There are two intentions behind this: The clicks are either intended to deplete a competitor's advertising budget or to generate unlawful income for publishers through networks like Google AdSense.
They are generated (primarily in low-wage countries) manually by paid click farms or automatically by bots and botnets. All PPC systems are affected, in practice particularly by market leaders Google Ads, Microsoft Ads, and Meta Ads.
Google reports some of these clicks as „invalid clicks“ in its reporting. Click fraud is only a deliberate subset of these. Invalid clicks also include accidental double-clicks or harmless crawlers without fraudulent intent.
The overarching term „Ad Fraud“ is broader. In addition to click fraud, it includes impression fraud, domain spoofing, and install fraud. Impression fraud specifically triggers ad impressions without clicks to artificially lower a competitor's CTR and thus their quality score.
For reimbursement and legal questions, this hierarchy is crucial because Google and courts focus on the narrower category in each case.
Who clicks and why
Two economic motives drive click fraud.
In the first scenario, a competitor deliberately clicks on a rival's ads to deplete their daily budget before the actual target audience sees them.
In the second scenario, the clicker is also a publisher within the display network (e.g., Google AdSense) and generates clicks on their own ad spaces to receive higher payouts.
The advertiser whose ad was displayed bears the cost of these clicks in both cases.
On the execution level, there are three typical forms.
- Manual clicks by individuals, such as employees of a competitor, are low-volume and locally limited, but difficult to distinguish from genuine traffic.
- Click farms are organized groups of low-paid workers who click on advertisements in large volumes on behalf of others.
- Botnets are networks of hijacked computers that automatically generate clicks without the knowledge of the actual device owners.
Technically sophisticated attacks today combine real residential IPs from botnets, human-like interaction patterns, and rotating device fingerprints. This combination is intended to bypass Google Ads and Meta's built-in filters. As a result, current click fraud operations differ from the obvious data center bots that the platforms filter out.
For evaluating one's own campaign, this means: The striking patterns often remain beneath the surface, visible anomalies are usually just the tip of the iceberg.
How to detect click fraud in your campaigns
Five signals are considered reliable in practice:
- A click-through rate above the industry average coupled with a plummeting conversion rate is a classic scenario: many clicks, no revenue.
- A very short dwell time just above zero seconds indicates that clickers do not perceive the page at all.
- Recurring clicks from identical IP addresses are a pattern that real users rarely produce.
- A geographic distribution that doesn't match the advertised target region (e.g., frequent clicks from countries outside the actual target audience) is another warning sign.
- Click clusters at unusual times like 3 AM are noticeable in the report's hourly distribution.
In Google Ads, basic diagnostics can be performed without additional tools. The „Invalid clicks“must first be activated in the campaign overview via column selection. It shows how many clicks Google has already filtered out before billing.
However, a low value does not mean „no problem,“ but only „the filter detected little.“.
For the actual diagnosis, it's worth looking at the segments by location, time, device, and network, as well as at the audience and placement reports, provided display or Search Partner network delivery is active. Google Ads does not list IP addresses.
Anyone who wants to identify individual sources needs the server log from their own Website or a third-party tool. Anyone who checks these five dimensions once a week will recognize anomalies early enough to react before the monthly budget is exhausted.
Here's how to deal with click fraud
If you suspect you've been a victim of click fraud, points 1 and 2 are most important: limit your spending and secure your data as long as the refund period is active. The rest can follow afterward.
- Lower the daily budget, instead of pausing the campaign. This limits the damage and allows data to continue accumulating. Anyone who shuts everything down loses real inquiries and the basis of evidence along with it.
- Secure the data, before you change settings. Export the affected period with segments by time, location, device, and network. If display or search partner delivery is running, add the placement report. Google Ads does not show IP addresses; they are in your website's server log.
- Request reimbursement, as soon as you can document a period. The deadline is 60 days from the click, after which the claim is lost. Don't expect any money back: Google corrects this with a credit to the advertising account, and the recognition rate is considered low. The application will only cost you time.
- Turn the free adjustment screws. Disable Search Partners, Geo-Switch targeting from „interest in location“ to „physically in location“, reduce broad match to phrase or exact, and add negative keywords. Block suspicious addresses from the server log under Admin → Account Settings → IP Address Exclusions. Exclusions at the account level also apply to Performance Max campaigns, but not at the campaign level.
- Don't buy a protection tool yet. The changes from step 4 are also a test. If the pattern disappears in two to four weeks, it was due to the setup and not an attack.

The next section will clarify which of the three causes is actually present.
Click fraud or just bad campaign setup?
Many campaigns that look like scams are simply set up incorrectly. Three causes can be distinguished:
- Ad fraud occurs when competitors, bots, or click farms intentionally click.
