Mobile App Install Fraud: 7 Ways to Save UA Budget (2026)

Somewhere inside a growth team’s dashboard right now, a chart is trending in exactly the right direction. Install volume is up. Cost per install is down. A particular ad network, one the team started testing three months ago, is quietly outperforming every other source in the media mix. The install manager pulls this network’s numbers into next week’s budget review as the good news story, the channel finally worth scaling. Someone on the finance side, looking at the same chart from a different angle, quietly starts building next quarter’s forecast around it.

What that dashboard cannot show, and what almost nobody in that meeting will think to ask, is whether any of those installs came from a human being who ever intended to open the app twice. The number on the screen is real in the sense that it was genuinely reported, genuinely billed, and genuinely counted toward this quarter’s growth target. Whether it represents a real customer is an entirely separate question, and mobile advertising, more than almost any other channel covered in this series, has built an entire technical architecture that makes that second question surprisingly hard to answer without deliberately going looking for the gap.

This is the specific, quiet blind spot mobile user acquisition has lived inside for over a decade, and in 2026 it is arguably wider than it has ever been. Not because the industry has gotten careless. If anything, the opposite is true. Attribution has gotten more privacy protective, more cryptographically verified, and more heavily audited than at any point in mobile advertising’s history. And fraud has adapted to every single one of those improvements in close to real time, often by exploiting the exact mechanism built to stop it. This piece is a full, current look at how that fraud actually works, who has been caught doing it, what the newest privacy frameworks did and did not fix, and what a genuinely fraud resistant mobile user acquisition program looks like heading into 2027.

The size of what is actually at stake

Mobile advertising is not a niche corner of the marketing budget anymore. It is, by a wide margin, where the money already is. Aggregating eMarketer’s own mobile forecasting, global mobile ad spend crossed 430 billion dollars in 2026, with mobile now absorbing roughly 74% of total digital advertising investment worldwide. In the United States alone, mobile ad spend reached 202.59 billion dollars in 2024, up close to 14.4% year over year, with in app advertising specifically accounting for the overwhelming majority of that total rather than mobile web.

Line chart showing global mobile advertising spend climbing from 362 billion dollars in 2023 to 447 billion in 2026 and a projected 480 billion in 2027
Line chart showing global mobile advertising spend climbing from 362 billion dollars in 2023 to 447 billion in 2026 and a projected 480 billion in 2027

It is worth pausing on something an honest researcher runs into immediately when trying to size this market precisely. Different research firms land on genuinely different totals for the exact same year, some citing figures as low as 262 billion dollars for 2025 and others as high as 447 billion for the same period, depending on whether in app, mobile web, and connected device inventory get counted together or separately, and depending on which underlying data source, whether that is SensorTower, Singular, or a firm’s own proprietary panel, the estimate is built on. None of these firms are lying to you. They are measuring genuinely different things and calling the result by the same name. Treat any single mobile ad spend figure, including the ones in this piece, as directionally accurate and useful for sizing the scale of the opportunity, not as an audited number precise to the decimal point.

What every credible source agrees on, regardless of methodology, is that a meaningful share of that enormous and growing budget is not reaching a real person. Mobile measurement platform AppsFlyer, which sits at the center of attribution for a huge share of the industry, found that approximately 22% of non organic app installs globally carried a fraud signal in 2025 and into 2026, up from roughly 17% in 2022, according to analysis of AppsFlyer’s own data published by marketing consultancy RocketShipHQ. Financial and shopping apps, the categories with the highest value per install and therefore the richest target for fraud, saw rates exceeding 35% in some regions. Total financial exposure to app install fraud globally now exceeds 5.4 billion dollars annually by AppsFlyer’s own accounting, a number that only captures the installs sophisticated enough measurement tools actually caught, which means the true figure, accounting for whatever share of fraud is currently slipping past even the best available detection, is almost certainly higher still.

It is worth sitting with what that 5.4 billion dollar figure actually represents before moving on. It is not abstract industry loss spread thinly across thousands of companies in a way no single team ever really feels. It is real budget, pulled from real marketing departments, spent on real invoices from real ad networks, for installs that in a meaningful share of cases never happened at all. Every dollar inside that total came out of a specific team’s specific quarter, justified in a specific budget review, very possibly presented as a success story the exact same way the opening scene of this piece described.

Anatomy of a scheme: what happened when Uber turned off its ads

Statistics are useful, but nothing makes mobile install fraud viscerally understandable quite like watching one company accidentally run the cleanest natural experiment in the industry’s history.

Between 2015 and early 2017, Uber paid its mobile advertising agency Fetch, owned by Dentsu Aegis, roughly 82.5 million dollars to run mobile user acquisition campaigns across a wide network of ad exchanges and sub publishers. On paper, the campaigns looked like a clear success, driving a steady, expensive stream of paid installs across the US, Mexico, France, the Philippines, Romania, and Singapore. Then, in March 2017, after Uber’s own internal analytics team, led by Kevin Frisch, then head of driver and rider acquisition, noticed ads appearing in places Uber had explicitly asked Fetch to avoid, including Breitbart News, Uber made a decision that would later become a genuinely famous case study across the entire ad fraud industry. It turned the entire Fetch mobile campaign off completely.

If those installs had been real, the effect should have been immediate and obvious: a sharp drop in total app installations, since a major paid acquisition channel had just vanished overnight. That is not what happened. According to Frisch’s own later account, delivered publicly at a Mobile Marketing Association event and widely reported since, total installations barely moved. What changed instead was the composition. Installs credited to paid advertising collapsed, while organic installs, the ones nobody paid for, rose by almost exactly the same amount. There was only one honest explanation for a pattern that clean. The vast majority of the installs Uber had been paying for were never actually caused by an ad at all. They were real people who were going to download the Uber app anyway, whose organic install was then fraudulently intercepted and credited to a paid click that had nothing to do with their actual decision, through techniques with names like click spamming, click injection, and ad stacking, according to Uber’s own subsequent legal complaint.

