara County filed a lawsuit against Meta, citing 15 billion fraudulent ads served daily, with the US Virgin Islands AG filing separately shortly after.

The narrative here is consistent with what we see on many advertising networks and syndicates: Ad platforms will tolerate high levels of fraud to protect their revenue, and advertisers end up funding the cycle.

Source: Reuters, TechPolicy

4. Trapdoor

Scale: 659 millionbid requests per day

In May, researchers dismantled a new self-perpetuating scheme that consistently funded itself, creating a positive feedback loop of ad fraud.

Called Trapdoor, the scheme worked through 455 malicious android apps and 183 command-and-control (C2) domains. When users downloaded one of these apps, they received fake app update notifications, nudging them to install a second app. This second app was the real fraud vehicle. It launched hidden browsers and loaded actor-controlled sites that secretly generated 659 million fraudulent bid requests daily.

Advertisers ended up paying for millions of impressions rendered inside a hidden browser, with no real user actually viewing them.

Some of the ad revenue generated by Trapdoor was used to fund another wave of in-app pop-up ads, prompting even more downloads.

Source: Yahoo Finance

5. Location-hopping bots

Scale: 87 countries one device appeared in within 72 hours

In May, Fraud Blocker identified a fraud pattern called “location-hopping” used by bots to evade filters and drain advertiser budgets. The findings were published in a report that analysed 200 million individual ad clicks across more than 20,000 domains.

Location-hopping involved a single device appearing in over 80 countries within just a few days, rotating through residential proxy networks to pass as legitimate users and evade geo-targeting filters.

A previous report revealed that ad fraud accounts for 22% of all digital ad spend, but their findings now suggest how a handful of bad actors are able to execute click fraud on such a large scale.

Source: Fraud Blocker

Note from Fraud Blocker

Ad platforms don’t always catch invalid clicks, and this quarter’s schemes show why. Some, like location hopping, exploit blind spots in geo-targeting filters. Others, like Trapdoor, are profitable enough to reinvest drained budgets into bigger schemes. We also see in Meta’s case that the issue isn’t necessarily detection-focused. Instead, some systems are incentivized to increase their fraud tolerance.

– Mike Schrobo, Founder and CEO of Fraud Blocker

Q2 Ad fraud takeaways

One common theme we see with the schemes in this quarter is exposure. Bad actors exploited Google Discover, benign-looking utility apps, and even Meta’s own platform to siphon ad budgets.

The conversation is no longer about whether some of your budget is being wasted but how much.

That’s why it’s important to use a third-party protection software like Fraud Blocker. Our system analyzes every click on your ads and blocks invalid traffic before it drains your budget, whether that’s sophisticated bots or hidden browsers.

Try it free for 7 days and see how much invalid traffic is in your campaigns.

Facebook
X
LinkedIn
matthew Iyiola - click fraud specialist

ABOUT THE AUTHOR

Matthew is the resident content marketing expert at Fraud Blocker with several years of experience writing about ad fraud. When he’s not producing killer content, you can find him working out or walking his dogs.

Matthew is the resident content marketing expert at Fraud Blocker with several years of experience writing about ad fraud.

More from Fraud Blocker