PRESS OFFICE
LISTING
HomeNewsAbout UsContact UsWebsite
News

AI is optimising for ad fraud… because you told it to

We discuss an investigation that exposed how a mobile app could turn an apparently genuine consumer into a marketing lead without that consumer ever seeing the advert.
AI is optimising for ad fraud… because you told it to

There is something deeply unsettling about phoning a prospective customer who, according to your marketing systems, has just requested you contact them, only to discover that they have no idea why you called or what you are talking about.

It becomes more unsettling when the product is pet insurance, and the person tells you they do not own a dog or a cat, even though the lead form submitted in their name says they do.

And it becomes something else entirely when you discover that a significant proportion of these leads are generated in the middle of the night, while consumers' Android phones are likely sitting on bedside tables, idle or charging.

That is what we found during a recent Offernet investigation.

It started, as many performance marketing investigations do, with numbers that seemed almost too good to be true.

We were analysing a lead-generation campaign for pet insurance when we noticed that a particular group of third-party mobile app placements began generating an extraordinary proportion of the campaign's volume. At one stage, roughly 70% of the leads were coming through this inventory at a fraction of the cost we were accustomed to seeing through Facebook feed placements. Some of the app placements reported apparent lead conversion rates ranging from 15% to 25%.

From a conventional performance dashboard, this looked like an optimisation breakthrough. The algorithm had apparently discovered a source of abundant, inexpensive demand.

But we did not increase the budget. Instead, we investigated.

The dashboard said the customers had converted. The customers disagreed

The first warning didn’t come from the media platform. It came from the people receiving the leads.

When agents began contacting these prospective customers, the responses did not match the digital data. Some people said they had never enquired about pet insurance; others said they did not have a pet at all. Yet the marketing record looked perfectly plausible. A form had been submitted. Contact information existed. Questions had been answered. The advertising system had recorded a conversion and treated it as evidence of successful marketing.

This is precisely the measurement problem we have spent years trying to solve at Offernet. Most advertising reports begin when an ad is served and end when a digital conversion occurs. Commercial reality does not. A customer may continue through qualification, contact, quotation, approval, payment, retention and, eventually, lifetime value. Touchpoint was developed to make that wider journey visible by connecting upstream marketing activity with downstream operational and revenue outcomes.

In this case, that downstream feedback changed the nature of the investigation. We were no longer asking which placement had generated the cheapest lead. We were trying to determine whether a lead had been generated by a customer. We started separating the mobile app placements, examining customer responses, device characteristics, conversion patterns and the times at which the leads were created.

The pattern became increasingly difficult to dismiss.

Then we noticed what was happening after midnight

One particular class of activity stood out. A significant number of questionable leads were generated between approximately 11pm and 6am.

There is nothing inherently suspicious about somebody applying for insurance at 1am. Consumers don’t operate within office hours, and one should be careful not to turn an anomaly into an accusation simply because it looks unusual. But anomalies become more meaningful when they begin to reinforce one another.

These leads were unusually cheap. Their apparent conversion rates were unusually high. Downstream customer conversations frequently contradicted the form data. The traffic was heavily associated with Android devices. Also, the time-of-day analysis showed a concentration during the hours when many of those devices would reasonably be expected to be idle.

We eventually traced some of this activity to a utility app whose stated purpose was to identify and help protect users from spam telephone calls. The irony was hard to miss.

Our investigation found evidence that the app environment could generate advertising activity even when users were not actively engaging with it. Ads could be loaded in the background, interactions could be generated, and information already available to the app could be used in a conversion process that resulted in personal details being submitted to marketers.

The consumer did not have to consciously see the advert in the way an advertiser would ordinarily understand advertising exposure. In the cases we investigated, people who received the resulting calls denied making the enquiry.

An app intended to protect its users from unwanted calls was therefore associated with activity that could lead directly to those users receiving unwanted marketing calls.

We have reported the relevant evidence to Meta and are engaging with the platform. We are not publishing the names of the applications involved while these processes continue. The specific app matters far less than the larger mechanism, because once we started researching the behaviour more widely, it became clear that the digital advertising industry has been confronting variations of this problem for ages.

Dr Augustine Fou has warned about the sleeping phone for years

Few researchers have been as persistent on this subject as Dr Augustine Fou, whose work through FouAnalytics has repeatedly challenged marketers to examine what actually sits underneath apparently valid digital traffic.

