Connected TV Advertising Is Booming, and So Is the Fraud Hiding Inside It

Somewhere in the last few years, the television in your living room quietly became a computer, and almost nobody threw it a proper welcome party for what that actually meant. Every smart TV, every streaming stick, every game console running Hulu or Tubi in the background is now, technically, an internet connected device sitting on your network, sending and receiving data the same way your laptop does. Advertisers noticed the opportunity in that shift immediately. Fraudsters noticed just as fast, and in several important ways, they noticed first.

Connected television advertising is no longer the experimental line item it was five years ago. US CTV ad spend is projected to reach roughly 37.95 billion dollars in 2026, and eMarketer’s own forecasting puts it on track to overtake traditional linear TV spend entirely by 2028, at 46.89 billion dollars against 45.10 billion dollars for linear. A more immediate milestone already happened this year. eMarketer projects 2026 CTV upfront commitments of 17.73 billion dollars will exceed primetime linear TV upfronts of 16.98 billion dollars, the first time in television advertising history that streaming has won the single most important negotiating season of the year.

Line chart showing US Connected TV ad spend rising from 24.6 billion dollars in 2023 to a projected 46.89 billion dollars in 2028, overtaking traditional linear TV ad spend

That growth curve is genuinely exciting for anyone building a media plan. It is also, according to the security researchers watching this space closely, exactly the kind of curve that draws fraud toward it the way water finds a crack in a foundation. This piece is about that second story, the one running quietly underneath the growth headlines, and what an advertiser can actually do about it.

Why fraudsters love your smart TV specifically

Ad fraud does not distribute itself evenly across the internet. It concentrates wherever three conditions line up at once, and connected television currently satisfies all three better than almost any other channel in digital advertising.

The first condition is price. CTV impressions routinely cost three to five times more than an equivalent desktop or mobile impression, according to research from digital marketing firm Zenon, which means every single fraudulent impression that slips through is worth considerably more to whoever generated it than the same trick would earn almost anywhere else online. The second condition is fragmentation. Unlike the reasonably standardized web browser ecosystem, CTV inventory is scattered across smart TV manufacturers, streaming platforms, virtual pay TV providers, game consoles, and third party streaming sticks, each running its own software stack, according to a detailed breakdown from ad exchange BidSwitch. That fragmentation means there is no single, unified way to verify what is actually happening on the other end of an ad request, and fraudsters have become experts at exploiting exactly the specific gaps each individual platform leaves open. The third condition is technical opacity, and it deserves its own explanation because it is genuinely unique to how modern streaming actually works.

The technology built to make your stream smoother is the same technology hiding the fraud

Here is the part that surprises most advertisers the first time they hear it explained clearly. The single biggest reason CTV fraud is so hard to catch is not attacker sophistication. It is a legitimate, widely used piece of infrastructure called server side ad insertion, or SSAI, that most streaming platforms rely on specifically to make your viewing experience better.

When you watch a show on a streaming app and the ad breaks feel seamless, with no buffering, no jarring transition, no separate ad player loading up, that smoothness is SSAI at work. Rather than your device requesting an ad directly from an ad server the way a website banner would, the streaming platform’s own server fetches the ad and stitches it directly into the video stream before it ever reaches your screen, so from your device’s perspective, the ad and the show are just one continuous piece of video. It is a genuine technical achievement, and it is also, according to a detailed technical breakdown published by marketing firm Zenon, the exact mechanism that fundamentally obscures the viewer’s device information from anyone trying to verify the ad was real, because once traffic passes through that server, fraud detection tools downstream can no longer see the actual device type, operating system, or behavior of whoever, or whatever, is really watching.

Fraudsters figured this out early and built an entire category of attack specifically around it. SSAI spoofing works by distributing millions of fake ad requests from ordinary data center servers, dressed up to look exactly like the legitimate ad calls a real streaming session would generate, according to research from ad fraud prevention firm Strategus. No actual viewer, human or otherwise, ever sees these ads. The inventory exists purely as a billing event, generated specifically to be billed for and nothing else. Layer on top of that a second, related technique called geographic misrepresentation, where fraudsters sell inventory they claim is reaching premium US viewers while the underlying impressions are actually served in markets with far lower legitimate CPMs, and you get a picture of a channel where the exact feature making streaming feel effortless for a real viewer is the same feature making it genuinely difficult to confirm a real viewer was ever there at all.

