You set a budget, launched the campaign, and watched the clicks roll in. However, the customers didn't follow. Here's the uncomfortable part: a meaningful share of that spend may have gone to traffic with no business value at all. Invalid traffic (IVT) is any ad click, impression, or visit generated by bots, fake users, or automated activity rather than a genuine prospect. In 2025, fraud0's Unmasking the Shadows report found that 21.3% of all onsite traffic was invalid (search-engine crawlers excluded), across 1.2 billion sessions. That's more than a fifth of your visitors who were never going to buy. This guide therefore shows you both ways to fight back: reduce the waste going forward, and recover what you've already lost.
Key Takeaways
In 2025, fraud0's Unmasking the Shadows found 21.3% of onsite traffic invalid (search-engine crawlers excluded), rising to 32.0% per individual user, so aggregate rates understate your exposure.
Ad spend recovery runs on two motions: mitigate the risk (reduce future waste through detection and exclusion) and refunds (recover past waste with documented evidence). Detection cuts the leak, but a brand-new bot's first click can still slip through, so refunds stay essential.
Refunds are evidence-based and process-driven. Outcomes depend on detected invalid activity and platform processes, and platforms like Google typically return money as account credit, not cash.
Channel matters: Paid Social showed 20.6% invalid traffic versus 7.0% for Paid Search, so where you spend changes your risk.

Most marketers never see this waste. Your platform dashboard reports clicks and conversions, your analytics looks healthy in the weekly report, and yet performance quietly underdelivers. The money's gone before anyone asks where it went. This is the gap what invalid traffic actually is sits in, and it's bigger than most teams assume.
Ad spend recovery is how you close that gap. It isn't a single tactic or a one-time refund request. It's a discipline with two arcs that work together. First, you make invalid traffic visible and reduce how much you pay for it going forward. Second, where invalid activity is detected, you document it and pursue recovery of what's already been wasted. Detection cuts the leak, but it never seals it completely, so the two arcs always run side by side. This pillar maps both and links you to the detailed playbooks for each.
What is ad spend recovery?
Ad spend recovery is the practice of cutting wasted ad budget and reclaiming what's already been lost to invalid traffic. In 2025, fraud0's Unmasking the Shadows report measured 21.3% of onsite traffic as invalid (search-engine crawlers excluded) and 9.75% of conversions as invalid (7.82% confirmed bots plus 1.92% suspected). Recovery therefore turns those hidden losses into a plan you can act on.
Think of it as two motions, not one. Specifically, the first is forward-looking: detect invalid traffic, exclude the sources, and reduce the spend that leaks. The second is backward-looking: where you can prove invalid activity hit your campaigns, you build evidence and pursue a refund or credit through the platform's process.
In 2025, fraud0's Unmasking the Shadows report analyzed 1.2 billion onsite sessions and 10.78 billion ad impressions and found 21.3% of onsite traffic invalid (search-engine crawlers excluded), 32.0% invalid per individual user, and 9.75% of conversions invalid. Ad spend recovery addresses both the future leak and the documented past loss.
Here's why the distinction matters. In particular, reducing future waste protects more of your budget from tomorrow onward, but detection never catches everything. Pursuing refunds addresses the budget already spent and the residual that slips past detection. You need both, because doing only one leaves money on the table. Skip prevention and you keep paying. Skip recovery and you write off what you've already lost.
The honest caveat up front: refunds are never guaranteed. They depend on what invalid activity is actually detected and on each platform's review process. We'll be specific about that throughout, because over-promising helps no one.
Why is so much ad budget wasted on invalid traffic?
Invalid traffic is far more common than most marketers realize, and notably it concentrates. In 2025, fraud0's Unmasking the Shadows report found that the aggregate 21.3% invalid rate climbed to 32.0% when measured per individual user, with search-engine crawlers excluded from both figures. So roughly a third of the average user-level activity touching your site carried no business value. That's the figure most dashboards never surface.
The wider web backs this up. In 2024, Imperva's Bad Bot Report concluded that bots made up 51% of all web traffic, the first year automated traffic overtook humans. Consequently, when more than half the internet isn't human, some of it inevitably lands on your ads and your site.
Moreover, the money scale is large too. Ad fraud is the deliberate generation of fake clicks, impressions, or conversions to siphon advertiser budgets, and it sits at the costly end of the invalid-traffic spectrum. For example, Juniper Research has estimated advertiser losses to ad fraud at roughly $84 billion for 2023, projected to keep climbing. These are industry estimates, not your invoice, but they frame the size of the problem you're managing.
Where does invalid traffic come from?
Invalid traffic isn't one thing. It's bots clicking ads, fake leads polluting your CRM, made-for-advertising sites harvesting cheap impressions, and conversion fraud inflating your reported results. Made-for-advertising (MFA) sites are low-quality web pages built primarily to farm ad revenue rather than serve real audiences. In 2025, fraud0's Unmasking the Shadows report found that 31.4% of ad impressions landed on MFA sites, placements built to farm ad revenue rather than reach real audiences.
As a result, you get data you can't fully trust. Your reports look fine because the invalid activity often mimics real behavior closely enough to pass. For example, invalid users in the fraud0 data averaged just 1.2 page views and 26-second sessions, versus 181 seconds overall, so they drag your averages down while padding your volume.
Why does waste concentrate by channel?
Your risk isn't spread evenly. Instead, it depends heavily on where you spend. In 2025, fraud0's Unmasking the Shadows report broke invalid traffic down by channel and found a wide spread, from 20.6% on Paid Social to 7.0% on Paid Search. Same budget, very different exposure depending on the mix.