Uber sued Fetch for roughly 40 million dollars in 2017, alleging the agency knowingly funneled its budget into fraudulent inventory while falsifying transparency reports to hide it. Fetch counter sued over unpaid invoices, and the two companies spent years locked in what industry press at the time called a case of toxic partner relations. Uber later withdrew that specific suit and refiled a second, considerably more ambitious one, this time naming the underlying ad networks and exchanges directly rather than its own agency, alleging roughly 70 million dollars had flowed through five named ad tech companies for performance campaigns riddled with the same fraud patterns. According to reporting by Forbes contributor and independent ad fraud researcher Dr. Augustine Fou, Uber ultimately won that fight. It is, to date, one of the only mobile ad fraud disputes of this scale to actually reach a legal resolution in the advertiser’s favor, and it remains the clearest publicly documented proof that a company can pay tens of millions of dollars for installs that were never real, for years, without anyone internally noticing until someone finally ran the experiment of turning the spend off entirely.

Why mobile fraud lives inside a different architecture than web fraud

If you have read our companion piece on connected television advertising fraud, one thing will already feel familiar here. The specific technical architecture behind how mobile apps measure success is exactly what fraud is built to exploit, the same pattern that made server side ad insertion such a rich target for CTV fraud.

Mobile attribution runs almost entirely through a small number of Mobile Measurement Partners, commonly abbreviated MMPs, with AppsFlyer, Adjust, Singular, and Branch representing the large majority of the market. An app developer integrates that MMP’s software development kit, or SDK, directly into their app. When a user clicks an ad, that click gets tagged with a unique identifier, sometimes routed through a tracking link, sometimes through a network specific parameter passed directly to the MMP’s servers. When the same device later opens the app for the first time, the SDK on the device fires an event back to the MMP, which matches that install to the most recent qualifying click within a defined attribution window, commonly somewhere between one and thirty days depending on the network agreement, and credits the corresponding ad network with the conversion, along with whatever payout that conversion is worth under the advertiser’s agreed pricing model.

This entire system, elegant as it is, rests on one assumption that turns out to be the single biggest vulnerability in the whole chain: that the click, the install, and the device reporting both are all genuinely connected to one real person’s one real decision. Nothing in the basic architecture described above independently confirms that assumption on its own. The MMP trusts the click data the network sends it. The MMP trusts the install event the SDK on the device reports. Absent additional verification layers, the entire multi billion dollar attribution system runs on a chain of mutual trust between parties that, in a meaningful share of cases, have a direct financial incentive to bend that trust as far as it will go. Every major mobile fraud technique that follows is, at its core, an attack on that one assumption, targeting whichever specific link in the chain, the click, the install event, or the device identity itself, happens to be least protected at any given moment.

The economics behind the epidemic

None of the techniques described above happen at random. Fraud, like any other criminal enterprise, follows the money with genuine discipline, and understanding exactly which verticals pay the richest bounty for a fraudulent install explains almost everything about where this problem concentrates most heavily.

Cost per install economics vary enormously by category, and that variance maps almost perfectly onto the fraud rates covered earlier in this piece. A casual mobile game might pay a few cents to a couple of dollars for a single install. A fintech app offering a cash sign up bonus, a crypto exchange paying an affiliate for a funded account, or a subscription based dating app optimizing for a paid conversion can pay anywhere from twenty to several hundred dollars for the same single event, and in categories with built in cash incentives, a successful fraudulent install is not merely a wasted ad dollar, it becomes directly, immediately profitable on top of the stolen attribution credit, since the fraudster can often claim the sign up bonus itself as a second payout layered on top of the first. This is precisely why AppsFlyer’s own data, cited earlier in this piece, found financial and shopping apps running fraud rates above 35% in some regions, more than a full order of magnitude above Apple Search Ads’ own sub one percent baseline. The fraud is not evenly distributed because the incentive to commit it is not evenly distributed either.

Gaming occupies a similarly exposed position for a related but distinct reason. Mobile games routinely run enormous user acquisition budgets chasing lookalike audiences of high value spenders, colloquially called whales inside the industry, and even a small percentage of fraudulent installs polluting that lookalike model’s training data can meaningfully degrade the algorithm’s ability to find genuinely high value real players for months afterward. The damage in this case is not only the wasted install cost. It is the compounding cost of an entire acquisition strategy quietly optimizing itself toward the wrong audience, a distortion that can persist long after the original fraudulent traffic has stopped.

Incentivized installs and the gray zone of the offer wall economy

Sitting adjacent to outright fraud, and frequently blurring directly into it, is an entire legitimate advertising category built specifically around paying users to install an app, and understanding where that legitimate category ends and fraud begins is genuinely difficult even for experienced user acquisition professionals.

Offer walls, commonly embedded inside other mobile games and utility apps, present users with a menu of sponsored tasks, install this app and reach level five, sign up for this trial, complete this survey, in exchange for in game currency or another small reward. Used transparently, this is a legitimate, longstanding advertising format, and networks running it above board disclose the incentive clearly and report the resulting installs as incentivized traffic rather than mixing them into an advertiser’s organic or premium reporting. The fraud risk emerges specifically when that disclosure quietly disappears, when a network reports incentivized, reward chasing installs as if they were genuine, unprompted interest, or when the underlying reward itself gets faked entirely through the click injection and SDK spoofing techniques covered earlier, letting a fraud operation claim a real incentive payout for a user who was never actually shown, or never actually completed, the sponsored task at all.

The practical detection challenge here compounds everything covered earlier in this piece, because incentivized installs, even entirely genuine ones, naturally produce weaker retention and engagement than organic or premium paid traffic, since the user’s underlying motivation was the reward rather than the app itself. A user acquisition team unaware they are receiving undisclosed incentivized traffic can easily misread that legitimately weaker retention as a broader problem with the network’s audience quality, rather than correctly identifying it as a labeling and disclosure issue that a straightforward conversation, and a contractual requirement for accurate incentive disclosure, would resolve directly.