The fraud has names, and some of them are genuinely audacious

Abstract statistics are useful, but a handful of specific, named fraud operations documented by security researchers make the scale of this problem considerably easier to feel rather than just read about.

Vastflux stands as one of the most brazen operations ever uncovered in video advertising. According to research compiled by fraud prevention platform SpiderAF, the scheme stacked as many as 25 separate video ads invisibly on top of each other within a single ad slot, and spoofed more than 1,700 different mobile apps to make the traffic appear to originate from legitimate, recognizable publishers. Every one of those 25 stacked ads got billed as a separate, viewable impression, even though only the top layer, if any layer at all, was ever technically rendered on a real screen. SneakyTerra, a separate operation also documented in SpiderAF’s research, demonstrated how thoroughly SSAI itself could be weaponized, hijacking the server side insertion pipeline directly to make server generated fraud indistinguishable from a legitimate streaming session at the point of measurement.

The most recent and, in some ways, most unsettling example arrived courtesy of generative AI tooling rather than traditional bot infrastructure. Ad verification firm DoubleVerify documented a scheme it named ShadowBot in June 2025, describing a single fraud operation that generated more than 35 million spoofed mobile device identities within the first quarter of 2025 alone. That is not a typo worth rereading twice to confirm. One operation, one set of AI assisted tools, 35 million fake devices, each one theoretically capable of representing a distinct, billable, entirely fictional viewer to whichever ad exchange happened to receive its traffic.

Just how much of this is actually happening right now

DoubleVerify’s 2026 Global Insights report, titled Must CTV, Streaming’s Shift From Promise to Performance and published on May 7, 2026, is the most current comprehensive look at the state of this specific problem, built from proprietary measurement data spanning billions of protected impressions alongside controlled tests run without protection applied, plus surveys of more than 2,000 marketers and 22,000 consumers across over 20 global markets. Its central finding is blunt. CTV fraud schemes and variants rose 140% in the first quarter of 2026 compared with the same quarter one year earlier, and the number of fraudulent CTV apps detected across 2025 was ten times higher than the count from 2024. The report puts a direct dollar figure on the exposure for anyone not actively filtering for this, estimating 1.8 million dollars lost per billion unprotected impressions served.

Bar chart comparing 13.8 percent CTV ad spend growth against 140 percent CTV fraud scheme growth, showing fraud accelerating far faster than the legitimate market

Put that fraud growth rate next to the legitimate market’s own growth rate and the imbalance becomes genuinely stark. The IAB’s own 2026 Ad Spend Forecast projects CTV ad spend growing 13.8% year over year, the second fastest pace of any advertising channel tracked. Fraud within that same channel grew roughly ten times faster. Independent measurement from ad fraud analytics firm Pixalate corroborates the scale from a different angle entirely, finding that roughly 19% of global programmatic CTV traffic was invalid in the third quarter of 2025, with the US specific rate for open, non curated CTV impressions running close to 18%.

Placed alongside other digital channels, CTV is not actually the single worst offender, and that context matters for an honest read of the data. SpiderAF’s own video advertising research, drawing on measurement across the second quarter of 2025, found invalid traffic running at approximately 18% on CTV, 19% on general web display, and considerably higher, close to 29%, within mobile apps specifically.

That comparison is worth sitting with for a moment, because it complicates the easy, scary headline. CTV is not uniquely broken compared to the rest of digital advertising. It is, however, uniquely expensive per fraudulent impression, uniquely opaque to standard verification because of exactly the SSAI dynamics described above, and uniquely under monitored relative to its own risk level. DoubleVerify’s own 2026 survey data found fewer than one in five advertisers currently measure invalid traffic or fraud specifically as a tracked CTV key performance indicator at all, which means a meaningful majority of the industry spending real, growing budget on this channel is not even looking at the specific number that would tell them how much of it is working.

Why the standard web playbook does not fully translate

Advertisers who have already built strong fraud discipline into their search and display buying, following the exact strategies covered in our broader look at protecting ad budgets across channels, sometimes assume that discipline transfers cleanly to CTV. It transfers partially, and the gaps matter.

