Skip to content
Back to Journal
Click Fraud Protection

Click Fraud Statistics 2026: Ad Fraud and Bot Traffic Data

16 min readBryan, Technical Analyst
Click Fraud Statistics 2026: Ad Fraud and Bot Traffic Data

This page collects the click fraud, ad fraud and bot traffic statistics that hold up to checking. Every figure below names its publisher and the year the data covers, and links to the original or to reputable coverage of it. We opened each source before listing it. Figures that only appear on click-fraud vendors' own blogs are left out, because they come from those vendors' customer data and are hard to verify independently.

Read the numbers by their unit. Most public studies measure impressions in open programmatic inventory or requests across the web, not clicks on Google Search or Meta ads. That difference matters, and the last section explains how to turn context into an account-level benchmark.

Key statistics at a glance

The five figures in the summary above are the ones most worth quoting, because each comes from a large dataset with a stated scope.

StatisticSource (publisher)YearLink
Invalid traffic: 20% of web, 41% of mobile app and 26% of CTV programmatic impressions globally (80+ billion impressions analyzed)PixalateQ2 2026Pixalate Q2 2026 EMEA release (includes global rates)
Bots made up 53% of web traffic; malicious bots made up 40%Thales (Imperva) Bad Bot Report2025 data, published 2026Thales press release
$84.2 billion lost to ad fraud (22% of $382 billion in digital ad spend); forecast $172.3 billion by 2028Juniper Research2023MediaPost coverage
8.3 billion ads blocked or removed; 24.9 million advertiser accounts suspendedGoogle Ads Safety Report2025Google report (PDF)
Traffic from AI agents and agentic browsers grew 7,851% year over yearHUMAN2025 data, published 2026HUMAN report (PDF)

Market size and the cost of ad fraud

The most cited global estimate is Juniper Research's: $84.2 billion lost to ad fraud in 2023, about 22% of global digital ad spend, rising to a forecast $172.3 billion by 2028. Industry anti-fraud standards also have a measurable effect: TAG estimated they saved US advertisers $10.8 billion in 2023.

StatisticSource (publisher)YearLink
$84.2 billion of $382 billion global digital ad spend lost to fraud (22%)Juniper Research2023MediaPost coverage
30% of mobile advertising spend lost to fraudJuniper Research2023MediaPost coverage
Ad fraud forecast to reach $172.3 billion of $747 billion projected spendJuniper ResearchForecast for 2028 (published 2023)MediaPost coverage
Anti-fraud standards saved an estimated $10.8 billion in US display and video, a 92% reduction versus modeled losses without themTAG with the 4A's, ANA and IAB2023 data, published 2024TAG press release

Two caveats apply. MediaPost reported that Juniper's 2023 study was produced in collaboration with an anti-fraud vendor and that no detailed methodology was published, so the dollar totals are directional. TAG's $10.8 billion is a modeled estimate of avoided losses, not a directly observed sum. We did not find a newer Juniper estimate published since 2023.

For what these totals mean for a single account, see How Much Does Click Fraud Cost?.

Invalid traffic rates by channel

Invalid traffic (IVT) rates differ sharply by channel. Mobile app inventory is the worst measured channel, at 41% of open programmatic impressions in Q2 2026, against 26% for CTV and 20% for web. Channels certified by TAG hold IVT under 1%.

StatisticSource (publisher)YearLink
Web (desktop and mobile web) IVT: 20% of programmatic impressions globallyPixalateQ2 2026Pixalate Q2 2026 EMEA release (includes global rates)
Mobile app IVT: 41% globallyPixalateQ2 2026Pixalate Q2 2026 EMEA release (includes global rates)
CTV IVT: 26% globallyPixalateQ2 2026Pixalate Q2 2026 EMEA release (includes global rates)
One year earlier: web 19%, mobile app 29%, CTV 18% (120+ billion impressions)PixalateQ2 2025Q2 2025 benchmarks
Country highs: mobile app IVT 37% in Germany and 36% in the UK; CTV IVT 34% in the UKPixalateQ2 2026Q2 2026 EMEA benchmarks
IVT in TAG Certified Channels: 0.82% (first half of 2023), versus 1.19% in non-certified channelsTAG (study by The 614 Group)2023TAG press release
IVT in US TAG Certified Channels held below 1% for the fourth consecutive year (January to June 2024)TAG2024TAG press release

Pixalate states that its data comes mainly from buy-side open auction programmatic traffic, so these rates describe open-exchange display, app and CTV inventory. They do not describe Google Search clicks.

