The term of art, and why the taxonomy decides what can be claimed
"Click fraud" is a lay term. The industry term is invalid traffic, and the controlling taxonomy is the Media Rating Council's, set out in its Invalid Traffic Detection and Filtration Standards Addendum, updated June 2020. It splits invalid traffic in two, and the split does more work in litigation than anything else in the field.
General invalid traffic (GIVT) is defined in the standard as traffic "identified through routine means of filtration executed through application of lists or with other standardized parameter checks." Its enumerated categories are known invalid data-center traffic; bots, spiders and crawlers; activity-based filtration using transaction-level parameters; non-browser or unknown user-agent headers; pre-fetch and pre-rendered traffic; invalid placements such as 0x0 and 1x1 ad sizes; and sessions with no capability to render or display images.
Sophisticated invalid traffic (SIVT) is defined as "more difficult to detect situations that require advanced analytics, multi-point corroboration/coordination, significant human intervention, etc., to analyze and identify." Its categories include automated browsing from dedicated and non-dedicated devices, incentivized human invalid activity, manipulated activity such as forced clicks and clickjacking, falsified measurement events, domain and app misrepresentation, hijacked ad tags, hidden and stacked ads, adware and malware, and cookie stuffing.
The evidentiary consequence is direct. GIVT is list-based and reproducible: an analyst holding server logs can apply known crawler user-agents and data-center address ranges and produce a number another analyst can check. SIVT, by the standard's own definition, cannot be found that way. An expert who claims to have measured sophisticated invalid traffic from an ad account export is claiming to have done something the governing standard says cannot be done by routine means.
What the platform shows the advertiser, and what it withholds
Google defines invalid clicks as "[c]licks on ads that aren't the result of genuine user interest, including intentionally fraudulent traffic and accidental or duplicate clicks," and states that advertisers are not charged for them. Its documented categories of invalid traffic run to six, and the sixth is worth naming: "[i]mpressions meant to artificially lower an advertiser's clickthrough rate." That is Google's own acknowledgment that impression-side attacks are a recognized category, which matters when the claim is competitor conduct rather than bot traffic.
Detection runs in two stages: real-time filtering, then detection of further invalid activity after invoices have issued, in which case "you'll receive credits for what the monitoring systems deem as 'invalid activity.'" The remedy is stated precisely, and it constrains any damages theory built on it: "You won't receive refunds for invalid traffic. Clicks determined to be invalid will result in adjustments or credits, not a refund."
What the advertiser can see is thin. The campaign table can display an "Invalid clicks" column covering roughly the last sixty days, aggregated by campaign, with no per-click detail and no reason codes. Separately, Report Editor offers an Invalid Activity Credit Report for Search and Performance Max campaigns, broken down by campaign and network, with credited clicks, credited interactions, credited amount and adjusted performance metrics. It is the closest thing to an exportable artifact of what the platform gave back, with one caveat that travels with it: Google describes the credit bucket as covering invalid traffic or interactions later found to be on inventory violating AdSense program policies. A credited click is not necessarily a click Google classified as fraudulent.
Microsoft Advertising uses different words, which matters when exports are compared across platforms. It classifies clicks as standard-quality, low-quality or invalid, bills only for standard-quality clicks, credits accounts where invalid clicks are found after billing, and exposes "Low-quality clicks" and "Low-quality click rate" rather than a column labeled invalid clicks.
The record the advertiser actually controls
The landing-page request log is the one dataset the advertiser owns outright, and it is where reproducible work happens. Every request carries a timestamp, source IP address, user agent, referrer, and — for paid traffic — the click identifier the platform appended to the URL: gclid for Google, msclkid for Microsoft, fbclid for Meta. Those identifiers make the log joinable to the platform's own click export, which is what turns two piles of data into one comparison.
On that joined dataset, GIVT-grade analysis is genuinely reproducible: data-center address ranges, known crawler user-agents, sessions incapable of rendering, impossible timing, and clicks whose corresponding landing-page request never arrived at all. Another expert with the same logs and the same lists gets the same answer, which is the property that makes the work survive cross-examination.
