Blocking: Ad-fraud Prevention or Cure?

Traffic verification has become an exercise in fear-mongering. We’ve reached a stage where everyone from publishers to verification vendors and agencies are bragging about their blocking rates, as if to say that blocking is the only or best way to stop ad fraud. Ad fraud is the industry’s worst kept secret with $35 billion lost to fraudulent activities committed via online, mobile and in-app advertising in 2018 according to Juniper Research – and losses expected to jump to $42 billion in 2019. Everyone knows the risks of ad fraud, but as CPMs plummet in the name of blocking and the relationship between advertisers and publishers are at an all time low, we have to ask ourselves: is the cost of blocking worth less than the fraud? Blocking might be one way to handle fraudulent traffic but it seems to have much further reaching negative ramifications. There has to be a better way to combat ad fraud without harming publishers, and inadvertently, the open internet itself. It’s time to move away from unilateral actions like blocking, and start communicating with publishers. A media buyer has a number of options available to help them to eliminate fraud in their traffic. and the first is shutting down traffic sources entirely. It’s a high risk move and will influence access to audiences in the future. This is a tactic which should only be employed when you’re sure that a traffic stream is entirely or mostly fraud, or if you’re looking at a high volume of cheap traffic where it might not pay to carve out the legitimate traffic. In the worst case scenario where probabilistic detection flags up false positives, eliminating a traffic source means missing valuable opportunities. Blocking is de rigueur – it’s trendy because blocking (by IP, device ID, browser etc) purportedly eliminates IVT while still serving ads to legitimate audiences, with a lower risk than shutting down a traffic source. Considering the lack of consequences for verification vendors who over-block, it’s fair to assume that verification partners err on the side of caution and take the approach of “if in doubt, block it out”. This is problematic because you risk losing legitimate users in a blocking exercise with a blocking happy vendor. You’ll also inevitably throw out non malicious IVT (scraper or indexing bots) and your publishers won’t understand why you’re refusing to pay for impressions which they have measured as clean. If media buyers don’t help publishers to understand why their traffic is being blocked then they cannot clean it up and eventually publisher CPMs will decline. This is a terrible consequence of over-blocking for media buyers who then lose out on audiences across the board. Shutting down traffic sources and blocking IVT are all important components of a robust anti-fraud strategy but they cannot provide long term protection from fraud. Instead of harming reputable publishers by taking harsh unilateral steps, there are many opportunities for media buyers to investigate, analyze and research traffic. Conversations about traffic quality are critical and in fairness it’s the supply side who are closest to the traffic and are well equipped to have an open conversation about the validity of their audiences. Media buyers have look at all of the variables in every scenario and choose the right tool from their anti-fraud arsenal. It’s important to keep in mind that if a marketer’s goal is to meet KPIs and they’re not buying traffic directly, it’s critical to use the right analysis tools so as not to take broad, unilateral steps which will harm them and exclude valuable audiences in the future. Read the full piece on MarTech Advisor
Hidden Danger To D2C Marketing: Fake ‘Lookalikes’

We’re currently in the middle of a retail revolution, with the rise of online direct-to-consumer (D2C) brands showing it’s possible to build a multi-billion dollar company without the aid of stores. D2C has also created a new marketing model that, by cutting out the ad agency, avoids some of the more dubious practices of the online advertising industry. However, the problem of fraud hasn’t gone away for the D2C brands, with many companies facing increasingly sophisticated attacks that threaten the very roots that D2C is built upon. D2C brands have changed retail from being a best-guess numbers game to a precisely targeted process where marketing is personalized at an individual level and social media is increasingly where outreach to customers takes place. D2C seems to offer a way forward that not only enables brands to communicate directly with both existing customers and their target audience, but also hugely reduces their potential exposure to ad fraud schemes and the criminal networks that run them. However, much like the agency model, where fake traffic and false impressions are reported as true because the client is pushing the agency to secure eyeballs at whatever cost, D2C brands can fall victim to scams that appear to give them exactly what they want. The results of these attacks are potentially disastrous because they also strike at the very heart of the D2C model: data quality. It’s exactly because D2C brands have specific KPIs that define their ideal customer that makes them vulnerable to fraud. A key part of their methodology is spotting “lookalikes” to existing customers on social media and serving creative to them based on shared metrics in terms of interests, career, age etc. The problem with this is that fraudsters also know what these KPIs are, and are able to create fake lookalikes that display the exact attributes the brands are searching for, but don’t actually exist. These “ghost profiles” are designed to generate fake traffic, despite happening within the supposedly safer environment of a walled garden social media platform. More than just losing potential sales or revenue, such scams chip away at the foundations of D2C’s raison d’être by skewing the data that they base their campaigns upon. They might think they’ve had numerous positive interactions with consumers, and therefore their campaign is successful, when in fact many of these responses are false. The more that this happens, the more it invalidates the entire D2C model, with their precision-based outreach ultimately built on lies. And the problem of dedicated attacks in the D2C space is growing simply because the brands often don’t realize they’re being targeted in this way. D2C is vulnerable because it’s still relying on old-school measurement tools left over from the agency model that are unable to spot attacks such as fake lookalikes. To stop D2C from becoming yet another online space polluted by fraud, brands need to become as innovative and forward-thinking in their verification methodologies as they have been in their customer relationship management. Read the full piece on MediaPost
Protected Media Exposes Giant Ad Fraud Scheme For BuzzFeed News- Hidden Video Ads Drained Users’ Batteries & Data

A scheme to stealthily run video ads behind banner images drained users’ batteries and data while they used popular Android apps Protected Media identifies harmful fraud scheme responsible for tens of millions of dollars in wasted ad spend “…Fraudsters are purchasing cheap in-app display inventory and are filling it with multiple video players behind innocuous fake branded display ads,” said Asaf Greiner, the CEO of Protected Media. This type of ad fraud is known in the industry as in-banner video ads, and has been documented in the past. Greiner’s team identified a new version of it last fall and said in total they’ve seen tens of millions of dollars’ worth of fraudulent video ads running per month as a result…” Read the full piece on Buzzfeed
Will Self-Regulation Be Enough To Keep Ad Fraud Legislation At Bay?

