All posts
15 Sept 2026· 18 min read

The Real Ad Fraud Taxonomy: GIVT vs. SIVT, Explained

Search this topic and you'll land on two very different kinds of guides. Some are written for programmatic and CTV buyers, covering categories like domain spoofing and SDK fraud that a Google Ads Search advertiser will genuinely never encounter. Others narrow entirely to click fraud, which is real and important but only one piece of a broader category — worth its own deep coverage, which is exactly what our click fraud prevention guide already does, rather than repeating it here. For a shorter, less academic version of this page focused on what actually applies to a Google Ads-only advertiser, see this page instead.

This page does something different: it starts from the actual industry-standard taxonomy — the classification the Interactive Advertising Bureau (IAB) and Media Rating Council (MRC) use, not any single vendor's marketing framework — and filters it down to what genuinely matters if you're running Search, Shopping, or Display campaigns, versus what belongs to a different world of advertising entirely. It also covers a worked example of reading these signals in your own account, and what the widely-cited industry cost figures actually do and don't tell you about your specific situation.

Everything below is written for exactly this purpose: giving you the real, industry-recognized vocabulary and framework, then being honest about which parts of it you actually need to act on given a typical Search-and-Shopping-focused Google Ads account, rather than treating every category in the full taxonomy as equally urgent regardless of what you actually advertise.

GIVT vs. SIVT, the actual industry standard

GIVT

General Invalid Traffic

Known bots & spiders
Listed datacenter IPs
Documented crawlers

Caught by routine, automatic filtering

SIVT

Sophisticated Invalid Traffic

VPN-rotating click fraud
Human-mimicking bots
Real-device click farms

Needs dedicated, behavior-aware detection

The IAB and MRC — the two organizations most of the digital advertising industry defers to for measurement standards — classify invalid traffic into two top-level categories, and understanding this split is more useful than memorizing any longer list of specific fraud techniques, because it tells you something about how each category needs to be caught.

General Invalid Traffic (GIVT) covers activity that's straightforward to identify programmatically: known bots and crawlers (search engine spiders, monitoring services), traffic from data centers rather than genuine residential or mobile connections, and other sources that can be filtered using existing published lists and technical signatures. This is the category Google's own built-in filtering, covered in our click fraud prevention guide, handles reasonably well — it's identifiable by pattern-matching against known, documented sources.

Sophisticated Invalid Traffic (SIVT) is the harder problem, and it's where most current detection research and investment is actually going. This covers residential-proxy botnets designed specifically to look like genuine home internet connections, human click farms (covered in detail in our dedicated guide), hijacked devices running fraud software in the background, and any other activity deliberately engineered to evade basic filtering by mimicking real user behavior. SIVT is, almost by definition, the category that platform-level filtering structurally struggles against — not because the filtering is poorly built, but because SIVT is specifically designed to defeat exactly the kind of pattern-matching GIVT detection relies on.

This distinction matters practically: if your account's invalid click rate (visible directly in Google Ads) looks low and stable, that's mostly telling you GIVT is being handled — it says very little about whether SIVT is slipping through, since SIVT is specifically built not to look anomalous by the metrics that catch GIVT. This is exactly why the deeper checks covered throughout this site — Analytics-session cross-referencing, IP concentration review, engagement-quality analysis — matter even on an account with a clean-looking invalid-click-rate number.

This same two-category split is worth keeping in mind any time you're reading a vendor's marketing claims about "detection rates" too — a tool that reports catching, say, 95% of invalid traffic is likely reporting strong performance against GIVT specifically, since that's the more measurable, catchable category. A meaningfully lower, harder-to-market figure for SIVT specifically is the more honest number, and it's worth asking any vendor directly which category their headline detection rate actually describes, the same evaluation instinct covered in more detail in our buyer's guide.

The fraud types that actually matter for a Search advertiser

Click fraud is the one most directly relevant to Search, Shopping, and Display campaigns — a click billed with no genuine buying intent behind it, whether from a bot, a click farm, or a competitor manually clicking your ads. This gets full, dedicated treatment in our click fraud prevention guide, including the specific audit steps and the mechanics of why IP-only blocking has real limits — worth reading in full rather than summarized again here.