Search and social: neither Google nor Meta publishes an aggregate invalid click rate, and we found no independent, methodology-backed public benchmark for paid search or paid social clicks. Google says it "catches most invalid traffic shortly after the ad interaction" and that "you aren't charged for invalid traffic detected before billing" (Google Ads Help). The per-platform click rates that circulate online come from click-fraud vendors' own customer data, which this page excludes. For risk by Google Ads campaign type, see Invalid Traffic Risk by Google Ads Campaign Type.

Bot traffic share of the internet

Bots now generate slightly more web traffic than humans. Thales (Imperva) measured automated traffic at 53% of web traffic in 2025, and Cloudflare measured humans at 47% of HTML requests on its network as of December 2025.

StatisticSource (publisher)YearLink
Bots: 53% of web traffic; humans: 47%; malicious bots: 40% of all web trafficThales (Imperva) 2026 Bad Bot Report2025 dataThales press release
Prior year: bots 51%, humans 49%Thales (Imperva)2024 dataSecurityBrief coverage
Humans generated 47% of HTML requests and non-AI bots 44% (as of December 2)Cloudflare Radar Year in Review2025Cloudflare blog
Automated traffic grew 8x faster than human traffic, year over year (1 quadrillion+ interactions analyzed)HUMAN2025 dataHUMAN report (PDF)
Only 2.4% of 21,491 popular domains were fully protected against all 10 test bots (down from 2.8% in 2025); 65.3% let every test bot through (vendor test, not audited)DataDome State of Bot & Agent Security Report2026 (June 2026 test)PPC Land coverage

These datasets come from each company's own network or customer base. HUMAN states that its report "does not represent the totality of internet traffic", and the same limit applies to the others. Their direction agrees: automation is growing faster than human use. For how this shows up in paid campaigns, see Google Ads Bot Traffic: Detect and Block Fake Clicks.

Click farms and device fraud operations

Click farms and infected-device networks are hard to count, so the reliable figures come from law-enforcement takedowns and published threat research. Two 2025 cases show the scale: a SIM-farm service in Europe linked to around 50 million fake online accounts, and an Android botnet of over 1 million devices used for ad fraud and click fraud.

StatisticSource (publisher)YearLink
Operation SIMCARTEL: 1,200 SIM-box devices holding 40,000 SIM cards seized; phone numbers from 80+ countries used to create around 50 million online accountsLatvian State Police (Europol-supported operation)2025State Police release
BADBOX 2.0: more than 1 million infected Android devices (mainly low-cost TV boxes) used for programmatic ad fraud, click fraud and residential proxies; over 500,000 cut off from command serversHUMAN Satori team with Google, Trend Micro and Shadowserver2025CSO Online coverage
Meta estimated that less than 5% of its worldwide daily active people consisted solely of violating accounts (fake and violating accounts, not click farms)Meta Platforms Form 10-KQ4 2025SEC filing

We did not find a recent peer-reviewed study that measures click-farm activity in paid search. For how click farms work and how to spot them, read What Is a Click Farm? and Bot Farms and Google Ads Click Fraud.

Google and Meta platform figures

Google and Meta publish enforcement totals, not invalid click rates. In 2025 Google blocked or removed 8.3 billion ads and suspended 24.9 million advertiser accounts. Meta removed over 159 million scam ads.

StatisticSource (publisher)YearLink
8.3 billion+ ads blocked or removed; over 99% stopped before they servedGoogle Ads Safety Report2025Google report (PDF)
24.9 million+ advertiser accounts suspended; 4.8 billion+ ads restrictedGoogle Ads Safety Report2025Google report (PDF)
1.29 billion+ ads actioned for "Abusing the Ad Network", the largest single policy categoryGoogle Ads Safety Report2025Google report (PDF)
602 million+ ads removed and 4 million+ accounts suspended for scam-related activityGoogle Ads Safety Report2025Google report (PDF)
245,000+ publisher sites actioned; 480 million+ web pages blocked or restrictedGoogle Ads Safety Report2025Google report (PDF)
Incorrect advertiser suspensions reduced by 80%Google2025Google Keyword blog
Prior year: 39.2 million+ advertiser accounts suspended; 5.1 billion+ ads removed; 9.1 billion+ restrictedGoogle Ads Safety Report2024PPC Land coverage
159 million+ scam ads removed, 92% before anyone reported themMeta Integrity Reports2025Meta Transparency Center
Meta internally projected about 10% of 2024 revenue (about $16 billion) would come from scam and banned-goods ads; an internal document estimated 15 billion "higher risk" scam ads shown dailyReuters, reporting on internal Meta documents2025 (covers 2024)Reuters report (syndicated)

