Seatext library / BotRefund evidence

Signs Your Competitors Are Clicking Your Ads — And How to Prove It

Competitor click fraud shows up as sudden CTR spikes on branded keywords, clicks clustered in the competitor's operating geography during their business hours, and repeated clicks from the same IP blocks. These patterns differ...

Built for advertisers who need clear, refund-ready traffic evidence.

Sudden CTR spikes on your branded keywords, clicks clustered in the competitor’s operating regions, and repeated clicks from the same IP blocks during their business hours are key signs of competitor click fraud.

If you see a sharp jump in click-through rate on your competitor's branded terms, clicks concentrated in the cities or regions where that competitor operates, and the same IP ranges hitting your ads repeatedly during their normal business hours, you are likely seeing targeted competitor click fraud. General bot traffic tends to be distributed across keywords, geographies, and times without that kind of alignment.

What competitor click fraud looks like in practice

Competitor click fraud is deliberate. A rival — or an agency acting on their behalf — clicks your paid ads to drain your budget, skew your conversion data, and push your cost per acquisition higher. Unlike broad invalid traffic from scrapers or click farms, this activity is surgical. It targets the campaigns and keywords where you compete head‑to‑head.

The most common scenario: you bid on a competitor's brand name or a high‑intent product term they also target. Their team or a script clicks your ad, burns your daily budget, and your ads stop showing for real prospects. On Meta, the same logic applies to lead campaigns — fake form fills poison the optimization algorithm so your ads serve to more bots.

Source‑level data from BotRefund case studies shows that bot clicks can steal up to 20% of a Google or Meta ad budget before the platform's own filters catch them. In one neobanking case, the average bot click rate was 14% and the client recovered $140,000 in disputed spend while lifting conversion rates by 18%.

How to distinguish targeted fraud from background bot noise

Background bot traffic is opportunistic. It hits whatever ads are visible, often from data‑center IPs, with no pattern tied to your competitive set. Targeted fraud leaves a fingerprint that matches a specific rival:

  • Keyword specificity: Spikes appear on the competitor's branded terms or a narrow set of high‑value product keywords you both bid on, not across your whole account.
  • Geographic clustering: Clicks come from the metro areas, ZIP codes, or regions where the competitor has offices, sales territories, or known customer density.
  • Time‑of‑day alignment: Activity peaks during the competitor's business hours — often 9–6 in their time zone — and drops off nights and weekends.
  • IP persistence: The same corporate IP blocks, VPN ranges, or office networks appear repeatedly across days or weeks.
  • Device and browser uniformity: Sessions share identical screen resolutions, browser versions, and OS builds — typical of a scripted environment running on a few machines.

If three or more of these line up, the probability shifts from random invalid traffic to intentional targeting.

Common Mistake

Failing to segment click data by keyword and geography, which hides targeted fraud patterns. Marketers often look at overall CTR or spend metrics. Without breaking the data down by individual branded keywords and by the regions where rivals operate, the fraud signal is diluted. Segmenting reveals spikes that would otherwise be masked by normal traffic.

Technical signals that point to a specific competitor

Client‑side detection picks up behavioral evidence that platform filters miss. BotRefund runs 106 independent checks per visit; each check adds one objective fact, and the AI model weighs the complete pattern instead of trusting a single rule. The following signals are especially telling when they cluster around a rival's known footprint:

  • Ghost click detection: Clicks that fire without the natural sequence of human intent — no hover, no scroll, no preceding mouse movement.
  • Honeypot trap interactions: Bots that respond to hidden or deceptive page elements a real user would never see.
  • Robotic linear mouse movements: Pointer paths that are unnaturally straight, lacking the micro‑tremor and hesitation of a human hand.
  • Absence of human‑like mouse tremor: The tiny imperfections and jitter typical of real movement are missing.
  • Superhuman input speed (<1 ms): Interactions faster than a person can physically perform — for example, form fields autofilled in sub‑millisecond intervals.
  • Grid‑aligned movement patterns: Movement that snaps to precise lines or blocks instead of natural curves.
  • Clean Context Iframe mismatches: Automation tools often patch or hide browser APIs; those changes break when the browser is checked from another angle.
  • Scrollbar Width Leak: A mismatch between what a real browser usually shows and what an automated browser reveals.

No single anomaly is a verdict. Privacy tools, corporate networks, and unusual devices can produce unexpected behavior for genuine people. BotRefund keeps each signal as evidence and cross‑checks it against independent browser, network, device, and behavior data. The model reaches 99% accuracy through corroboration, not one browser tell.

Behavioral patterns that suggest intentional targeting

Beyond technical fingerprints, the shape of the session tells a story. Meta Ads invalid traffic research identifies several repeatable patterns that separate automated and invalid activity from normal lead‑quality variation:

  • Contactability anomalies: Disconnected numbers, invalid email domains, repeated addresses, or an unusual concentration of one country code.
  • Timing bursts: Several leads arriving in short windows, forms submitted immediately after landing, or conversions concentrated at unusual hours.
  • Session behavior gaps: No scrolling, no field corrections, uniform click paths, and no meaningful time on the offer page.
  • Campaign pattern divergence: A sharp lead‑quality difference by placement, creative, audience expansion, device, or landing page — especially when the divergence maps to a competitor's known targeting.
  • CRM outcome mismatch: A high reported lead count paired with no calls connected, demos booked, qualified opportunities, or repeat engagement.

Affiliate lead fraud research adds that modern bots bypass basic static protection using headless browsers (Puppeteer, Selenium, Playwright), human‑in‑the‑loop CAPTCHA solving centers, spoofed data pools scraped from public listings, and residential proxy routing that spreads submissions across consumer‑owned IPs to bypass geolocation firewalls. When these leads hit a CRM like HubSpot or Salesforce, they look genuine until sales follows up.