Impression fraud is the second, and it's genuinely relevant if you run Display or Performance Max campaigns specifically, less so for pure Search. This covers fake or non-human ad impressions — bots loading pages specifically to register an ad view without any human ever seeing it, or ads placed in ways designed to be technically "viewable" by a narrow technical definition while never actually being seen by a real person (stacked ads, tiny or off-screen placements on low-quality sites). Unlike click fraud, you're not paying per fraudulent impression directly under most CPC billing — the cost shows up more indirectly, through Display and PMax budget being consumed by placements that could never have converted regardless of ad quality, and through polluted performance data that can mislead PMax's own automated placement decisions over time, the same automation-blind-spot mechanism covered in our automation tools guide.

Attribution fraud is the third, and it's the one most advertisers underestimate the relevance of. This covers manipulation of which touchpoint gets credit for a conversion — click spam and click injection (covered in full in our dedicated guide) are the mobile-app-specific version, but a lighter version of the same underlying problem shows up in Search too: cookie stuffing or last-click manipulation designed to insert a fraudulent touchpoint into a genuine customer's path right before they were going to convert anyway, stealing credit (and, in an affiliate context, payout) for a conversion that would have happened regardless.

It's worth checking which of these three you're genuinely exposed to based on your actual campaign mix, rather than treating all three as equally urgent by default — a Search-only account with no Display or Shopping campaigns running has essentially no direct impression-fraud exposure, since that category specifically requires the placement mechanics Display and PMax introduce. Spending equal monitoring effort across all three when only one or two genuinely apply to your account wastes attention better spent going deeper on the category that actually matters for your specific setup.

The fraud types that mostly don't apply to you, and why they're still worth knowing

Domain spoofing is a programmatic advertising problem: a fraudster's low-quality inventory gets misrepresented to an ad exchange as coming from a premium, reputable site — imagine fake inventory claiming to be nytimes.com when it's actually an obscure, low-traffic page. This exploit is specific to how programmatic ad buying works, matching buyers to inventory through automated exchanges with limited real-time verification of the actual source — a Google Ads Search or Shopping campaign, bought directly rather than through a programmatic exchange, isn't exposed to this particular mechanism.

SDK spoofing and app-install fraud are mobile-app-specific, covered from the attribution angle in our click spam guide — these exploit the software development kits mobile apps use to report installs and in-app events to attribution platforms, a mechanism that doesn't exist in Search or Shopping advertising at all.

Ad stacking and pixel stuffing are Display-network and programmatic-specific techniques — layering multiple ads on top of each other so only the top one is visible while all of them register as served, or shrinking an ad to a single pixel so it's technically "displayed" without ever being genuinely seen. These are real problems for advertisers buying broad Display or programmatic inventory at scale; they're a non-issue for Search text ads, which have no equivalent stacking mechanism.

Connected TV (CTV) and video ad fraud is its own growing category, driven by fake or hijacked streaming apps reporting inflated ad views — entirely irrelevant unless you're specifically running video or CTV campaigns, which sit outside the Search-and-Shopping focus most of this site addresses.

It's worth knowing these categories exist, even if they don't apply to your account today, for two reasons: first, if your business ever expands into programmatic Display, mobile app advertising, or video/CTV, this is the vocabulary you'll need. Second, understanding the full taxonomy helps you correctly interpret industry-wide statistics — a headline number about total ad fraud losses usually blends all of these categories together, and a meaningful share of it reflects programmatic and CTV fraud that has nothing to do with a Search-focused advertiser's actual exposure.

Affiliate fraud, and when it's worth knowing about

Affiliate fraud is a distinct category worth its own mention if your marketing extends beyond direct Google Ads spend into an affiliate program — fraudulent affiliates generating fake leads or fake sales to collect commission payouts, or claiming credit for conversions that would have happened without their involvement through the same last-click attribution manipulation covered in the attribution fraud section above. This is a genuinely separate risk from anything covered elsewhere in this piece, since it involves a business relationship (paying commissions to partners) rather than a platform billing you directly for clicks or impressions.

