Skip to content
Back to Journal
Click Fraud Protection

Is Click Fraud Illegal? Lawsuits, Real Cases & Your Options

12 min readBryan, Technical Analyst
Is Click Fraud Illegal? Lawsuits, Real Cases & Your Options

When advertisers discover click fraud draining their budget, the first question is usually practical: how do I stop it? The second question comes right after: is this actually illegal, and can I do something about it legally?

The honest answer requires looking at what courts have actually decided. The record includes a $90 million settlement with Google, a fraud operator sentenced to a decade in federal prison, a jury that acquitted an alleged botnet operator of every felony, and a $2.3 million click fraud verdict that was reduced to zero on appeal.

This guide walks through the real cases and what they mean for your options.

The Short Answer: Illegal Conduct, but No "Click Fraud Law"

No US federal or state statute criminalizes click fraud by name. Prosecutors and plaintiffs reach it through existing laws:

Outside the US, the UK's Fraud Act 2006 (fraud by false representation) and Computer Misuse Act 1990 apply in principle, though we found no verified UK click fraud prosecution to date.

The pattern across all of it: the law can reach click fraud, but only when the evidence is specific and the scale justifies the effort. That distinction runs through every case below.

Criminal Cases: When Click Fraud Led to Prison

Methbot and 3ve: the "King of Fraud" gets 10 years

The largest ad fraud prosecution to date began with a 13-count indictment unsealed in the Eastern District of New York in November 2018, charging eight defendants behind the Methbot and 3ve operations with wire fraud, computer intrusion, aggravated identity theft, and money laundering.

Methbot ran from roughly 2014 to 2016. Its operator, Aleksandr Zhukov, rented around 2,000 datacenter servers that simulated human behavior — mouse movements, scrolling, fake sessions — across more than 6,000 spoofed domains impersonating premium publishers. The scheme billed US advertisers more than $7 million for ads no human ever saw. The related 3ve operation caused losses above $29 million.

Zhukov was arrested in Bulgaria, extradited, and convicted by a jury in 2021 of wire fraud and money laundering charges. He was sentenced to 10 years in prison and ordered to pay $3,827,493.

What it proves: large-scale ad fraud is prosecutable as ordinary wire fraud. What it also proves: the takedown required an FBI-led coalition of ad-tech companies, and five of the eight defendants were never in US custody. This is what enforcement looks like at its absolute peak — and it has not been repeated since.

United States v. Gasperini: the caution for prosecutors

In 2017, Italian national Fabio Gasperini became the first click fraud defendant to face a US jury. Prosecutors alleged he ran a botnet of more than 150,000 compromised devices for an auto-clicking scheme, charging him with felony computer intrusion, wire fraud, and money laundering — up to 70 years of exposure.

The jury acquitted him of every felony. He was convicted only of misdemeanor computer intrusion and sentenced to the one-year statutory maximum plus a $100,000 fine, an outcome affirmed on appeal.

This case is frequently miscited as a felony click fraud conviction. It was the opposite: a demonstration that proving click fraud beyond a reasonable doubt to a jury is genuinely hard, even with a botnet in evidence.

The click farm gray zone

In 2017, Thai police raided an operation near the Cambodian border and found three operators, roughly 500 phones on racks, and over 340,000 SIM cards being used to inflate engagement metrics. The notable legal detail: the operators were charged with working without permits and customs violations — not fraud. In many jurisdictions, manually clicking things for pay is not clearly a crime at all.

That gray zone matters for advertisers, because a meaningful share of paid-click abuse comes from exactly this kind of operation, sitting outside any realistic enforcement reach.

Civil Lawsuits: What Happens When Advertisers Sue

The civil record is where expectations need the most adjustment. Here are the cases that define it:

Lane's Gifts v. Google: the $90 million template

The landmark. In 2005, advertisers filed a class action in Arkansas alleging Google billed them for invalid and fraudulent clicks. Google settled in 2006 for $90 million — but roughly a third went to attorneys' fees, and the rest was paid as advertising credits, not cash, working out to about $4.50 per $1,000 spent. Google admitted no liability, and an independent report it commissioned concluded its invalid-click detection was "reasonable."

Twenty years later, this is still the template: platform recourse means credits, not damages. A related chapter closed in 2025, when a long-running class action over Google's click billing practices — alleging improper Smart Pricing discounts and charges for clicks outside geo-targets — received final approval of a $100 million settlement. That case concerned how Google billed for clicks rather than third-party fraud, but the shape of the outcome was the same: a long fight, a fund, no admission.

Motogolf v. Top Shelf Golf: the door that closed

If you remember one civil case, make it this one. Motogolf, an online golf retailer, sued a competitor in 2020 alleging a coordinated campaign of clicking its Google ads to exhaust its budget and knock its ads off the page. It brought federal computer-crime, Lanham Act, racketeering, and tortious interference claims.

The court dismissed the CFAA claim with reasoning that now dominates this area: clicking a publicly accessible ad is not access "without authorization," no matter how malicious the intent. The Lanham Act claim failed too, and judgment was ultimately entered for the defendants.

For advertisers, the lesson is blunt: the most obvious federal statute mostly does not cover competitor click fraud.