The core web era verification stack, built by the IAB Tech Lab specifically to bring transparency to programmatic supply chains, does extend into CTV, and it forms the genuine foundation of any serious defense here. Ads.txt and its CTV specific counterpart, app ads.txt, let a publisher publicly declare exactly which companies are authorized to sell their inventory, closing off the domain and app spoofing that made schemes like Vastflux possible in the first place. Sellers.json lets a buyer look up the actual corporate identity behind every intermediary handling a bid request, rather than trusting an opaque string of resold inventory. The SupplyChain object, transmitted directly inside the bid request itself, lets a buyer see every single hop a given impression passed through before it reached them. And ads.cert 2.0, described by the IAB Tech Lab as an open cryptographic security standard for the entire programmatic ecosystem, adds a layer of verifiable authenticity on top of all of it, making it considerably harder for a fraudulent intermediary to simply lie about who they are.

CTV specifically required an extension to this framework that display and search never needed, because of a genuinely unique business relationship structure in streaming. When a content owner and a distinct app distributor both have a legitimate claim to sell portions of the same streaming inventory, standard ads.txt had no clean way to represent that shared authorization. The IAB Tech Lab’s response was a new variable called inventorypartnerdomain, added to both ads.txt and app ads.txt specifically to let content owners and their distribution partners each formally vouch for the other inside their own authorization files, closing a gap that had previously made it genuinely difficult for a buyer to confirm a piece of CTV inventory was legitimately sourced at all.

None of this framework helps much, however, against the SSAI specific blind spot described earlier, because ads.txt and sellers.json verify who is authorized to sell inventory, not what actually happened technically once server side insertion took over the ad delivery. Closing that specific gap requires a different tool, generally referred to as IFA pass through, short for Identifier for Advertising, which preserves device level identification information through the SSAI pipeline rather than letting it disappear into the server side black box. Marketing firm Zenon’s own guidance for media buyers is direct on this point. Buyers should be explicitly asking their CTV supply partners whether they support IFA pass through as a standard practice, not an optional extra, since without it, a buyer is functionally purchasing inventory it has no real technical ability to independently confirm.

What actually helps, in practice

Pulling this together into concrete buying behavior, a handful of specific practices show up consistently across the research cited throughout this piece as genuinely reducing CTV fraud exposure, and they largely mirror, with important CTV specific adjustments, the broader curated buying philosophy covered in our companion piece on protecting ad budgets.

Prioritizing private marketplace and curated deals specifically for CTV inventory, rather than buying purely through the open exchange, remains one of the single highest leverage moves available, for exactly the same structural reasons that apply in display and search. A direct, negotiated relationship with a known publisher closes off the anonymous reselling and domain spoofing that anonymous open exchange buying leaves wide open. Requiring app ads.txt and sellers.json compliance from every supply partner, treating it as a genuine baseline requirement rather than a nice to have, is described by programmatic advertising platform Basis in its own 2026 guidance as table stakes rather than a differentiator at this point, given how mainstream the standard has become among legitimate publishers. Layering third party verification specifically for post bid, impression level analysis matters even when buying through a PMP or a supposedly trusted walled garden, since DoubleVerify’s own research makes clear that even protected environments are not immune to the newer, AI assisted fraud techniques covered above. And explicitly asking supply partners about IFA pass through support before committing meaningful budget closes the specific SSAI blind spot that standard supply chain verification alone cannot reach.

Perhaps the single most immediately actionable finding in all of DoubleVerify’s 2026 research is also the simplest to act on directly. If fewer than one in five advertisers are currently tracking invalid traffic as a defined CTV KPI, then the advertisers who start doing so this quarter are not just closing a measurement gap. They are moving into a genuinely small minority of buyers who can actually see what is happening inside their own campaigns, while the rest of the market continues optimizing blind toward whatever a Q1 2026 report already showed growing 140% faster than the legitimate channel underneath it.

What 2027 looks like for this channel

A few forward looking signals are worth carrying into next year’s planning specifically because they point toward the problem intensifying rather than resolving on its own.