The five ways your install budget actually gets stolen

Understanding mobile fraud requires understanding that it is not one attack. It is a family of related but technically distinct techniques, each exploiting a slightly different weak point in the attribution chain described above, and each requiring a slightly different detection approach.

Click spamming, sometimes called click flooding, is the crudest and still among the most common. A fraudulent network fires an enormous volume of fake ad clicks, often thousands per device, hoping that sheer statistical odds will cause at least one of those fake clicks to land within the attribution window right before a device organically installs an app it was always going to install anyway. Because the MMP’s default rule generally credits the most recent click before an install, a network flooding enough fake clicks across enough devices will eventually, purely by chance, steal credit for a meaningful share of organic growth without ever showing a real ad to a real person.

Click injection is a more surgical, considerably more dangerous variant of the same underlying idea. Rather than firing clicks blindly and hoping for a statistical hit, a piece of malware sitting on a device, often bundled inside an unrelated app the user genuinely wanted, actively monitors for the specific system broadcast Android fires when a new app finishes installing from the Play Store. The moment that broadcast fires, the malicious app fires a fake, perfectly timed click, arriving seconds before the install event reaches the MMP, guaranteeing it wins attribution credit over any real, earlier ad interaction. Because the malware is watching for a real install to hijack rather than guessing, click injection converts at a suspiciously fast, suspiciously high rate compared to legitimate advertising, which is exactly the pattern that eventually makes it detectable.

SDK spoofing skips the device almost entirely. Rather than needing a real phone, a real install, or a real user anywhere in the chain, a fraud operation reverse engineers exactly how the MMP’s own SDK communicates with its servers, then generates fabricated install and event payloads directly, sometimes with a spoofed device identifier stolen or synthesized to look legitimate. According to a detailed technical breakdown from mobile fraud research firm Adsafee, once that fabricated payload is signed and formatted correctly, it can be posted straight to the same attribution endpoint a real device would use, and the advertiser ends up paying a full cost per install bounty for something that was never installed on anything at all.

Device farms take a completely different approach, trading technical sophistication for sheer physical scale. Warehouses packed with hundreds or thousands of real, physical phones, or increasingly their software emulated equivalents, run scripted install, open, and immediate uninstall cycles around the clock, each one collecting a cost per install payout for an app that will never be opened a second time. Because the traffic originates from genuine hardware and genuine mobile networks, basic fraud filters built around datacenter IP detection frequently miss it entirely, which is precisely why fraud researchers increasingly describe this category using behavioral signals rather than infrastructure signals, watching what a device does after install rather than only where its traffic originated.

Install hijacking, the final major category, blends elements of the techniques above with straightforward account and payment abuse, using stolen or synthetic identities to complete an install and often a first purchase or sign up bonus, then abandoning the account entirely once the associated reward has been claimed. This variant hits fintech, crypto, and ecommerce apps specifically hard, since those categories routinely offer cash value sign up incentives that make a single successful fraudulent install directly, immediately profitable rather than merely a stolen ad credit.

Taken together, these five techniques rarely operate in isolation inside a genuinely sophisticated fraud operation. A single well resourced network might run click flooding as a broad, low effort baseline across its entire traffic pool, layer click injection specifically onto the subset of devices where malware access has already been established, and reserve SDK spoofing and device farm traffic for whichever specific advertiser campaigns are paying the richest bounty at any given moment. Understanding each technique individually matters less for its own sake than for what it teaches about the underlying detection signal it inevitably leaves behind, since every one of these methods, however they get combined, still has to eventually produce a click and an install event that passes through the same attribution architecture described earlier, and that architecture, imperfect as it is, still records enough about the timing and pattern of that event to make each technique detectable to a team that knows specifically what to look for.

Not every network is equally exposed to this taxonomy, and the gap between the safest and riskiest sources is genuinely enormous.

Bar chart showing non organic install fraud rates ranging from below 1 percent for Apple Search Ads up to an industry average of approximately 22 percent
Bar chart showing non organic install fraud rates ranging from below 1 percent for Apple Search Ads up to an industry average of approximately 22 percent

Apple Search Ads runs below 1% by AppsFlyer’s own measurement, Meta’s fraud rate sits at 1 to 2% on iOS and 2 to 5% on Android, and Google Ads runs 3 to 6% on Android specifically. RocketShipHQ’s analysis attributes that gap directly to incentive alignment rather than superior technology alone. These are the networks with the deepest pockets and the strongest internal motivation to keep their own algorithms clean, since fraudulent installs actively degrade the machine learning models these platforms use to find real customers, making the platform worse at its actual job. Smaller, less accountable networks and long tail programmatic exchanges simply do not carry that same self correcting incentive, which is exactly why the industry wide 22% average sits so much higher than any of the major platforms individually.

The single most useful practical signal across every one of these techniques, and the one that shows up consistently across every fraud detection guide reviewed for this piece, is simply timing.

Bar chart comparing click to install time across three scenarios: roughly 3 seconds for fraudulent click injection, roughly 7 minutes for a typical legitimate install, and hours to days for click flooding fraud
Bar chart comparing click to install time across three scenarios: roughly 3 seconds for fraudulent click injection, roughly 7 minutes for a typical legitimate install, and hours to days for click flooding fraud

A real person clicks an ad, gets curious, maybe reads a review or two, waits for a download to complete, and opens an app somewhere between thirty seconds and several minutes later on average, according to detection guidance published by marketing analytics firm Improvado. Click injection collapses that window down to single digit seconds, since the fraudulent click is generated automatically the instant a real install broadcast fires. Click flooding produces the opposite distortion, an install that traces back to a click fired hours or even days earlier, from a network sending out clicks in such enormous, indiscriminate volume that a statistical match eventually lands regardless of when the user actually engaged with anything at all.