Fou has written extensively about apparently innocuous utility apps, including flashlight, alarm clock, keyboard, and camera applications, that generate advertising activity even when users are not actively using them. In 2021, he discussed the problem in almost exactly the terms we encountered, asking what happens when an "alarm clock app [is] loading ads in the background when the person is asleep".

His broader argument is important, because it challenges the comforting assumption that fraud must originate from an obviously fake device or a conventional bot. A real person can own the phone. The phone can be real. The installed application can perform a genuine utility. The network request can be technically valid. Yet the advertising activity itself may still have no relationship to human attention or intent.

Fou has described mobile devices as particularly attractive fraud infrastructure because they remain switched on and connected for long periods. He documented utility-style apps loading ads continuously in the background, even when neither the app nor the device was actively in use. More recently, he has highlighted apps containing hidden browsers that load webpages in the background on devices, noting that these interactions can evade simplistic fraud models precisely because the underlying device is genuine.

This distinction matters enormously. If an advertiser's anti-fraud logic asks only, "Was this a real Android device?", the answer may be “Yes”.

The better question is, "Was there a real human intentionally performing this action?" Those are not the same thing.

The industry has a name for some of this behaviour

One established technique is known as click flooding, or click spam. AppsFlyer describes it as fraudulent clicks being generated for users who did not make them, sometimes while the fraudulent app is operating in the background. The objective is often attribution theft, with the fraudulent source hoping that one of its fabricated clicks will be recorded as the final interaction before a legitimate conversion occurs.

Adjust describes a similar pattern in which apps, including utility tools, can invisibly load and click advertisements in the background. The resulting tracking requests can contain convincing device and campaign information even though the person using the phone never performed the interaction.

What we encountered, however, raises the stakes beyond the click. A click can steal attribution or waste advertising spend. A fabricated conversion can influence the optimisation system itself.

Lead generation fraud is a recognised problem. Impact.com, for example, documents schemes in which malicious publishers obtain genuine personal information and then automatically populate advertiser forms with that data, making automated activity resemble legitimate lead generation. The identity can therefore be real even when the acquisition event is not.

There is no single universally adopted industry term that neatly describes every element of the pattern we investigated. I think the most useful description is conversion-event fraud: technology generates the event that an advertiser has defined as success, without the human intent that the event was supposed to represent.

That is a particularly dangerous form of fraud in an AI-optimised advertising environment.

Hidden WebViews have turned real phones into invisible advertising machines

The scale of related fraud operations should remove any temptation to dismiss this as a fringe problem.

In September 2025, Human Security disclosed SlopAds, an operation involving 224 Android apps downloaded more than 38 million times across 228 countries and territories. The apps created hidden “WebViews”, effectively invisible browser environments, which navigated to threat-actor-controlled websites and generated fraudulent ad impressions and clicks. At its peak, Human recorded 2.3 billion fraudulent bid requests per day. The operation also used anti-analysis checks, encrypted code and even steganography, hiding elements of the malicious payload inside image files to make detection more difficult.

What makes SlopAds especially instructive is its conditional behaviour. Human found that the fraudulent activity was activated only for certain installs associated with the threat actor's advertising campaigns. An ordinary installation could therefore behave differently from one that enters via the fraudster's preferred acquisition path. This makes static inspection considerably less reliable, because the app can appear innocent under one set of circumstances while behaving differently under another.

In 2026, Human uncovered Trapdoor, another Android operation involving 455 malicious applications and more than 24 million downloads. Many of the first-stage apps presented themselves as ordinary utilities, including PDF readers and device-cleaning tools. Secondary applications used automated touch fraud and hidden WebViews to request advertising. At its peak, Human attributed 659 million bid requests a day to the operation.

Then there is Pareto, which offers perhaps the most memorable warning against taking apparently mundane utility apps at face value. Human found almost one million infected Android phones pretending to be consumers watching advertising on connected televisions. The operation generated an average of 650 million bid requests per day while spoofing more than 6,000 CTV apps. One of the Android applications involved was a flashlight utility that advertised itself as ad-free. Human's analysis found that, while the app did not visibly display adverts to its users, code within it was generating fraudulent advertising activity.

The humble utility app has therefore appeared repeatedly in documented ad-fraud investigations. That doesn’t mean utility apps are inherently suspicious, nor does it mean Android itself is the problem. It means that an application with a simple reason to remain installed on millions of phones can provide attractive infrastructure to somebody seeking scale.