Industry forecasts cited by ad platform Adwave project artificial intelligence will power roughly 80% of all CTV ad creative and personalization by 2027, a shift that cuts both ways for this specific problem. Better AI driven measurement and personalization should, in principle, improve an advertiser’s ability to confirm a real viewer actually saw a real ad. The same underlying AI capability is exactly what powered the ShadowBot operation’s ability to generate 35 million convincing fake device identities in a single quarter, and there is no reason to expect fraud operators to fall behind on adopting the same tools improving legitimate measurement. Retail media’s expansion into CTV specifically adds a further layer of complexity worth tracking closely, with CTV focused retail media ad sales projected to grow from roughly 4.99 billion dollars in 2025 to 10.28 billion dollars by 2028, more than doubling as commerce data increasingly connects directly to streaming inventory, according to research firm Adwave’s 2026 market update. And the underlying supply itself remains structurally fragmented heading into next year, with only three companies expected to individually command more than 10% of US CTV ad sales in 2026, meaning the diffuse, multi party supply chain that makes verification so difficult in the first place shows no near term sign of consolidating into something simpler to police.

None of this is a reason to slow down CTV investment, and nothing in the data reviewed for this piece suggests that would even be the right response. CTV remains, by every measure of consumer attention and advertiser growth cited above, one of the strongest opportunities in the entire advertising landscape heading into 2027. It is a reason to bring the same fraud aware discipline to this channel that increasingly sophisticated advertisers already bring to search and open exchange display, rather than treating a smart TV screen as somehow inherently safer just because it sits in a living room instead of a browser tab.

Questions advertisers ask most often about CTV fraud

A handful of specific questions come up often enough in CTV budget conversations that they deserve direct answers rather than a vague gesture back toward the general topic.

Is CTV actually worse for fraud than other digital channels. Not necessarily, and the data is genuinely more nuanced than the scariest headlines suggest. SpiderAF’s own measurement puts CTV invalid traffic at roughly 18%, comparable to web display at 19% and meaningfully lower than mobile app traffic at close to 29%. What makes CTV distinct is not a uniquely high fraud rate. It is the combination of a high CPM, meaning each fraudulent impression costs considerably more, and the SSAI driven verification gap that makes catching that fraud technically harder than it is on the open web.

Does buying through a walled garden platform like a major streaming service automatically protect me from this. No, and DoubleVerify’s own 2026 research is explicit on this point. Even protected, branded environments are not immune to newer, AI assisted fraud techniques, and the survey finding that fewer than one in five advertisers track invalid traffic as a CTV KPI applies across buying methods, not just open exchange purchases.

What is the single highest leverage first step if I have not addressed this at all yet. Start measuring it. DoubleVerify’s own data suggests a meaningful majority of the industry is not currently tracking invalid traffic as a defined CTV metric at all, which means simply adding it as a tracked KPI on your next campaign report puts you ahead of most of the market before you have changed a single buying decision.

Will this problem get better or worse heading into 2027. The honest answer, based on every trend line in this piece, is that it depends on execution rather than time alone. AI is improving both fraud detection and fraud generation simultaneously, and the underlying supply chain remains structurally fragmented with no major consolidation expected in the near term. Advertisers who adopt the verification practices covered above should see meaningfully better outcomes. Those who do not are buying into a channel where the fraud growth rate has outpaced the legitimate market’s own growth rate by roughly ten times over the past year alone.

A practical checklist for your next CTV buy

Start by confirming invalid traffic and fraud rate are explicit, tracked KPIs on every CTV campaign your team runs, not just an assumption baked silently into your verification vendor’s invoice. Require app ads.txt, sellers.json, and full SupplyChain object visibility from every publisher and supply path before committing meaningful budget, and treat a supply partner’s refusal or inability to provide this as a genuine disqualifying signal rather than a minor inconvenience. Ask directly about IFA pass through support on any deal involving server side ad insertion, since this is the single most CTV specific gap in the standard verification stack and the one most likely to go unasked. Weight your buying mix toward private marketplace and curated deals with publishers you can name and verify directly, accepting the CPM premium in exchange for the fraud and viewability improvement the broader research cited throughout this piece consistently shows. And revisit this checklist on a genuine quarterly cadence rather than treating it as a one time setup task, given how directly DoubleVerify’s own data shows the underlying fraud landscape shifting inside a matter of months, not years.