WickFire v. TriMax: winning the verdict, losing the money

WickFire, a performance marketing firm, convinced a Texas jury that a competitor had committed click fraud against it and won $2.3 million in damages for tortious interference. The Fifth Circuit then reversed every dollar: no evidence any specific contract was actually breached, and the alternative damages theory was too speculative. Net recovery: zero.

The appeals court did confirm that click-fraud-adjacent conduct can support a Lanham Act claim in the right fact pattern. But the case is the clearest illustration of where these lawsuits die — not on whether fraud happened, but on proving exactly what it cost.

Satmodo v. Whenever Communications: the realistic middle path

Satmodo, a satellite phone retailer, documented a competitor clicking its ads through rotating proxies — around 96 clicks within minutes — and sued in 2017. The court dismissed the federal computer-crime claims but allowed a California unfair competition theory to proceed, observing that click fraud can constitute unfair conduct that "violates the spirit" of competition law. The case was resolved and dismissed with prejudice in 2019, consistent with a settlement whose terms were never made public.

This is the realistic best case for an advertiser with strong evidence: survive on state unfair-competition claims, then settle quietly.

Platforms as plaintiffs

The most active click fraud litigants today are the platforms themselves. Facebook sued app developers LionMobi and JediMobi in 2019 over click injection fraud — apps that generated fake ad clicks from users' phones — in a case that reportedly settled with damages and permanent bans. Uber sued ad network Phunware over billing for fake app installs and settled for $6 million in 2020. And in July 2025, Google filed suit against the operators of BadBox 2.0, a botnet of more than 10 million infected Android devices used for large-scale ad fraud and residential proxy resale.

Platform suits protect the ecosystem, and that helps advertisers indirectly. But none of them put money back in an individual advertiser's account.

Why Click Fraud Cases Are So Rare

Across two decades of cases, four barriers repeat:

That last point deserves emphasis. There has been no major US federal ad fraud enforcement action since the 3ve takedown in 2018 — a gap prominent enough that in March 2025, Senator Mark Warner publicly pressed the FTC and DOJ to address "rampant fraud in digital advertising." For everyday advertisers, no cavalry is coming.

What You Can Realistically Do

The legal record points to a clear hierarchy of options:

Two practical notes on the Google route. First, approved invalid-click claims are paid as ad credits, never cash — that has been true since Lane's Gifts. Second, the review window is short, generally 60 days, so evidence collection cannot wait until you are certain. Our guide to recovering invalid click credits covers the process step by step.

If you suspect a competitor specifically, build the evidence file before doing anything else:

We cover the attribution problem in detail in how to prove competitor click fraud — including why patterns matter more than motives.

Prevention Beats Litigation

Here is the uncomfortable math the cases teach. Lane's Gifts took a year to settle and paid out in credits. WickFire litigated for seven years and recovered nothing. Motogolf lost outright. Meanwhile, every one of those advertisers kept paying for invalid clicks while their cases moved.

The legal system treats click fraud as it treats most commercial harms: slowly, expensively, and only with proof. Real-time click fraud protection inverts that equation — it blocks the suspicious source in the moment, and it generates exactly the click-level evidence file (IPs, timestamps, patterns, session behavior) that both Google's review team and any future legal action would require.

In other words, protection is not the alternative to your legal options. It is what makes them usable.

If you are currently watching suspicious clicks drain a campaign, start with our guide to how click fraud works, document what you are seeing, and file for invalid activity credits inside the 60-day window while the evidence is fresh.

Start Protecting Your Enterprise Campaigns Today

ClickFortify provides enterprise organizations with the sophisticated, scalable click fraud protection they need to safeguard multi-million dollar advertising investments.

Unlimited campaign and account protection
Advanced AI-powered fraud detection
Multi-account management dashboard
Custom analytics and reporting

Enterprise Consultation

Speak with our solutions team to discuss your specific requirements.

Frequently Asked Questions

Is click fraud illegal in the United States?

There is no statute that criminalizes click fraud by name. Large-scale operators have been prosecuted under existing laws such as wire fraud and computer intrusion statutes, and the Methbot operator received a 10-year sentence. Small-scale click fraud, such as a competitor clicking your ads, is much harder to reach legally.

Can I sue a competitor for clicking on my ads?

You can, but the track record is discouraging. Federal computer-crime claims have repeatedly failed because clicking a publicly visible ad is not unauthorized access, and even a jury verdict for click fraud was reversed on appeal for lack of provable damages. State unfair-competition claims have survived early motions, but most cases end in quiet settlements.

Has anyone gone to prison for click fraud?

Yes. Aleksandr Zhukov, operator of the Methbot ad fraud scheme, was convicted of wire fraud and money laundering in 2021, sentenced to 10 years in prison, and ordered to pay $3,827,493. Prosecutions at this scale are rare and required an FBI-led industry coalition.

Can I get money back from Google for invalid clicks?

Google filters invalid clicks automatically and lets advertisers request a manual review of suspicious activity, generally within 60 days of the traffic. Approved claims are paid as account credits, not cash refunds. Detailed evidence such as click timestamps, IPs, and campaign data improves the outcome.

What evidence do I need to prove click fraud?

Courts and platform review teams both want specifics: dates and timestamps, campaigns and keywords affected, click IDs, IP addresses and network patterns, session behavior, and quantified financial impact. Vague suspicion of a competitor is not enough — the cases that fail usually fail on attribution and damages.