A bot that clicks a product ad costs you the click. A bot that clicks, loads the product page, adds the item to the cart and then leaves costs you the click plus the next three weeks of campaign decisions.
That second bot is what makes e-commerce ad fraud its own category. In most invalid traffic the fake stops at the click, so the funnel below it does the detection work: no session, no event, no order. In retail the fake keeps walking, because what gets imitated is not an impression but shopping behavior, and shopping behavior is a set of ordinary web events the store publishes itself.
In practice, teams looking at this for the first time go hunting for the missing half of the funnel and find it fully populated. Add-to-cart rates hold up, product pages look busy, and nothing reads as broken until margin or repeat-purchase rate slides.
Contents
- The Fake That Does Not Stop at the Click
- Click Inflation on Product Campaigns
- Fabricated Browse and Cart Events
- How Invented Demand Trains the Bidding Algorithm
- Attribution Theft in Coupon and Promo Code Paths
- Scalper Bots: When the Bot Actually Pays
- Where Store Analytics and Campaign Reporting Disagree
- A Funnel-Wide Detection Routine for Retail Campaigns
- What Stays Ambiguous After the Filters Run
- FAQ
- What Your Campaign Learns While You Wait
Key Takeaways:
- Cost decides how far a fake walks. Everything above the payment step is close to free to fabricate, and payment is where invalid activity gets expensive.
- Fabricated cart events cost more than the click they arrived on: they teach the bidding model that the source which produced them deserves more budget.
- Attribution theft leaves total store revenue untouched and only moves the credit, so it stays invisible in any report that reads one channel alone.
- Scalper bots pay, so conversion metrics look excellent and the damage surfaces in retention, refunds, and stock.
- Campaign reporting and store analytics count different things by design, and the gap between them is never zero even on clean traffic.
The Fake That Does Not Stop at the Click
Product view, add to cart, checkout start, and purchase are all calls that a store’s own tags and endpoints accept. Anything able to replay them in a plausible order can produce the outline of a shopper, and nothing in the first four steps needs hardware.
What limits an operation is the price of the next step, and that price is not linear. It rises sharply at one boundary: the point where money has to move.
| Funnel Stage | What the Fake Has to Produce | Cost to the Operator |
|---|---|---|
| Impression | A rendered slot, or a claim of one | Almost nothing |
| Click | A request that survives the redirect chain | Very little per click |
| Product view | A session that loads store scripts and passes client checks | Low, needs a browser-like environment |
| Add to cart | Event calls in a plausible order and timing | Low to medium, needs valid product IDs |
| Checkout start | A form flow, an address, sometimes an account | Medium, identifiers start repeating |
| Payment | A payment instrument that clears | High, and traceable |
| Repeat purchase | A second payment nobody is forcing | Not worth it unless goods resell |
Click Inflation on Product Campaigns
Invalid clicks in e-commerce campaigns come from the cheap end: scripted clients hitting tracking links directly, hijacked redirect chains firing a click the user never made, and click floods sprayed at a merchant in affiliate paths so any later organic purchase falls inside the attribution window.
The 2025 Imperva Bad Bot Report reports that automated traffic reached 51% of all web traffic and passed human traffic for the first time in a decade, with bad bots at 37% of internet traffic. In retail specifically it puts bad bots at 59% of the sector’s traffic, so a store carries a baseline of machine activity before any campaign launches.
Google’s documentation on invalid activity sets out what counts as invalid clicks and impressions and states that detected invalid activity is filtered out and not charged to advertisers. The traffic a buyer ends up arguing about is the residue that survived that filtering, not the raw volume.
The first number worth watching is clicks the ad platform counted against sessions the store’s own analytics counted for the same campaign tag. Click inflation drives those apart while cost per click keeps looking ordinary.
Fabricated Browse and Cart Events
One step up in cost sits traffic that behaves. Fake add to cart bots do not just land on the site, they walk it: a product page, a variant selection, a cart call. The events arrive through the same endpoint a real shopper triggers, so nothing in the payload is inherently wrong.
The reason to bother is that mid-funnel events are what everyone grades on. A source with a healthy add-to-cart rate survives a quality review, clears a partner threshold, and gets more budget, so the operator is selling the appearance of intent rather than clicks.
What the pattern leaves behind is timing and shape: cart events with no dwell time or scroll in front of them, a product mix that is unnaturally narrow or unnaturally even, and a sequence that stops dead at checkout. Real checkout traffic produces a mess of failed payments, address errors and abandoned tabs, and the absence of that mess is more informative than any single event count.
How Invented Demand Trains the Bidding Algorithm
Three separate systems consume those events as truth, which is where the cost overtakes the media.
The bidding algorithm is the first. Most retail campaigns cannot optimize on purchases alone, because purchase volume is too thin to train on, so they optimize toward view-content or add-to-cart signals instead. That is a sensible choice, and it is the one fabricated events exploit: the model raises its valuation of the placements, audiences, and hours that produced the fake engagement, then buys more of them.
Merchandising is the second. Recommendation modules, popular-right-now widgets, and internal search ranking all read product-level engagement, so fabricated browsing promotes whatever the bots touched to real customers. The third is planning: restock decisions made against demand that includes invented demand.
A refund on invalid clicks does not fix any of it. Removing the traffic stops the bleeding but does not untrain the model, and the learned bias persists until the affected window ages out or the campaign is rebuilt. The flow below shows where each scheme enters the shopping path, where it stops, and what the loop reads back.
Attribution Theft in Coupon and Promo Code Paths
Affiliate attribution fraud works on a different axis. The shopper is real, the basket is real, the payment clears. What gets manufactured is the last click before it, because in a last-click model whoever owns that click owns the commission.