The privacy shift that redrew the entire battlefield

For most of mobile advertising’s first decade, the identifier at the center of this entire attribution system was a persistent, stable device level ID called the IDFA on Apple devices and the Google Advertising ID on Android, both of which any app could read and any ad network could use to build a direct, cross app profile of a single user’s behavior. Apple ended that era abruptly with iOS 14.5’s App Tracking Transparency framework in 2021, requiring every app to explicitly ask for permission before accessing that identifier at all, and the overwhelming majority of users, when actually asked, said no.

In place of the old device level tracking model, Apple built SKAdNetwork, a privacy preserving attribution framework where the operating system itself, rather than any individual app or network, decides which click gets credit for which install, and reports that decision back to advertisers only in aggregate, only after enough installs have accumulated to protect any individual user’s privacy, a threshold the industry calls the crowd anonymity limit. It was, and remains, a genuinely significant piece of privacy engineering. It was never, despite some early industry hope, a fraud solved problem.

Apple’s own privacy framework has fraud problems of its own

AppsFlyer’s own security research team published a detailed breakdown of exactly where SKAdNetwork’s fraud protections hold up and where they do not, and the honest answer is genuinely mixed. Every SKAdNetwork postback, the message reporting a conversion back to an advertiser, is cryptographically signed by Apple and carries a unique transaction ID specifically designed to prevent a fraudulent network from simply inventing conversions out of thin air or replaying the exact same valid conversion multiple times. Those protections are real, and they closed off some of the crudest attacks that had worked freely in the pre SKAdNetwork era.

What those protections were never designed to verify is something more fundamental: whether the underlying click or impression that triggered the postback in the first place ever reflected genuine user interest at all. AppsFlyer’s own security research is explicit that click flooding remains fully viable inside the SKAdNetwork framework, since a network can still fire an enormous volume of fake click reports at Apple’s own attribution system, hoping one of them lines up with a real, organic install purely by chance, exactly the same underlying attack that worked against the older identifier based system, simply redirected at a new target. The cryptographic signature protects the integrity of the message. It says nothing at all about the integrity of the interaction the message claims to represent.

What comes after SKAdNetwork

Apple has continued evolving this framework rather than treating it as finished, and any advertiser planning a 2027 budget needs to understand where that evolution is currently headed. SKAdNetwork 4.0, the current operational version as of this writing, introduced hierarchical source identifiers and multiple staggered postback windows, giving advertisers considerably more granular signal than the single, delayed, all or nothing report the framework originally provided. Apple has simultaneously begun rolling out a newer framework called AdAttributionKit, described by mobile measurement platforms including SplitMetrics and Adjust as the eventual successor to SKAdNetwork, designed to unify how attribution works across both App Store installs and web to app conversions under one consistent system. Mobile measurement partners have responded by building their own additional validation layers directly on top of Apple’s framework. Adjust, for instance, offers a product it calls SKAdNetwork Signature specifically designed to catch spoofed or replayed postbacks that technically pass Apple’s own cryptographic check, an explicit acknowledgment from a major MMP that Apple’s built in protections, while genuinely useful, are not sufficient on their own.

The practical takeaway for any team running iOS user acquisition heading into 2027 is that attribution fidelity here is now a stack, not a single framework. Apple’s own signature and transaction ID checks form the base layer. An MMP’s additional postback validation forms a second layer on top of that. And a marketer’s own post install behavioral analysis, covered in more depth further in this piece, forms the third and arguably most important layer, since it is the only one of the three actually capable of asking whether the person behind an install ever did anything a real customer would do.

The AI era arrives on the factory floor

Everything described so far represents the fraud landscape’s steady, incremental evolution. What arrived in 2026 was something else entirely, and the clearest illustration of it reads less like a marketing case study and more like a genuinely strange piece of investigative reporting.

In late July 2026, cybersecurity research firm Bitsight published findings on a fraud operation it named Fuyao, uncovered after researchers began investigating a batch of unusually cheap Android TV boxes, the small streaming devices sold under budget brands like H96, commonly plugged into a television’s HDMI port. Bitsight found these boxes shipping with preinstalled applications that quietly ran a sophisticated, continuous ad fraud operation in the background, invisible to whoever had actually purchased the device. The apps used device identity spoofing to disguise the box as a premium mobile phone rather than a cheap streaming device, since phone traffic commands considerably higher ad rates, combined that spoofing with residential proxy routing to disguise the traffic’s true origin, and layered AI generated websites on top of the whole operation to give the fraudulent ad placements somewhere to superficially point back to. According to Bitsight’s own reporting, the fraud software even incorporated computer vision models specifically trained to automatically identify where an ad unit sat on any given webpage, letting the operation adapt to new sites without any human involvement at all.

The detail that makes this story genuinely hard to forget, and worth sharing with anyone who still pictures ad fraud as a lone hacker in a basement, is how the underlying automation itself was actually built. Bitsight’s investigation traced the fraud logic back to Blockly, the visual, drag and drop programming environment originally created by Google specifically to teach children the fundamentals of coding. A commercial criminal operation, publicly marketed to potential buyers using the phrase AI digital humans, had assembled a continuously running fraud engine, advertised at more than 120,000 connected devices, using the same building block interface a ten year old might use to make a video game character walk across a screen. Bitsight’s own network telemetry, gathered by sinkholing the operation’s command infrastructure, recorded close to 38,000 unique device identifiers communicating with it within a single 24 hour window. The company behind it, according to patent records Bitsight matched directly to the malware’s internal architecture, was a mainland Chinese firm called Zhejiang Fengwo IoT Technology, operating publicly under the name Fengwo Group, with shell entities registered in Hong Kong and Singapore specifically structured to collect the resulting ad revenue.