The bottom line

Connected television earned its explosive growth honestly, delivering real, differentiated value for advertisers willing to move budget away from a shrinking linear TV audience and toward where actual viewers increasingly spend their time. That same growth, and the immaturity of the measurement infrastructure still catching up to it, is precisely why fraud has flowed into this channel as fast as legitimate spend has. The advertisers who treat CTV with the same measurement rigor, supply chain scrutiny, and ongoing verification discipline they already apply elsewhere in their media mix are the ones positioned to capture the genuine upside of this channel’s growth through 2027 and beyond, rather than quietly subsidizing 35 million fake devices they will never actually get to see convert.

References

Every figure and claim in this piece traces to one of the sources below.

Market size and growth data

  1. IAB, 2026 Outlook Study Forecasts 9.5% Growth in U.S. Ad Spend, Fueled by Digital Growth, Major Cyclical Events and Accelerating Adoption of Agentic AI, official IAB newsroom, January 2026. https://www.iab.com/news/outlook-study-forecasts-9-5-growth-in-u-s-ad-spend/
  2. DigitalApplied, Connected TV Advertising in 2026: A Performance Guide, aggregating eMarketer CTV and upfront spend forecasts. https://www.digitalapplied.com/blog/connected-tv-ctv-advertising-2026-performance-marketer-guide
  3. MNTN Research, CTV Ad Spend Will Grow to $46.89 Billion by 2028. https://research.mountain.com/trends/ctv-ad-spend-will-grow-to-46-89-billion-by-2028/
  4. AI Digital, Connected TV Statistics: Trends and Insights, 2026. https://www.aidigital.com/blog/connected-tv-stats
  5. Adwave, CTV Advertising in 2026: Updated Market Forecast, including 2027 AI personalization and retail media CTV projections. https://adwave.com/resources/ctv-advertising-2026-update

Fraud mechanics and measurement data

  1. DoubleVerify, Global Study: Fueled by AI, CTV Fraud Schemes Surge 140% Globally, official newsroom release of the 2026 Global Insights report Must-CTV, Streaming’s Shift From Promise to Performance, May 7, 2026. https://doubleverify.com/company/newsroom/global-study-ctv-fraud-schemes-surge-140-globally
  2. DoubleVerify, Sophisticated SSAI Scheme Hijacks Real CTV Device Sessions, official documentation of the SneakyTerra fraud operation. https://doubleverify.com/sophisticated-ssai-scheme-hijacks-real-ctv-device-sessions/
  3. SpiderAF, Video Ad Fraud: The 2025 Playbook to Protect CTV, YouTube, and Programmatic Video Budgets, including Vastflux case data and channel level invalid traffic rates. https://spideraf.com/articles/video-ad-fraud-the-2025-playbook-to-protect-ctv-youtube-and-programmatic-video-budgets
  4. SpiderAF, CTV Ad Fraud: SSAI Risks, IVT, and How to Stop It. https://spideraf.com/articles/ctv-ad-fraud-what-it-is-how-it-drains-budgets-and-how-to-stop-it
  5. Zenon Wholesale Digital Marketing, Fraud in OTT/CTV: Device Spoofing, 5 Proven Patterns, covering IFA pass through and CTV botnet behavior. https://zenonwholesaledigitalmarketing.com/ad-fraud/
  6. Strategus, What is CTV Ad Fraud and How Advertisers Can Prevent It, covering SSAI spoofing and geographic misrepresentation. https://www.strategus.com/blog/ad-fraud

Supply chain transparency standards

  1. IAB Tech Lab, CTV Programmatic Guide, covering sellers.json, the SupplyChain object, and ads.cert 2.0. https://iabtechlab.com/standards/advanced-tv/ctv-programmatic-guide/
  2. Index Exchange, More Transparency in CTV Through Ads.txt and App-ads.txt, covering the inventorypartnerdomain standard. https://www.indexexchange.com/2022/08/22/more-ctv-transparency-through-ads-txt-app-ads-txt/
  3. Basis, Transparent Programmatic Advertising Platforms: A 2026 Guide to Brand Safety and Fraud Protection. https://basis.com/insights/transparent-programmatic-advertising-platforms-a-2026-guide-to-brand-safety-and-fraud-protection

Leave a Comment