Meta disputed the Reuters report: a spokesman said the documents "present a selective view" and called the internal 10.1% estimate "rough and overly-inclusive". The Google figures cover policy enforcement against bad advertisers and publishers. They are not invalid click counts. Invalid clicks are filtered separately and appear in your own account's Invalid clicks column (Google Ads Help). For Meta specifics, see Meta Ads Click Fraud and Meta Ads refunds for invalid clicks.

Industry and vertical figures

Credible public data on invalid-click rates by advertiser industry does not exist. What does exist is industry data on bot attacks, AI traffic and app categories. Financial services absorbed 24% of bot attacks in 2025, and three industries took more than 95% of AI-driven traffic.

StatisticSource (publisher)YearLink
Financial services: 24% of all bot attacks and 46% of account takeover incidentsThales (Imperva) 2026 Bad Bot Report2025 dataSecurityBrief coverage
More than 95% of AI-driven traffic went to retail and e-commerce, streaming and media, and travel and hospitalityHUMAN2025 dataHUMAN report (PDF)
Mobile app categories: Hobbies and Interests had the highest IVT among the top 10 (29%); Video Gaming 21% globally; Music and Audio highest in North America (23%)PixalateQ3 2024Pixalate category report

The app-category figures describe where ads ran (the publisher's app), not the advertiser's industry. For advertisers, the practical rule still holds: high-CPC lead-generation verticals such as legal, finance, insurance and home services lose more per bad click, so they justify closer monitoring. That is a cost argument, not a measured fraud rate.

Affiliate and mobile app fraud

Mobile app inventory carries the highest measured invalid traffic of any channel, and app install fraud is concentrated in a few traffic sources. AppsFlyer found that the fraud gap between affiliate traffic and self-reporting networks reached 36x.

StatisticSource (publisher)YearLink
Mobile app programmatic IVT: 41% globally, up from 29% a year earlierPixalateQ2 2026 vs Q2 2025Pixalate Q2 2026 EMEA release (includes global rates)
30% of mobile ad spend lost to fraudJuniper Research2023MediaPost coverage
Fraud gap between affiliate traffic and self-reporting networks (SRNs) reached 36x; organic installs account for 52% of all fraudulent installs; fraud rates held largely flat in 2025 (100 billion+ installs, 246,000+ apps)AppsFlyer, State of Fraud for Marketers2026 edition (2025 data)AppsFlyer report

We did not find a methodology-backed public figure for total affiliate fraud losses. The affiliate totals that circulate come from vendors without published methods. For the mechanics, see Click Fraud in Affiliate Marketing and Mobile App Install Fraud.

AI agents and agentic traffic

AI-driven traffic is the fastest-growing category online. HUMAN measured agentic traffic growth of 7,851% in 2025, and Cloudflare found AI bots made up 4.2% of HTML requests on its network.

StatisticSource (publisher)YearLink
Traffic from AI agents and agentic browsers grew 7,851% year over yearHUMAN2025 dataHUMAN report (PDF)
Monthly AI-driven traffic grew 187% from January to DecemberHUMAN2025HUMAN report (PDF)
77% of agentic AI activity was on product and search pages; 2.3% on checkout pagesHUMAN2025HUMAN report (PDF)
AI bots (excluding Googlebot) averaged 4.2% of HTML requests; Googlebot 4.5%Cloudflare Radar Year in Review2025Cloudflare blog
AI "user action" crawling increased by over 15xCloudflare Radar Year in Review2025Cloudflare blog
AI agent and crawler traffic rose from 1.2% to 1.7% of all requests between July 2025 and June 2026, up 82.3%DataDome State of Bot & Agent Security Report2026PPC Land coverage
AI-driven bot attacks rose 12.5xThales (Imperva) 2026 Bad Bot Report2025 dataSecurityBrief coverage

Agentic traffic matters for advertisers because agents browse product and search pages the way shoppers do. Most of it is not malicious, but an agent that clicks an ad on someone's behalf is not a buyer you can retarget or close. See AI Agent Clicks and Invalid Traffic in Google Ads and AI Agents and Ad Fraud.