The platform-side counterpart is narrow and expires quickly. Google exposes a click_view reporting resource keyed on gclid, and Google's own API support channel has described the restriction in the documentation's words: queries including ClickView "must have a filter limiting the results to one day and can be requested for dates back to 90 days before the time of the request," with no workaround for older data. That is a preservation deadline, not a reporting inconvenience. A dispute that surfaces in month five has no click-level record from Google at all, only aggregate counts. Web server logs rotate, analytics retention defaults are short, and the invalid-clicks column reaches back about sixty days. In my experience the reason a click-fraud claim cannot be run is more often that the data is gone than that the conduct did not occur.
Why neither side can audit the platform's determination
No platform publishes its detection logic. There is a reasoned argument for that, and it has been on the record for twenty years, made by a court-appointed expert rather than by a platform.
In connection with the settlement of the Arkansas click-fraud class action against Google approved on 27 July 2006, Dr. Alexander Tuzhilin of New York University was appointed to evaluate Google's invalid-click detection and to conclude whether its efforts were reasonable. He concluded that they were. The more durable finding is the definitional one: he found there is no conceptual definition of invalid clicks that can be operationalized, because determining validity requires knowing user intent, and separately that an operational definition "cannot be fully disclosed to the general public because of the concerns that unethical users will take advantage of it."
Two consequences follow. No outside expert can reproduce the platform's determination on a specific click or say what the filters caught and missed, and an expert who testifies about why a particular click was charged is claiming access to something that has never been public. The report is from 2006 and describes a system two decades old; its enduring value is the definitional argument, not its description of any current system.
Third-party detection dashboards, and what they are evidence of
Click-fraud detection vendors sell a JavaScript tag placed on the advertiser's landing pages, which scores each visiting session and, where the platform permits, writes offending addresses into the account's exclusion list. Their output is often the first thing counsel is handed, and it needs to be characterized accurately before it is relied on.
What that data actually is: the vendor's own tag observing sessions on the advertiser's own site, plus proprietary cross-customer reputation data. It is not platform-side data and not the platform's determination, and a "fraud" label is the vendor's classification under undisclosed rules, with tunable thresholds and a generally unpublished false-positive rate. The vendor also sells the remedy, which is a commercial interest an opposing expert will name in the first five minutes. The dashboard may be usable as a business record of what the tool reported. It is not an independent finding of fact.
Measurement vendors accredited by the Media Rating Council are a different category. They measure in the ad-serving path rather than on the landing page, make invalid-traffic determinations against the MRC standard, and submit to annual audits covering data collection, IT general controls and invalid-traffic detection. Where their outputs exist they are the more defensible artifact. Accreditation is granted per metric and per environment and is time-limited, so it should be checked against the MRC's current list at the date of the engagement.
What the litigation record actually decided
Two cases are cited constantly and both are overstated.
Lane's Gifts & Collectibles, LLC v. Google, Inc., in the Circuit Court of Miller County, Arkansas, settled. Judge Joe Griffin approved the settlement on 27 July 2006 as fair, reasonable and adequate, over objection from smaller advertisers who said they lacked the resources to establish click-fraud losses. The headline value was $90 million, but the form matters: the class received advertising credits rather than cash, described in contemporaneous reporting as roughly a $4.50 credit per $1,000 spent across the class period. Google did not admit liability, and there is no holding on whether its detection was adequate, on whether click fraud occurred, or on any standard for advertiser recovery.
AdTrader, Inc. v. Google LLC, No. 5:17-cv-07082-BLF (N.D. Cal.), is the modern case and is closer to the point. Advertisers alleged Google failed to provide full refunds or credits for invalid traffic while withholding payment to publishers for that same traffic. It also settled: the court granted final approval of a $7 million class settlement on 1 November 2022, finding it fair, adequate and reasonable. Earlier interlocutory rulings, including a Ninth Circuit decision in 2021, addressed standing, contract interpretation and pleading. There is no judicial finding that Google mishandled invalid traffic.
The criminal cases run the other way — against fraud operators, brought by the government with compulsory process, and concerning publisher-side inventory fraud rather than advertiser-side click-fraud claims. Conflating the two is the most common error in writing about this subject.
What advertiser-side data cannot establish
That a click was fraudulent. It can show a click was anomalous, and anomalous is not fraudulent. Every advertiser-visible signal — a repeated address, short dwell time, no conversion, an odd hour, a data-center network — has innocent explanations: shared corporate network address translation, mobile carrier addressing, VPN and private relay services, accidental taps on mobile creative, comparison shoppers, and people who clicked and immediately saw the offer was not for them.