If you don't run an affiliate program, this category simply doesn't apply to you — worth confirming explicitly rather than assuming, since the line between "affiliate marketing" and "paid advertising" isn't always obvious from the outside, and some businesses run affiliate relationships without necessarily labeling that spend the same way they think about their Google Ads budget.

If it does apply to your business, the detection approach differs meaningfully from platform-level ad fraud too — affiliate networks generally offer their own fraud-monitoring dashboards specific to partner activity, worth reviewing directly rather than assuming your Google Ads-focused click fraud tool extends coverage to affiliate relationships it was never built to monitor.

A worked example: reading GIVT vs. SIVT in your own account

Say your invalid click rate, visible directly in Google Ads, sits at a stable 2-3% — a reasonable, unremarkable figure that suggests GIVT (the obvious, pattern-matchable stuff) is being caught normally. On its own, this tells you very little about SIVT exposure, since sophisticated invalid traffic is specifically built to avoid tripping this exact metric.

Now check the gap between your Google Ads reported clicks and your real Analytics sessions for the same period, covered in detail in our click fraud prevention guide. If that gap is meaningfully wider than the 2-3% invalid click rate would suggest — say, Ads reports 1,000 clicks but Analytics shows only 920 matching sessions, a roughly 8% gap — that additional, unexplained difference is a genuine SIVT signal: traffic sophisticated enough to avoid Google's own GIVT-level filtering but that never actually resulted in a real browser session reaching your site.

This is precisely the diagnostic value of understanding the GIVT/SIVT split rather than treating "invalid click rate" as the complete picture: a clean invalid-click-rate number paired with a real Analytics gap tells a specific, actionable story — your account has a genuine SIVT problem that the platform's own GIVT-focused filtering isn't going to catch on its own, and it needs the deeper checks (IP clustering, engagement-quality review) covered throughout this site's fraud-prevention content specifically because they're built to catch what GIVT-focused metrics structurally miss.

As a rough calibration point, some marketing analytics firms cite a gap above roughly 15% between platform-reported clicks and Analytics-recorded sessions as a reasonable threshold worth treating as a red flag, versus the smaller gaps (10-15%) that can reflect ordinary tracking latency or minor technical noise rather than invalid traffic. Treat this as a directional calibration rather than a precise cutoff specific to your account — the right threshold depends on your own historical baseline, which is exactly why establishing what's normal for your specific account matters more than applying any external number uniformly.

Detection approach by category, concretely

For GIVT: Google's own built-in filtering, visible as invalid clicks in your reporting, handles most of this automatically — your job is mainly monitoring the trend (is the rate climbing) rather than actively hunting for it, since this category is specifically the one platform-level filtering is well-suited to catch.

For SIVT in the click-fraud context: the layered approach covered in full in our click fraud prevention guide — Analytics-session cross-referencing, IP concentration review, and for anything beyond basic IP exclusion's real limits, device-fingerprinting or behavioral-scoring tools covered in our software buyer's guide.

For impression fraud on Display/PMax: review placement-level performance directly (Campaigns, then Placements) for any Display or PMax campaign, looking for sites or apps with meaningfully high impression or click volume relative to conversion rate — the same placement-exclusion practice covered briefly in our click fraud prevention guide, worth its own dedicated, recurring check specifically for Display-heavy accounts.

For attribution fraud: this is harder to self-diagnose without dedicated tooling, since it involves manipulation of the attribution path itself rather than a single visible metric — if you suspect this specifically (an unusual pattern of last-click conversions from an unfamiliar or unexpected source), a specialized attribution-fraud or affiliate-fraud detection tool, distinct from a general click fraud tool, is the more appropriate category to evaluate.

None of these four detection approaches require expensive or exotic tooling to start — everything in the GIVT, click-fraud SIVT, and impression-fraud checks above is available natively inside Google Ads and Google Analytics, the same free-tool-first approach emphasized throughout this site's fraud-prevention content. Attribution fraud is the one genuine exception, where specialized tooling becomes more necessary rather than optional, simply because the manipulation happens at a layer (the attribution path itself) that standard ad platform reporting doesn't expose directly.