How to use these numbers against your own account

Public statistics show the problem is real. They cannot tell you what share of your own budget is wasted. Pixalate's 41% mobile app rate is a measure of impressions in open exchanges, and it does not mean 41% of your Search clicks are fake.

Before quoting any figure, check four things:

  • Unit: impressions, clicks, requests, installs or leads.
  • Scope: open programmatic, a vendor's customer base, or a platform's whole network.
  • Filtering: measured before or after the platform filtered invalid activity.
  • Method: whether the publisher explains how the number was produced.

Then build your own baseline over 30 days, or 90 days if volume is low:

Account metricFormulaWhat it tells you
Invalid click rateInvalid clicks / total clicks (Google Ads Invalid clicks column)What Google already classified as invalid
Rejected lead rateRejected paid leads / paid leadsHow much paid conversion volume fails sales review
Qualified CPA gapQualified CPA minus reported CPAHow far platform CPA is from business reality
Placement waste rateSpend on placements with no qualified outcome / placement spendHow much broad inventory produces nothing
Repeat suspicious source rateSuspicious repeat sources / total paid sourcesWhether blocking specific sources is justified

If an account reports 100 leads on $10,000 and sales accepts 50, reported CPA is $100 but qualified CPA is $200. That gap is not all fraud, but it is the pool to investigate first. For the investigation steps, see How Invalid Traffic Damages Lead Quality in PPC and How to Reduce Click Fraud Without Hurting Conversions.

How we chose these sources

We included figures from research firms, industry bodies, platform disclosures, law enforcement and threat-research reports with a stated dataset. Where the original was not reachable, we linked reputable trade coverage and named it as coverage. We excluded figures that appear only on click-fraud vendors' own blogs or customer-data reports. Several publishers listed here (HUMAN, Pixalate, DataDome, Thales, AppsFlyer) also sell security or measurement products. We cite their research, not their tools. Figures are labeled with the year the data covers. We will replace them as newer editions are published.

Related reading:

Protect your Google Ads and Meta budget

ClickFortify scores every paid click in real time, excludes bots, click farms and repeat offenders automatically, and keeps fake conversions out of Smart Bidding and Meta CAPI.

Google Ads: Search, Shopping, Display, YouTube and Performance Max
Meta Ads: Facebook and Instagram, with fraud-filtered CAPI
Automatic exclusions with an evidence trail for every block
Plans from $8/mo billed yearly, with a 7-day free trial

Try it on your own account

See what ClickFortify flags in your first week. No credit card required.

Frequently Asked Questions

How much money is lost to ad fraud each year?

Juniper Research estimated that $84.2 billion, about 22% of global digital ad spend, was lost to ad fraud in 2023 and forecast $172.3 billion by 2028. It is the most widely cited global estimate, but MediaPost noted that no detailed methodology was published, so treat it as directional.

What percentage of ad traffic is invalid?

In open programmatic inventory, Pixalate measured invalid traffic at 20% of web impressions, 41% of mobile app impressions and 26% of CTV impressions globally in Q2 2026. In channels certified by the Trustworthy Accountability Group (TAG), invalid traffic has stayed under 1% in the US for four straight years (2021 to 2024).

What share of internet traffic is bots?

The Thales (Imperva) 2026 Bad Bot Report found that bots made up 53% of web traffic in 2025, and 40% of all web traffic came from malicious bots. Cloudflare measured humans at 47% of HTML requests on its network as of December 2025.

Is there a published invalid click rate for Google Search or Meta ads?

No. Neither Google nor Meta publishes an aggregate invalid click rate, and we found no independent, methodology-backed public benchmark for paid search or paid social clicks. The figures that circulate come from click-fraud vendors' own customer data, which we exclude. Use the Invalid clicks column in your own Google Ads account as your baseline.

How fast is AI agent traffic growing?

HUMAN's 2026 benchmark report found that traffic from AI agents and agentic browsers grew 7,851% year over year in 2025, and that automated traffic overall grew eight times faster than human traffic.

Do these statistics apply to my Google Ads account?

Only as context. Most public figures measure programmatic impressions or overall web requests, not paid search clicks. Your own benchmark should come from invalid clicks, rejected leads and cost per qualified lead in your account.