The pattern’s documented ancestor is cookie stuffing, where affiliate tracking cookies are dropped on visitors who never clicked anything. MarTech’s coverage of the eBay case reports that Shawn Hogan, then eBay’s top affiliate, pleaded guilty to one count of wire fraud and was sentenced in 2014 to five months in federal prison, a 25,000 dollar fine and three years of supervised release, with court documents showing 28 million dollars in affiliate commissions from eBay. It is an old case whose value is that it established the pattern in court.
The modern surface is the browser. As a documented technique, an extension or toolbar watching for a merchant domain can fire an affiliate click in the background when a user reaches the checkout page, so last-click credit lands on its partner rather than on whatever brought the customer in. Coupon and promo code pages do the same with the user’s cooperation.
This leaves total store revenue unchanged, so any report reading one channel alone sees nothing wrong. Server-to-server postbacks do not solve it either: they protect the conversion event against tampering and tracker blocking, but the parameter rewrite happens at click time, before the tracker has anything to log.
Scalper Bots: When the Bot Actually Pays
Scalper bots in retail spend real money, which makes them the exception to everything above. The goal is inventory rather than commission: limited stock bought at machine speed and resold at a markup.
Imperva’s write-up on scalping bots exploiting a vulnerable retail API documents the mechanism. Instead of driving a browser through the storefront, the operators worked against the retailer’s own application programming interface, the endpoints the site calls behind the scenes, hitting them at a rate no human sequence of page loads could produce. Any defense watching page behavior sees little, because most of the page behavior never happened. Account takeover feeds the same play, because an established account with saved payment details is both a faster checkout and a more convincing customer.
For an advertiser this is the most flattering fraud in the set: conversion rate looks superb, cost per acquisition looks like a personal best, and the model concludes it found a rich audience. The damage arrives later as no repeat purchases from that cohort, elevated cancellations and refunds, real customers who could not buy, and restock decisions built on demand that will never repeat.
Where Store Analytics and Campaign Reporting Disagree
These two systems are not two views of one number. Campaign reporting counts what the ad platform observed and billed after its own invalid traffic filtering, while store analytics counts what the site’s tags and servers saw, minus everything blocked, refused, or lost. They disagree constantly, and the shape of the disagreement identifies the scheme.
Clicks far above sessions points at click inflation. Events far above revenue points at fabricated cart activity. Credited channel share moving while total revenue holds flat points at attribution theft. A strong conversion rate with no cohort surviving to a second order points at bots that bought something. The matrix below sets the four side by side, with what each costs to run and the shopper habit each detection signal can misread.
A Funnel-Wide Detection Routine for Retail Campaigns
Reading the whole funnel comes down to a few reconciliations run on a schedule rather than after a bad month. Hold click count against session count per campaign and per source weekly, and read the trend rather than the absolute value. Watch stage-to-stage ratios instead of single-stage rates: an add-to-cart rate rising while checkout starts stay flat is more specific than either number alone.
Then reconcile credited channel share against total revenue rather than against itself, and read cohort retention by source at 30 and 60 days. Attribution theft surfaces only in the first, and bots that paid only in the second.
Two checks need engineering rather than reporting: money-stage events checked on the server, and rate limits on the endpoints behind checkout and stock reservation. Neither belongs on a media buyer’s desk.
What Stays Ambiguous After the Filters Run
Every signal above has a legitimate twin: prefetch inflates click-to-session gaps, and price comparison shoppers abandon carts on purpose. Analysts who work these cases will not clear a source on one metric, because reconciliation gaps are never zero even on clean traffic. Consent refusal, tracking prevention, and blocked tags all cost store analytics real sessions, so the honest reading is a change in the gap over time.
Two limits deserve no softening. Filtering removes traffic but does not untrain a bidding model that already learned from fabricated events, so recovery means a window reset or a rebuild. And a bot that bought something looks better than an average customer on almost every axis, which is why that call still needs a person who knows the product.
FAQ
What is e-commerce ad fraud?
It is invalid traffic and invalid attribution aimed at retail campaigns: inflated clicks on product ads, fabricated browse and cart events, stolen last-click credit, and bots that buy inventory outright. The fake imitates shopping behavior, so parts of it survive deep into the funnel.
How do fake add to cart bots work?
They replay the event calls a real shopper triggers, so cheap traffic looks engaged enough to pass a quality review and win budget. They stop at checkout, because a payment that clears costs real money.
How can I tell if my online store is getting fake traffic?
Compare clicks the ad platform reports against sessions your analytics recorded for the same campaign, then read stage-to-stage ratios rather than single rates. Cart events with no dwell time and cohorts that never return are the clearest tells, though consent settings and prefetch move the same numbers.
What is affiliate attribution fraud in coupon codes?
It is theft of last-click credit on a purchase that was going to happen anyway, through cookie stuffing historically and browser-side clicks near checkout today. Total store revenue does not move, only the channel that gets paid.
Are scalper bots retail fraud or a security problem?
Both, which is why they get missed. The buying is real, so campaign metrics look excellent while the damage lands in refunds, dead cohorts, and lost customers, and the controls that work sit on checkout and inventory endpoints.
What Your Campaign Learns While You Wait
Invalid clicks are a billing problem and they get resolved as one. Invalid customers are a modeling problem, and nobody sends a credit note for those.
That is the reason to stop treating the click as the unit of investigation in retail. A source sending traffic that browses, fills carts, and never pays is teaching your bidding algorithm what to buy more of and your merchandising what to promote. The sooner funnel disagreement gets read as evidence rather than an analytics quirk, the less of that training there is to undo.
Join our Telegram for more insights and share your ideas with fellow-affiliates.