Fuyao is not an isolated curiosity. It sits inside a much larger, well documented shift in how fraud infrastructure is being built and sold. Security intelligence firm LexisNexis Risk Solutions, in research published in March 2026, found that agentic traffic, meaning automated bots specifically engineered to convincingly pose as real human users rather than crude scripted traffic, rose 450% during 2025 alone. Identity verification firm GeeTest’s own 2026 industry analysis found that roughly half of sophisticated fraud operations now route their traffic through residential proxies and mobile botnets specifically to defeat IP based filtering, and flagged a genuinely new frontier the industry is only beginning to grapple with, so called bare metal cloud phones, meaning fraud infrastructure built on real, physical, high performance phone hardware rented at scale specifically because it defeats the software based emulator detection built to catch the previous generation of virtual device farms.

Bar chart comparing the non organic install fraud rate in 2022 at 17 percent, the fraud rate in 2025 and 2026 at 22 percent, and agentic bot traffic growth in 2025 at 450 percent year over year
Bar chart comparing the non organic install fraud rate in 2022 at 17 percent, the fraud rate in 2025 and 2026 at 22 percent, and agentic bot traffic growth in 2025 at 450 percent year over year

That gap between the two growth curves matters enormously for how a marketing team should actually think about this problem going forward. The headline fraud rate, 17% climbing to 22%, looks like a real but manageable, gradual escalation. The infrastructure powering that fraud is not escalating gradually at all. It is compounding, and a detection strategy calibrated to the pace of the first number will find itself badly behind the pace of the second one within a single budget cycle.

When mobile fraud becomes a privacy scandal instead

Not every serious problem inside the mobile attribution industry in 2026 involved fake installs at all. Some of the most consequential news involved what happens to the very real data collected from very real devices, and the story of Kochava is worth understanding specifically because the company sits inside the same broad ecosystem, mobile attribution and advertising identifiers, as everything else covered in this piece.

Kochava, a mobile attribution and analytics company founded in Sandpoint, Idaho, found itself the subject of a Federal Trade Commission lawsuit filed in August 2022, alleging the company was selling precise geolocation data, accurate to roughly ten meters by the company’s own marketing claims, tied to persistent mobile advertising identifiers, harvested from hundreds of millions of devices and sold onward with essentially no restriction on who could buy it or what they could do with it. The FTC’s complaint specifically alleged this data could be used to trace an individual’s visits to reproductive healthcare facilities, addiction treatment centers, and places of worship, filed not long after the Supreme Court’s Dobbs decision had raised acute public concern about exactly that kind of tracking. Kochava fought the case aggressively for nearly four years, at one point preemptively suing the FTC itself over what it characterized as vague and shifting definitions of sensitive data, a genuinely unusual legal strategy industry press at the time nicknamed the Kochava Gambit.

That fight finally ended in a settlement reached in May 2026, requiring Kochava to implement a mandatory privacy block feature preventing the sale of raw location data tied to healthcare facilities, schools, jails, and other sensitive location categories, under a two year court supervised injunction. The settlement explicitly did not require the affected consumers, whose data had been sold without their knowledge, to waive their own right to pursue separate monetary damages later. According to legal analysis published by the International Association of Privacy Professionals, Kochava’s settlement lands within the same general pattern the FTC has now applied to several other mobile data brokers, including XMode, Gravy Analytics, and Mobilewalla, all of which reached broadly similar settlements in 2024 and early 2025, suggesting this is now a settled, actively enforced area of FTC priority rather than an isolated case.

The Kochava story matters for this piece for a specific reason beyond privacy policy in the abstract. The same mobile advertising identifiers, the same SDK based attribution architecture, and in some cases literally the same corporate infrastructure that mediates legitimate mobile ad attribution is exactly what made this kind of large scale, non consensual location tracking commercially possible in the first place. Fraud and privacy overreach are not the same problem, but in mobile advertising specifically, they frequently share the exact same underlying plumbing.

A very particular kind of risk: children’s apps

One category of mobile app carries a meaningfully higher regulatory and reputational stakes than any other when advertising and data collection intersect, and 2025 and 2026 delivered some of the clearest, highest profile enforcement the space has ever seen.

The Children’s Online Privacy Protection Act, in force since 2000 and substantially updated through new FTC rules finalized in 2025, requires any app directed at children under 13, or any app operator with actual knowledge it is collecting data from children that young, to obtain verifiable parental consent before collecting personal information, explicitly including the persistent device identifiers that mobile advertising attribution depends on entirely. The updated 2025 rule expanded that coverage further still, now explicitly reaching biometric and government issued identifiers, imposing new limits on how long collected data can be retained, and requiring separate, specific parental consent before a child’s data can be disclosed to third parties for targeted advertising purposes.

The FTC has backed this framework with real, escalating enforcement rather than treating it as background policy. In September 2025, the agency announced a 10 million dollar settlement with Disney, alleging that certain children’s videos uploaded to a third party platform had not been properly marked as child directed content, resulting in unauthorized collection and third party sharing of children’s personal information, according to legal analysis published by law firm Reed Smith. Current FTC guidance puts the maximum civil penalty for a COPPA violation at 53,088 dollars per violation, per day, a figure that compounds extremely quickly across any ad network serving even a modest volume of impressions inside a non compliant children’s app. FTC Chairman Andrew Ferguson has publicly and repeatedly framed children’s privacy protection as a top agency priority, and the pattern of enforcement through 2025 and into 2026, reaching a major, globally recognized brand like Disney rather than only smaller, less visible operators, sent a clear signal that scale and brand reputation offer no meaningful protection from this specific category of risk.

For any advertiser or network running user acquisition campaigns inside gaming, entertainment, or education apps with any meaningful child audience, this regulatory backdrop needs to sit directly alongside, not separately from, the fraud detection practices covered throughout the rest of this piece. A children’s app with weak fraud controls is frequently also a children’s app with weak consent and data handling controls, since both problems tend to trace back to the exact same underlying cause, an SDK integration and third party ad network relationship that was never audited carefully in the first place. The practical implication for a user acquisition team is that vetting a new ad network partner for a children’s category app is no longer purely a fraud and quality question. It has become, in effect, a joint legal and technical due diligence process, since the same third party SDK responsible for reporting an install back to your MMP is very often the same piece of code responsible for whatever data that SDK collects along the way, and a network cutting corners on one is statistically likely to be cutting corners on the other.