Is 2019 destined to be the year in which the menace of ad fraud finally makes the front pages of mainstream media around the world? With the vast sums of stolen money involved — Juniper Research reported $19 billion in 2018, while others believe this is a conservative estimate — it’s perhaps surprising that it isn’t already a bigger story. But now, a serious momentum is beginning to grow around the issue, with both law enforcement agencies and political figures becoming increasingly engaged with it.For instance, the FBI is currently involved in a number of investigations into media buying practices and were partly responsible for cracking the so-called “3ev” ad fraud scheme last November. And Senator Mark Warner, the vice chair of the U.S. Senate Intelligence Committee, has been pressing the Federal Trade Commission to do more to tackle the problem, most recently in response to the exposure of another major fraud ring making hundreds of millions of dollars. This might set alarm bells ringing for fraudsters who, for the most part, have been allowed to act with impunity up until now. However, it should also be a wake-up call for an online advertising industry that turned a blind eye to a plethora of dubious practices and created an ecosystem in which bad actors have been able to thrive. As the industry comes under greater scrutiny and increased pressure to crack down on fraud, this apparent complicity over the past 10 years or so will not go unnoticed. The question is, what can the industry do to make amends ahead of the ad fraud can of worms spilling open? Will self-regulation be enough to stave off legislation, or will the industry find itself subject to the type of stringent laws that the financial sector must now comply with? Perhaps the main reason that ad fraud hasn’t already hit the broadsheet headlines is because, as far as the public is concerned, it’s a victimless crime. So, what if X% of Coca Cola’s advertising budget is being siphoned off by click bots and fake publishers — isn’t it just their bad luck if a multi-billion dollar corporation hasn’t been careful enough with its money (assuming, of course, it even realizes it’s been defrauded)? Of course, ad fraud is far from a victimless crime. Just as the reckless practices of the financial industry threatened the world’s economy following the 2008 crash, so it is that ad fraud is helping to fund new existential threats in the form of terrorism and election-rigging. The money made by black operatives online has the potential to impact all of our lives, not just the bottom line of those companies being stolen from. It’s a truth that not only legislators are starting to wake up to — certain parts of the advertising industry have also begun to acknowledge the scale of the problem and how far it reaches. For example, the Joint Industry Committee for Web Standards (JICWEBS) aims to provide the industry with a means to demonstrate self-regulation. As it says itself, “If we don’t do this, the government may look to impose legislation.” This isn’t just scaremongering; a recent publication from the U.K.’s House of Lords, Select Committee on Communications, states, “It is in the interests of the whole industry to take greater steps to self-regulate through independent third parties such as JICWEBS … If businesses fail to do so, the Government should propose legislation to regulate digital advertising.” It is only when a problem has become too big to ignore (i.e., when it potentially has wide-ranging consequences for a significant proportion of the population) that legislation is introduced. It is an act of last resort when an industry has failed to properly police itself and protect its customers. Nobody wants legislation to be brought in — often, not even the legislators — because for both sides, it is time, resource and cost-intensive. And in the digital age, it also tends to be ineffective, with online criminals quickly finding ways around it or already ahead of its reach. So, what can the industry do to prevent legislation being imposed on it that nobody actually wants? Self-regulation through the likes of JICWEBS is certainly an important step forward, but the industry not only needs to be seen to take the problem seriously, but it also has to do something about it. Just as organizations that handle large quantities of other people’s money, such as banks and insurance companies, are required to have chief security officers sitting on the board, so should advertising agencies trusted with budgets of billions of dollars look to make similar appointments, with a chief verification officer in place to oversee the accuracy and legitimacy of the online services they’re providing. Advertising groups also need to open themselves up to third-party oversight, whether it’s allowing professional auditors to look for any financial irregularities in the figures they’re providing to clients or working more closely with dedicated experts in traffic and data verification. And yet, the industry still drags its feet over such measures. For many agencies, the problem is a technical one that they don’t really understand, while for others, they simply don’t want to admit the problem exists for fear of a deluge of clients demanding their wasted budget be returned. The unfortunate truth is that many agencies are content to wait until the legislators force them to change the way they work because at least then they can charge on the cost of new procedures and increased manpower to their long-suffering clients. In this current scenario, legislation, for all its faults, is inevitable. The best the industry can do is continue to push for as much self-regulation as possible and for bodies such as the Interactive Advertising Bureau (IAB) and Media Rating Council (MRC) to seek the ear of legislators and attempt to influence the nature of the regulation to be introduced in the hopes that the industry doesn’t find itself hobbled as a consequence of its own inaction. Read the full piece on Forbes