What the industry-wide cost figures actually mean for you

You'll see large, headline-grabbing numbers attached to this topic — a commonly cited $63 billion figure for 2025 invalid traffic losses (from Lunio's own annual Global Invalid Traffic Report — worth noting it's the vendor's own research, not an independent audit), and Statista projections putting total digital ad fraud losses above $170 billion by 2028. These numbers are worth understanding as industry-scale estimates, not as a figure that translates proportionally down to your specific account.

These headline totals blend every category covered throughout this piece — programmatic domain spoofing, CTV fraud, mobile SDK spoofing, click fraud, and more — into one combined figure. A Search-and-Shopping-only advertiser's actual relevant exposure is a meaningfully narrower slice of that total than the headline number implies, since a large share of industry-wide ad fraud losses sit in programmatic and CTV categories that, as covered above, don't apply to a Search-focused account at all.

The genuinely useful number is your own account's own data — the invalid click rate and Analytics-session gap covered in the worked example above, translated into an actual dollar figure at your own spend level, the same exercise covered with a full worked calculation in our Google Ads cost guide. Treat industry-wide statistics as context for why this category deserves attention at all, not as a number that tells you anything precise about your own account.

It's also worth a healthy dose of skepticism toward any specific percentage-growth or year-over-year figure attached to these headline numbers, for the same reason covered throughout this site regarding unsourced benchmark claims generally — methodology, scope, and what's being measured vary enough between reports (Lunio's own advertiser-focused survey versus Statista's broader market projection, for instance) that comparing the specific numbers directly against each other, or treating either as a precise forecast, reads more certainty into the underlying research than the research itself usually claims.

Why the taxonomy itself is worth understanding, not just the checklist

It's reasonable to wonder why any of this classification matters if the practical advice ultimately points back to the same handful of checks (invalid click rate, Analytics cross-referencing, IP review) covered throughout this site. The answer is that the taxonomy changes what you're actually looking for and why a given signal matters, which changes how confidently you can interpret an ambiguous result.

Without the GIVT/SIVT distinction, a clean invalid-click-rate number might reasonably be read as "no fraud problem here" — a completely understandable but potentially wrong conclusion, since that metric specifically reflects GIVT detection and says nothing directly about SIVT. With the distinction in mind, the same clean number becomes a more precise, useful signal: "the obvious stuff is handled; now check the SIVT-specific signals separately before concluding anything." That's a genuinely different, more accurate read of the same underlying data, and it's the kind of interpretive clarity a longer, unstructured list of fraud techniques doesn't provide as directly as the two-category framework does.

The same logic applies to the channel-specific and category-specific filtering covered throughout this piece — knowing that domain spoofing is a programmatic-exchange problem, not a direct-buy Search problem, means you don't waste evaluation time asking a Search-focused tool vendor about protection you don't actually need, and you don't mistakenly assume a tool that handles domain spoofing well is therefore strong on the click-fraud protection that actually matters for your account.

How exposure differs by channel, if you run more than one

Search carries primarily click-fraud risk — the mechanism covered in depth in our fraud prevention guide, billed per click, with GIVT and SIVT both potentially present.

Shopping carries similar click-fraud risk to Search, plus a feed-quality dimension worth mentioning briefly: a poorly maintained product feed can indirectly increase wasted spend by surfacing your products for irrelevant queries, which isn't fraud exactly but compounds with genuine invalid-traffic waste in a similar direction.

Display and Performance Max carry both click fraud and impression fraud, given their broader placement mix across the Display Network — worth the placement-level review covered above specifically because this channel mix has exposure Search alone doesn't.

If you're running Meta or other platforms alongside Google Ads, the risk profile shifts again — covered in detail in our platform comparison guide, since Meta's interest-and-impression-based model carries a different mix of fake-engagement and bot-account risk than Search's click-based model.

The practical takeaway: a multi-channel advertiser needs a genuinely different monitoring checklist per channel, not one unified check applied uniformly — treating Display placement review, Search click-rate monitoring, and Shopping feed health as three distinct, recurring tasks rather than assuming one general "fraud check" covers all of them equally.