Who is actually supposed to be watching: the Mobile Measurement Partner landscape

Every technique, every case study, and every statistic covered so far runs through a small handful of companies sitting at the center of the entire mobile attribution industry, and understanding what these companies actually do, and do not, protect against is essential context for any user acquisition team relying on them.

AppsFlyer, Adjust, Singular, and Branch collectively handle attribution for the overwhelming majority of app install advertising globally. Each has invested heavily in fraud detection specifically because their own commercial reputation depends directly on advertisers trusting the numbers they report. AppsFlyer’s own Protect360 product screens for click flooding, click injection, and SDK spoofing simultaneously, cross referencing device level signals against a continuously updated blocklist of known fraudulent sub publishers. Adjust’s Fraud Prevention Suite runs a comparable set of checks and layers on the SKAdNetwork Signature product described earlier, specifically targeting spoofed or replayed iOS postbacks that pass Apple’s own cryptographic validation but fail a second, independent authenticity check. Singular and Branch each offer broadly similar detection stacks, generally differentiated less by which fraud types they catch and more by how deeply their reporting integrates with an advertiser’s broader analytics and attribution stack.

What an MMP fundamentally cannot do, no matter how sophisticated its detection stack becomes, is verify something happening entirely outside its own visibility. An MMP sees the click, and it sees the install event its own SDK reports. It generally cannot independently verify that the person behind that install ever saw the ad the click claims to represent, which is exactly the gap every technique described earlier in this piece is specifically engineered to exploit. This is also precisely why the cross referencing discipline covered in our companion piece on auditing bot traffic across your marketing stack applies here with particular force. Comparing an MMP’s reported install and event counts against independent, first party product analytics, the actual session data your own app backend records directly, remains one of the single most reliable ways to catch fraud an MMP’s own detection missed, precisely because it introduces a second, independent measurement source the fraud never had to specifically defeat.

The detection signals that actually hold up

Pulling every technique and case study above into something genuinely actionable, a consistent set of signals shows up across every credible fraud detection resource reviewed for this piece as reliably separating real user acquisition from fraudulent activity, regardless of which specific technique is being used to generate it.

Click to install time remains the single most cited signal for a reason. As covered above, legitimate installs cluster in a plausible window of thirty seconds to several minutes after a genuine ad click, while click injection collapses that window to single digit seconds and click flooding stretches it out to hours or days. Any source consistently producing installs clustered tightly at either extreme deserves immediate scrutiny regardless of how attractive its cost per install otherwise looks.

Day one retention by source is close behind in reliability, and arguably more directly tied to actual business outcomes than timing alone. Detection guidance from Improvado puts legitimate sources at above 20% day one retention as a rough, category dependent baseline, with fraudulent sources typically showing under 5%, since a device farm or spoofed SDK payload has no reason to ever open the app a second time once its single attributed event has been recorded and paid out.

Click to install conversion rate, meaning what share of a given source’s reported clicks actually convert into an install, is a third strong signal specifically for click injection detection. RocketShipHQ’s own guidance flags any individual sub publisher converting above roughly 25% of clicks to installs as an almost certain sign of injection or some other form of attribution manipulation, since real advertising, even genuinely excellent, highly targeted advertising, essentially never converts that efficiently at meaningful scale.

Device level behavioral analysis rounds out the most reliable layer, and it is where the industry’s detection technology has advanced the furthest in response to the AI driven threats described earlier. Rather than only checking static, spoofable identifiers like a device ID or an IP address, modern fraud detection increasingly analyzes the actual pattern of on device interaction itself, touch pressure variance, gesture fluidity, navigation timing, and the presence of known automation frameworks like Frida or Xposed used to hook and manipulate an app’s behavior programmatically, according to detection guidance published by verification firm GeeTest. A spoofed device can convincingly fake what phone model it claims to be. It has a much harder time convincingly faking how a distracted, imperfect human actually holds and touches a screen.

Geographic and linguistic consistency forms a final, often overlooked layer worth building into any serious review process. A source reporting installs concentrated in a country your app has never marketed toward, in a language your creative has never been localized into, or at a time of day that lines up poorly with that region’s actual waking hours is a pattern worth investigating regardless of how strong the raw volume or cost numbers look on their own. Fraud operations optimizing purely for cost per install frequently route traffic through whichever region currently offers the cheapest device or proxy access, a decision that has nothing to do with where an advertiser’s actual customers live and everything to do with where fraud infrastructure happens to be cheapest that particular month.

Building a fraud resistant user acquisition program

Translating all of the above into an actual operating practice, a handful of concrete steps show up consistently as genuinely reducing fraud exposure across the sources and case studies covered in this piece.

Insist on log level, source by source reporting from every network and MMP in your stack, broken down granularly enough to spot the specific timing and conversion rate anomalies described above at the individual sub publisher level, not just an aggregated network total that can hide a badly performing pocket of traffic inside an otherwise healthy looking average. Cross reference your MMP’s reported install and event totals against your own first party product analytics on a recurring basis, treating any meaningful, persistent gap between the two as a signal worth investigating rather than a rounding error to ignore, exactly the discipline the Uber case study above shows can uncover fraud that had been running undetected for years. Build day one and day seven retention into your core source level reporting alongside cost per install, not as a separate, occasional check, since a source that looks efficient purely on install volume and cost can look completely different once retention enters the picture. Treat any single source converting clicks to installs at an unusually high rate as a reason for closer manual review rather than a reason to immediately scale budget toward it, resisting the natural instinct to reward whichever number looks best on a dashboard without first understanding why. And build your MMP’s own fraud protection settings into your actual contract negotiations and network vetting process from day one, confirming explicitly which specific detection layers, SKAdNetwork postback validation, device fingerprint clustering, and known fraud network blocklisting among them, are actually active on your account, rather than assuming a platform’s general reputation for fraud protection automatically applies in full to your own specific setup.