- Technically inferior traffic arises from accidental clicks or users who have no intention of purchasing from the start, without any attack being behind it.
- A setup problem This occurs when overly broad "Broad Match" keywords, missing negative keywords, activated Search Partners, or overly broad geographic targeting direct the budget to segments that never convert.
In the data columns, the third scenario looks like fraud, but it's a configuration error.
The difference determines the correct reaction. Anyone who buys an external protection tool while the actual problem lies in the Match Type or Search Partners is solving the wrong problem and paying for symptom treatment.
What can help is a pragmatic test: Before investing in additional software, first reduce broad match to phrase or exact, add negative keywords, disable Search Partners, and switch geo-targeting from „interest in location“ to „presence in location.“ If the anomalous pattern persists after two to four weeks, the fraud hypothesis is more robust. If it disappears, it was not click fraud.
What Google filters and what is actually reimbursed
Google works with a two-stage filter. In the first stage, algorithms check every click in real-time for patterns such as conspicuous click rates, suspicious IP constellations, and time and date patterns. Clicks classified as invalid do not appear on the bill at all and are visible in the „Invalid Clicks“ column. The second stage is a downstream, partly manual review that can still detect patterns after billing.
Bernd KleinschrodEdit Profile
For reimbursement expectations, a distinction is important that gets lost in many marketing guides: Google does not reimburse in cash. If invalid clicks are subsequently detected, a correction is made as a credit to the advertising account, which is offset against future costs. The system does not provide for a refund to the bank account.
How to Apply for a Refund with Google Ads
The official way for a backdated claim is the „Click Quality Form“ from Google Ads.
The deadline is 60 days from the time of the click in question; after that, the claim is irrevocably forfeited. There are no reliable public figures on the recognition rate. Individual agency reports cite a rate of less than 5 % of the originally billed clicks, which should be viewed as an isolated figure rather than an industry consensus. The primary line of defense is therefore proactive filtering, not retroactive complaints.
How to protect your campaigns
The cheapest protection is Google Ads' built-in features. Suspicious addresses from the server log can be blocked under Admin → Account Settings → IP Address Exclusions. At the account level, the exclusion applies to all campaign types, including Performance Max.
The path through campaign settings (Settings → More settings) excludes Performance Max, Video, Hotel, App, and Smart Display campaigns. It remains manual in both cases and does not work against rotating IPs or VPN usage. However, it is useful and free against recurring individual sources.
Geo-targeting should be switched from „interest in location“ to „physically in location“ so that clicks from regions that have only incidentally shown interest in the target location are not counted.
Indirect protection is switching from manual CPC to Smart Bidding with a CPA or ROAS target: Bots don't convert, the conversion signal becomes the filter because the algorithm automatically downweights clicks from non-converting sources.
Specialized third-party tools like ClickCease, ClickGUARD, Fraud Blocker, or Lunio (formerly PPCProtect) automate IP exclusions, document incidents for Google claims, and work with fingerprint and behavioral analysis.
As a rule of thumb from agency practice, such an investment is worthwhile from a monthly advertising budget of around 5,000 euros (our experience value, not an independent study). Below that, the costs of the tool usually outweigh the expected savings, and the built-in tools plus a clean campaign setup are sufficient.
The order remains important: first clean up match types, negative keywords, and search partners, then follow up with IP exclusions and geo-targeting, and only then check a third-party tool.
Is click fraud a criminal offense?
From a competition law perspective, the situation in Germany is clear. Click fraud fulfills the elements of targeted obstruction of competitors according to § 4 No. 4 UWG (Act Against Unfair Competition) and establishes a claim for damages under § 826 BGB (German Civil Code) due to immoral intentional harm. Accordingly, civil law claims are available, provided the perpetrator can be identified.
From a criminal law perspective, click fraud can generally be discussed under Section 263a of the German Criminal Code (StGB) (computer fraud) because it is not a person, but rather the billing system of the advertising platform that is influenced, thereby damaging the advertiser's assets. A court ruling that classifies precisely this constellation as computer fraud does not yet exist. The oft-cited ruling of the Regional Court of Frankfurt/Oder dated January 10, 2005 (12 O 294/04) concerns a different constellation: there, a human advertising partner was deceived through a manipulated click process, and the court classified the case under Section 263 StGB (classic fraud), not under Section 263a. For today's typical case, where the automatic billing system of Google or Meta is manipulated exclusively without human intervention, the dogmatic classification therefore remains open.
In practice, this means that civil claims are dogmatically sound but regularly fail due to the identification of the perpetrator, particularly in the case of botnet or click farm attacks from abroad. Criminal charges are possible but, due to a lack of investigative resources and a missing highest court precedent, rarely lead to proceedings with a tangible outcome. Practical and effective defense is therefore technical, not legal.