Campaign‑level anomalies worth investigating

Platform reporting often masks the problem. Ads Manager may show a steady cost per lead while the sales team receives unreachable contacts. A structured audit compares three data layers before changing targeting or filing a refund request:

  1. Preserve attribution before changing the campaign. Keep campaign, ad set, creative, placement, and click identifiers intact so you can trace each suspicious conversion back to its source.
  2. Cross‑reference ad‑platform data, website sessions, and CRM outcomes. Look for the signals above: timing bursts, session behavior gaps, and CRM outcome mismatches.
  3. Segment by placement, audience, and device. A sharp quality drop on a specific placement or audience expansion segment often reveals where the fraud is entering.
  4. Map IP and network data to known competitor ranges. Corporate office IPs, known agency VPNs, and data‑center blocks associated with the rival's tech stack are high‑value leads.
  5. Document everything with timestamps, click IDs, and behavioral evidence. Video proof of each bot session — mouse paths, scroll behavior, form interactions — is what ad reps accept for refund disputes.

BotRefund captures this evidence automatically and exports detailed client‑side behavioral proof logs for Google and Meta invalid click disputes. Refunds have been recovered on Google Ads spend dating back to 2017.

Building evidence for a refund request

Ad platforms require evidence that meets their standards. Platform‑level invalid click reports are often generic and lack the granularity to prove intentional competitor targeting. A successful dispute package typically includes:

  • Click IDs and timestamps for each disputed interaction
  • IP addresses, ASN data, and geolocation mapped to the competitor's known locations
  • Behavioral session recordings showing non‑human patterns (ghost clicks, linear mouse paths, superhuman input speeds)
  • Correlation tables linking spikes to the competitor's business hours and branded keyword bids
  • CRM outcome data showing zero revenue, zero qualified pipeline, and zero repeat engagement from the disputed clicks

BotRefund's audit trails are described by a VP of Acquisition at a neobank as "the gold standard that Meta ad reps accept." The platform detects every bot that clicks your ads, captures video proof for each one, and negotiates with Google and Meta on your behalf.

Key facts

MetricValueSource
Average bot click rate (FinTrust case)14%S7
Ad spend refunded (FinTrust case)$140,000S7
Conversion rate increase after suppression (FinTrust case)+18%S7
Bot click budget impact (platform estimate)Up to 20% of Google and Meta ad budgetS2
Detection accuracy (corroborated model)99%S2, S3, S5
Independent behavioral checks per visit106S3, S5
Refund recovery window (Google Ads)Dating back to 2017S2
Typical setup time for free bot auditAbout one minuteS2

Limitations of platform‑level detection

Google and Meta run their own invalid traffic filters, but they optimize for scale, not precision. Their systems:

  • Rely heavily on IP reputation and click velocity — easy for sophisticated actors to rotate.
  • Do not expose session‑level behavioral evidence (mouse paths, scroll depth, form interaction timing) to advertisers.
  • Often classify competitor clicks as "valid" if they come from residential IPs and mimic human timing loosely.
  • Provide limited refund windows and generic dispute forms that rarely result in full recovery without third‑party evidence.

Client‑side detection fills this gap by observing the browser directly. However, it requires adding a script to your landing pages, and it cannot retroactively analyze past traffic — only future visits. Privacy regulations (GDPR, CCPA) require proper consent disclosure for behavioral tracking.

FAQ

How do I know if a click spike is a competitor or just a bad keyword?

Check the keyword list. If the spike is isolated to the competitor's branded terms or a tight cluster of high‑intent product keywords you both bid on, and the geographic and time‑of‑day patterns match the competitor's known footprint, it's likely targeted. A bad keyword usually shows broader, noisier distribution.

Can I block competitor IPs in Google Ads?

Yes, Google Ads allows IP exclusions up to 500 entries per campaign. But sophisticated competitors use residential proxies, VPNs, and rotating data‑center IPs. Static IP blocks are a temporary band‑aid; behavioral detection and suppression of conversion events for automated sessions is more durable.

What evidence does Meta accept for lead‑quality refunds?

Meta typically requires CRM outcome data showing zero contactability, zero qualified pipeline, and a clear pattern of automated behavior (superhuman form fill speeds, no scroll, no mouse movement) tied to specific click IDs. Video session recordings strengthen the case significantly.

How far back can I recover wasted spend?

Google Ads refund requests can reach back to 2017 for invalid clicks if you have the evidence. Meta's window is shorter and varies by account type. The key is preserving click IDs and behavioral logs continuously so you have the data when you file.

Does blocking bots hurt my quality score or ad rank?

No. Suppressing conversion events for verified bot sessions actually improves the signal your bidding algorithm receives. In the FinTrust case, suppressing bot conversions lifted the conversion rate by 18% because the algorithm stopped optimizing for fake leads.

What's the difference between click fraud and invalid traffic?

Invalid traffic is a broad category that includes accidental clicks, crawlers, scrapers, and general bot noise. Click fraud is a subset — intentional, human‑directed or scripted clicks meant to harm a specific advertiser. Competitor click fraud is the most targeted form.

How much does behavioral detection cost?

BotRefund offers a free bot audit with no credit card required. Paid tiers scale with ad spend: under $10,000 / mo, $10,000–$50,000 / mo, $50,000–$250,000 / mo, $250,000–$1 M / mo, $1 M–$5 M / mo, and over $5 M / mo. Enterprise plans include dedicated escalation and custom recovery management.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Further reading and comparison sources

These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.

Learn more

Visit the website for more information.

Learn more