Is ad fraud the same thing as invalid traffic?

Not exactly, though the terms overlap heavily and get used interchangeably in a lot of content. Invalid traffic (IVT) is the broader technical/measurement term covering both GIVT and SIVT — some invalid traffic is genuinely accidental or non-malicious (a misconfigured monitoring tool, an automated uptime checker) rather than deliberate fraud. Ad fraud specifically implies deliberate, intentional manipulation for financial gain. In practice, most of what an advertiser actually needs to act on falls under SIVT and is genuinely fraudulent, but the technical distinction is worth knowing when reading more formal industry material.

Which ad fraud type costs advertisers the most money overall?

This varies by source and methodology, and — consistent with the caution throughout this piece about industry-wide figures — is worth treating as directional rather than precise. Several sources point to sophisticated invalid traffic and bot-driven fraud as accounting for the largest overall dollar losses across the industry, since it's both harder to detect and often targets higher-value inventory, but the specific type that costs *your* account the most depends entirely on which channels you run and your own account's actual data, not any industry-wide ranking.

Do I need a different tool for each type of ad fraud I might be exposed to?

Not necessarily, though it's worth being clear-eyed about scope — a tool built specifically for Search and Shopping click fraud protection, covered in our tool comparison and buyer's guide, won't meaningfully address programmatic domain spoofing or mobile SDK fraud, simply because those exploit entirely different systems. If your advertising is genuinely confined to Search, Shopping, and Display, a dedicated click-and-impression-fraud tool covers your real exposure. Expanding into programmatic, mobile app, or CTV advertising later would genuinely warrant evaluating a separate, category-specific tool for that new channel rather than assuming your existing Search-focused tool extends to cover it.

How often should I revisit which fraud types actually apply to my business?

Whenever your channel mix changes meaningfully — adding Display, Shopping, PMax, mobile app campaigns, or a new platform entirely — is the natural trigger to revisit this, since each addition can introduce exposure to a category that didn't apply before. Absent a channel change, the underlying taxonomy itself doesn't shift quickly enough to need frequent revisiting; your recurring attention is better spent on the account-level monitoring covered in the detection section above than on re-reading the taxonomy itself.

Is bot traffic always fraud, or can bots be harmless?

Not all bot traffic is fraudulent or even unwanted — legitimate bots (search engine crawlers, uptime monitors, accessibility tools) serve genuine, disclosed purposes and generally don't interact with paid ads or register as billable clicks in the first place, since they're not designed to click on advertising at all. The GIVT category specifically includes these legitimate, known bots alongside more clearly problematic automated traffic, which is part of why GIVT filtering doesn't treat every bot as inherently malicious — it's filtering based on known, documented source lists rather than assuming all automation is an attack.

Does ad fraud affect organic search rankings the same way it affects paid ads?

No — organic search ranking algorithms and paid ad billing are entirely separate systems, and the invalid-traffic concepts covered throughout this piece are specific to paid advertising's billing and measurement mechanisms. Organic SEO has its own separate category of manipulation concerns (link spam, fake reviews, content scraping) that operate through different mechanisms and require different countermeasures, genuinely outside the scope of what this piece or the broader fraud-prevention content on this site addresses.

The short version

Ad fraud splits into two useful categories, per the actual industry standard: General Invalid Traffic (obvious, pattern-matchable, handled reasonably well by platform-level filtering) and Sophisticated Invalid Traffic (deliberately engineered to look legitimate, and the reason the deeper checks throughout this site exist). If you run Search, Shopping, or Display, click fraud and impression fraud are your genuine, relevant exposure — covered in full depth in our dedicated guide. Domain spoofing, SDK fraud, and CTV fraud belong to programmatic and mobile-app advertising, not your account, unless your channel mix expands into those areas. And the industry-wide dollar figures you'll see cited are useful context for why this category matters, not a number that tells you anything precise about your own account — that number comes from your own invalid click rate and Analytics-session gap, translated into your own actual spend.

See exactly what's hitting your account

ClickPurity fingerprints every click on your Google Ads and automatically blocks confirmed fraud — no manual review needed.