What the filters missed. The invalid-clicks column is the platform's count of what its own systems rejected. There is no denominator. A low figure is equally consistent with clean traffic and with undetected sophisticated traffic; a high one is equally consistent with an attack and with a noisy but innocent placement.
Who was responsible. An address is not a person. Traffic resolving to a competitor's network establishes that traffic came from that network — not who was at the keyboard, not whether anyone directed it, not whether the machine was compromised, and not whether it was an employee doing competitive research, which is not fraud. Establishing that a named party directed invalid clicks generally requires payment records, communications and third-party logs the advertiser does not hold.
That an industry estimate applies to this account. Aggregate prevalence is not individual causation, and a damages model built on an industry percentage does not survive contact with a competent opponent.
Google's documentation also supplies ready-made alternative explanations for the anomalies advertisers point at most often: accidental double clicks are expressly invalid and unremarkable, and Google states that a click can be removed while its conversion is not, so conversions can exceed clicks. Expect both, and address them first.
Frequently Asked Questions
Can click fraud be proven from the advertiser's own account data?
Rarely on its own. Advertiser-side data can establish that traffic was anomalous, and where landing-page server logs are joined to the platform's click export it can support reproducible general-invalid-traffic analysis: data-center address ranges, known crawler user-agents, sessions that never rendered, clicks with no corresponding page request. What it cannot do is identify who generated a click or reproduce the platform's own validity determination, because no platform publishes its detection logic. The documented criminal cases were made by the government with subpoenas and seized infrastructure, not by reading an ad account export.What is the difference between GIVT and SIVT, and why does it matter in a report?
The Media Rating Council's standard defines general invalid traffic as traffic identified through routine filtration using lists and standardized parameter checks, and sophisticated invalid traffic as situations requiring advanced analytics, multi-point corroboration and significant human intervention. The difference is reproducibility. A second expert with the same logs and the same lists can check a GIVT figure. A SIVT figure cannot be derived from an account export plus a server log, and labeling GIVT-grade work as sophisticated invalid traffic overstates it in a way the governing standard itself contradicts.Does the Invalid Activity Credit Report show what the platform refunded?
It shows what was credited, which is not the same thing. Google states that invalid traffic produces adjustments or credits rather than refunds, so an advertiser that has left the platform may hold a credit it cannot realize. The report gives credited clicks, credited interactions, credited amounts and adjusted performance metrics by campaign and network for Search and Performance Max campaigns. Google also describes the credit bucket as covering invalid traffic or interactions later found to be on inventory violating AdSense program policies, and the report does not distinguish the two.How quickly does click-level data disappear?
Faster than most cases move. Google's per-click reporting resource is keyed on the click identifier and, per Google's own API support channel, must be queried one day at a time for dates within the last ninety days, with no workaround for older data. The advertiser-visible invalid-clicks column covers roughly sixty days. Web server logs rotate on whatever schedule the host set, and analytics retention defaults are short. Preservation has to be raised in the first weeks of a matter, because the most common reason one of these claims cannot be run is that the underlying records no longer exist.What is a click-fraud vendor's dashboard evidence of?
Of what that vendor's tool reported. These products place a script on the advertiser's landing pages, score sessions using undisclosed rules and tunable thresholds, and add proprietary cross-customer reputation data. The output is the vendor's classification, not the platform's determination and not an independent finding of fact, and the vendor sells the remedy the number justifies. It may be admissible as a business record of the tool's output, and it can be a useful starting point for identifying sessions to examine in the server log — which is where reproducible work is done.Has any court ruled that a platform's click-fraud detection was inadequate?
Not on the merits, in the cases usually cited. The Arkansas class action settled in 2006 for $90 million in advertising credits, approved without any liability admission and without any holding on the adequacy of detection; the court-appointed expert in that matter concluded the efforts were reasonable. The later California case about invalid-traffic credits settled for $7 million with final approval on 1 November 2022, again without a merits determination. Both are frequently described in marketing writing as rulings against the platform. Neither is.Can an IP address identify who generated the clicks?
No. An address identifies a network endpoint at a moment in time, and often not even that: corporate networks share one address across hundreds of users, mobile carriers share addresses across thousands, and VPN and private relay services deliberately break the link. Traffic resolving to a competitor's network shows the network, not the person, not whether anyone directed it, and not whether the machine was compromised or the visitor was simply an employee doing competitive research. Establishing direction by a named party generally requires records held by third parties and obtained through process.Published