What 2027 looks like for mobile fraud

A handful of forward looking signals from the research in this piece are worth carrying directly into next year’s planning, since they point toward specific, foreseeable shifts rather than a vague continuation of the current trend line.

Apple’s continued rollout of AdAttributionKit alongside SKAdNetwork means iOS attribution infrastructure itself will keep changing meaningfully through 2027, and any fraud detection logic built around the specific mechanics of SKAdNetwork 4 today will need active maintenance to keep working correctly as that transition continues, not a one time setup. The AI driven infrastructure shift documented in the Fuyao case and the LexisNexis agentic traffic data is very unlikely to plateau on its own, since the underlying tools that made both possible, cheap, capable AI models and increasingly accessible computer vision, are themselves continuing to improve on a timeline entirely independent of anything the ad fraud detection industry controls. The regulatory environment covered above, spanning the FTC’s continued location data broker enforcement and its clearly stated COPPA priority under Chairman Ferguson, shows every sign of continuing to intensify rather than settle, meaning that data handling compliance and fraud prevention are likely to become an increasingly shared, rather than separate, discipline inside user acquisition teams.

The bare metal cloud phone trend flagged by GeeTest’s research deserves particular attention heading into next year specifically because it represents a genuine escalation in the underlying economics of this fight, not just another incremental technique. Software emulated device farms have always carried a fundamental weakness fraud detection could reliably exploit, the underlying virtualization layer leaves detectable fingerprints no amount of spoofing fully erases. Fraud infrastructure built on real, physical phone hardware rented at scale removes that weakness almost entirely, which means the behavioral detection layer described earlier in this piece, watching what a device actually does rather than what it claims to be, is likely to become the single most important line of defense remaining as this specific arms race continues, precisely because it is the one signal that stays genuinely difficult to fake even once the hardware itself is real.

And the fundamental economic incentive underneath all of it, genuinely large, genuinely growing global mobile ad budgets described at the start of this piece, is not going anywhere, which means the fraud drawn toward that budget is not going anywhere either. None of this is a reason to slow down mobile user acquisition investment, a channel that, for the vast majority of legitimate advertisers, continues to deliver real, measurable growth. It is a reason to build the specific, layered detection discipline covered throughout this piece as a permanent, actively maintained part of the program, rather than a one time integration task completed once during initial MMP setup and never revisited again.

Questions user acquisition teams ask most often

A handful of specific questions come up constantly enough in mobile budget conversations that they deserve direct, sourced answers.

Is iOS genuinely safer than Android for fraud, now that Apple requires tracking permission. Meaningfully safer, but not immune, and this is one of the more persistent misconceptions in the industry. AppsFlyer’s own fraud data, cited throughout this piece, shows iOS sources like Apple Search Ads and Meta’s iOS campaigns running well below Android equivalents. SKAdNetwork’s cryptographic signature and transaction ID checks close off some of the crudest attacks that worked freely against the old identifier based system. Click flooding, however, remains fully viable against SKAdNetwork by AppsFlyer’s own security research, since the framework verifies the integrity of a postback message, not the integrity of the underlying interaction it claims to represent.

How much of my install budget is realistically at risk if I have never specifically audited for this. Based on the industry average cited throughout this piece, a reasonable starting assumption for an unaudited program is somewhere in the range of one in five non organic installs carrying some fraud signal, though the real number for any specific account depends heavily on which networks and sub publishers make up its actual media mix. The Uber case study above is the clearest available reminder that this number can run dramatically higher than industry averages for years without anyone noticing, absent a deliberate effort to check.

Do I need different fraud detection strategies for gaming apps versus fintech or ecommerce apps. Directionally yes, though the underlying detection signals, click to install timing, retention by source, and click to install conversion rate, stay consistent across categories. What changes by vertical is the specific fraud economics described earlier in this piece. Fintech and other cash incentive categories attract fraud specifically chasing sign up bonuses layered on top of stolen attribution credit, while gaming fraud more often targets the lookalike modeling that powers an app’s broader acquisition strategy, meaning the downstream damage in gaming can persist well beyond the immediate cost of the fraudulent installs themselves.

Should I be worried about incentivized traffic specifically, or is it always a red flag. Not always, and treating all incentivized traffic as inherently fraudulent would mean walking away from a legitimate, longstanding advertising category. The distinction that actually matters is disclosure. Transparently labeled incentivized traffic, reported accurately as such, is a legitimate format with predictably different retention characteristics. The risk sits specifically in undisclosed incentivized traffic being reported as if it were organic or premium paid interest, which is a contract and network vetting problem as much as a technical fraud detection one.

A practical checklist for your next campaign review

Pull source level, not just network level, reporting for every active campaign and specifically check click to install timing distribution for any source clustering suspiciously at either extreme. Compare day one and day seven retention by source directly against cost per install, treating a cheap install with poor retention as more expensive, not less, than an accurately priced one with strong retention. Flag any individual source converting clicks to installs above roughly 25% for manual review rather than automatic budget increases. Cross reference your MMP’s reported totals against your own first party analytics on a recurring, calendared basis rather than only when a number looks obviously wrong. Confirm explicitly, in writing, which specific fraud detection layers are active on your account with each MMP and ad network, rather than assuming general platform reputation covers your specific setup. And if your app has any meaningful audience under the age of 13, audit your third party SDK and ad network relationships against current COPPA requirements as a distinct, standalone compliance project, not folded quietly into general fraud prevention.

The bottom line

Mobile app install fraud persists not because the industry has failed to respond to it, but because every serious response so far has been met with an equally serious, equally well funded adaptation on the other side. Apple built a genuinely sophisticated privacy preserving attribution framework, and fraud operators found the specific seams where its cryptographic guarantees stopped short of verifying genuine human interest. Mobile measurement partners built increasingly capable detection layers, and fraud operations responded by renting real phone hardware and building AI powered infrastructure sophisticated enough to convincingly imitate the exact behavioral signals those detection layers were built to catch. The Uber case study that opened this piece is, in one sense, a story from the earlier, cruder era of this fight. It remains relevant precisely because the underlying lesson, that even a company spending tens of millions of dollars a year can have no real idea how much of its paid growth is fake until it deliberately goes looking, has not gone out of date at all. If anything, in an environment where fraud infrastructure is now compounding in sophistication considerably faster than fraud volume itself is growing, that lesson matters more heading into 2027 than it did when Uber first learned it the hard way.