Google explicitly prohibits the behaviour

None of this exists because the major platforms consider it acceptable.

Google Play's current ad-fraud policy is strikingly explicit. It prohibits apps from rendering advertisements invisible to users, automatically generating clicks without user intention, generating equivalent network traffic to claim click credit, producing false installation attribution and displaying adverts when the user is not actively within the app. Google defines this behaviour as ad fraud, because it tricks an advertising network into believing activity arose from authentic user interest when it did not.

Google Play Protect has even adopted a specific warning for detected click-fraud applications: the app "tries to use your device to commit advertising fraud".

The policy language matters because it gets to the heart of this investigation. The offence is not simply that software did something automatically; the problem is the false representation of user interest.

Digital advertising depends on that assumption. An impression is meant to indicate an opportunity for someone to see something. A click is supposed to reflect some level of interaction. A lead form indicates that someone has raised their hand and asked the business to continue the conversation.

Once those signals are divorced from human intention, the measurement system starts reporting a fiction.

Why AI can make a fraudulent lead look even more attractive

This is where the commercial risk becomes more serious.

Modern advertising systems are designed to optimise. If an advertiser tells the platform that a completed lead form is the campaign's success event, the platform will search for environments that can produce more completed forms at a lower cost.

It does not inherently know whether one lead came from a genuine consumer seeking insurance, while another was generated in an abusive app environment. Unless higher quality downstream information is returned, both may appear as the same positive training signal.

In our case, that helps explain why the original numbers we found were so dangerous. A placement producing a 15% or 25% lead conversion rate at an unusually low cost does not merely make a dashboard look good; it can encourage the optimisation system to allocate more money towards the source.

Fraud can therefore create its own feedback loop.

The fraudulent environment manufactures the conversion. The optimisation engine interprets the conversion as a success. More budget flows towards the environment that created it. As performance improves, the human marketer is less likely to question it.

This is Goodhart's Law in operational form. Once the proxy becomes the target, participants discover ways to produce it.

The marketer thinks they are buying demand. The system may simply be buying the appearance of demand.

We found the fraud because the data did not agree with itself

There was no single dashboard alert that solved our investigation. What exposed the problem was disagreement between different parts of the customer journey.

The media data said the campaign was performing exceptionally well. The cost per lead said the placements were efficient. The form data said people had applied. However, the call-centre conversations said something completely different.

That contradiction was not an inconvenience. It was evidence.

This is why I increasingly believe that fraud detection and marketing measurement are becoming inseparable disciplines. You need to know where the lead originated, when it originated, on which device and placement, what happened after it reached the CRM, whether the customer could be contacted, whether the information was accurate, whether the person was genuinely interested, and, eventually, whether commercial value materialised.

Offernet's own measurement approach explicitly distinguishes between diagnostic activity and qualified demand, revenue, profit and lifetime value. It also treats spend anomalies, lead-routing failures and source-quality problems as operational signals that require investigation rather than numbers to be filed away in a monthly report.

In this case, that philosophy proved decisive. Had we stopped at the frontend conversion, we might have celebrated. But because we kept measuring, we became suspicious. Because we became suspicious, we started listening to what customers were telling us. And because the customer data didn't match the platform data, we kept digging until we could see the pattern underneath.

There is a broader lesson here for every performance marketer. Do not assume that an unusually low CPA is evidence of brilliance. Do not assume that a valid telephone number proves a valid enquiry. Do not assume that a conversion event proves human intent. Most importantly, do not let the system that sells you the advertising be the only one that tells you whether the advertising worked.

The industry has spent years improving its ability to automate advertising. The next challenge is making our independent measurement sophisticated enough to audit what that automation is actually producing.

In our investigation, the marketing system indicated that a consumer had seen enough value in a pet insurance offer to provide their details and request to be contacted.

The consumer told us they had not done this. By the time the lead arrived, some of them were probably asleep.

That difference between what the machine recorded and what the human actually intended may prove to be one of the most important fraud problems modern marketers must learn to measure.

26 Aug 2026 13:19

<<Back

About JG Bezuidenhout

JG Bezuidenhout is a founding partner of the South African subsidiary of Offernet.net, the data technology company housed in London, United Kingdom. Although based in Cape Town, JG is the global head of Offernet's advisory and innovation hub and, as such, is responsible for the monitoring and implementation of cutting-edge solutions, particularly within the digital marketing environment.