The teams that come out ahead through the next phase of this fight will very likely not be the ones with the single best fraud detection vendor on paper. They will be the ones who built the habit described throughout this piece into their actual operating rhythm, checking retention against cost, checking an MMP’s numbers against first party data, checking a suspiciously strong network’s timing distribution before scaling budget toward it, on a genuine recurring cadence rather than as a one time audit filed away and forgotten. Fraud in mobile advertising is not a problem any single tool, contract clause, or platform update will ever fully close. It is a permanent, ongoing cost of doing business in a genuinely enormous and genuinely valuable channel, and the honest goal was never elimination. It was always making sure the real number, whatever it turns out to be, is one your team actually knows rather than one quietly buried inside a dashboard nobody thought to question.

References

Every figure and case study in this piece traces to one of the sources below.

Market size and scale

  1. DigitalApplied, Mobile Marketing Statistics 2026: 160+ Data Points, aggregating eMarketer, AppsFlyer, Adjust, and Sensor Tower mobile ad spend data. https://www.digitalapplied.com/blog/mobile-marketing-statistics-2026-data-points
  2. SQ Magazine, Mobile Advertising Statistics 2026: Growth, Spend and ROI. https://sqmagazine.co.uk/mobile-advertising-statistics/
  3. RocketShipHQ, Most Advertisers Assume iOS Is Safer Post ATT. AppsFlyer’s Fraud Data Disagrees, analysis of AppsFlyer’s 2025 to 2026 fraud dataset. https://www.rocketshiphq.com/appsflyer-mobile-fraud-report-2025-summary/

Fraud mechanics and detection

  1. Improvado, Ad Fraud 2026: Detection and Prevention Guide, covering click to install timing and retention benchmarks. https://improvado.io/blog/ad-fraud
  2. Adsafee, SDK Spoofing Detection: A 2026 Technical Mobile Fraud Guide. https://adsafee.com/blog/en/sdk-spoofing-detection/
  3. ClickFortify, Mobile Click Fraud Detection: Advanced Strategies for 2026. https://www.clickfortify.com/blog/mobile-click-fraud-detection-strategies
  4. GeeTest, What Is Device Spoofing? How to Stop Fraudsters in 2026, covering behavioral detection and residential proxy adoption rates. https://www.geetest.com/en/article/device-spoofing

The Uber and Fetch case

  1. Forbes, contributor Dr. Augustine Fou, One of Uber’s Lawsuits Against Ad Fraud Comes Full Circle, They Won, January 2021. https://www.forbes.com/sites/augustinefou/2021/01/17/ubers-lawsuit-against-ad-fraud-comes-full-circlethey-won/
  2. Veracity Trust Network, Uber Turned Off 100 Million Dollars of Ad Spend Due to Ad Fraud. https://veracitytrustnetwork.com/blog/digital-marketing/uber-ad-fraud/
  3. AdExchanger, Is Uber’s New Ad Fraud Lawsuit Futile or Game Changing. https://www.adexchanger.com/mobile/is-ubers-new-ad-fraud-lawsuit-futile-or-game-changing/

SKAdNetwork and iOS attribution

  1. AppsFlyer, Immediate Fraud Risks in iOS 14 and SKAdNetwork, official AppsFlyer security research. https://www.appsflyer.com/blog/mobile-fraud/fraud-ios-14-skadnetwork/
  2. SplitMetrics, Apple SKAdNetwork 2025: What It Is and How It Works, covering AdAttributionKit and Privacy Manifest requirements. https://splitmetrics.com/blog/apple-skadnetwork-guide/

The Fuyao operation and AI driven fraud

  1. Help Net Security, Criminals Used AI and Children’s Coding Software to Build a Multimillion Dollar Ad Fraud Empire, July 31, 2026. https://www.helpnetsecurity.com/2026/07/31/fuyao-ad-fraud-botnet-android-tv-boxes/
  2. Bitsight, The Fuyao Enterprise: Building an Ad Fraud Empire With AI and Kids’ Coding Blocks, original research disclosure. https://www.bitsight.com/blog/fuyao-enterprise-building-ad-fraud-empire-ai-and-kids-coding-blocks
  3. HUMAN Security, Understanding Click Fraud Tactics: Advanced Bots, Click Farms, and Mobile Fraud, Satori Threat Intelligence research. https://www.humansecurity.com/learn/blog/click-fraud-bots-click-farms/

Kochava and mobile data privacy

  1. MediaPost, Kochava Privacy Settlement Granted Final Approval, November 2025. https://www.mediapost.com/publications/article/410644/kochava-privacy-settlement-granted-final-approval.html
  2. IAPP, A View From DC: Kochava Is Not Enough. https://iapp.org/news/a/a-view-from-dc-kochava-is-not-enough
  3. AdExchanger, The FTC Bars Kochava From Selling Sensitive Data Without Consent. https://www.adexchanger.com/privacy/the-ftc-bars-kochava-from-selling-sensitive-data-without-consent/

Children’s apps and COPPA

  1. Reed Smith, It’s All About the Kids: The FTC’s Latest Round of COPPA Enforcement, covering the Disney settlement. https://www.reedsmith.com/our-insights/blogs/viewpoints/102l3cw/its-all-about-the-kids-the-ftcs-latest-round-of-coppa-enforcement/
  2. Federal Trade Commission, Children’s Online Privacy Protection Act, official FTC guidance. https://www.ftc.gov/terms/childrens-online-privacy-protection-act-coppa

Leave a Comment