Source: fraud0, Unmasking the Shadows 2025 (search-engine crawlers excluded).
Most fraud-rate headlines quote a single aggregate number, which quietly understates the real exposure for two reasons. First, the per-user rate runs higher than the per-session rate, because invalid users tend to come back. fraud0 found that 5.19% of bot users drove 17.67% of bot sessions, and on Paid Social, 71.6% of bot sessions were repeat bots. Second, your channel mix can push your personal exposure well above or below the headline. A single average hides both effects.
What does channel-level waste look like in dollars?
A single rate feels abstract until you put a budget behind it. Therefore, let's model one. The table below is an illustrative model, not a guarantee or a quote. It takes a hypothetical $100,000 monthly budget, splits it across channels the way many advertisers do, and applies the per-channel invalid rates from fraud0's Unmasking the Shadows 2025 report. Your real numbers depend on your own detected invalid activity.
Channel | Monthly spend | Invalid rate | Estimated wasted spend |
|---|---|---|---|
Paid Search | $40,000 | 7.0% | $2,800 |
Paid Social | $30,000 | 20.6% | $6,180 |
Programmatic/Retargeting | $20,000 | 20.0% | $4,000 |
Affiliate | $10,000 | 17.5% | $1,750 |
Total | $100,000 | 14.7% blended | $14,730 |

Source: Invalid rates from fraud0, Unmasking the Shadows 2025; spend split illustrative, not a quote or guarantee.
For example, walk the math channel by channel. Paid Search takes the largest slice at $40,000, but its 7.0% invalid rate is the lowest in the mix, so the modeled waste is about $2,800. Paid Social carries $30,000 at a 20.6% rate, nearly three times the search rate, which models out to roughly $6,180, the biggest single line of waste here.
Programmatic and Retargeting runs $20,000 at 20.0%, around $4,000, and Affiliate adds $10,000 at 17.5%, about $1,750. Add the lines together and the model suggests roughly $14,730 of monthly spend reaching traffic with no business value. That's a blended 14.7% on this particular mix, well below Paid Social's headline rate because lower-risk Paid Search carries the heaviest weight.
The lesson isn't the exact dollar figure, which will differ for every account. It's that two advertisers with identical budgets and identical platform rates can lose very different amounts, purely from how they weight the mix. Shift that same $100,000 toward Paid Social and the modeled waste climbs. Shift it toward Paid Search and it falls. Your media plan is a risk decision, not just a reach decision.
How invalid traffic varies across Meta, Microsoft and TikTok explains how to read this channel by channel for your own accounts.
Arc one: how do you mitigate the risk of wasted ad spend?
Mitigation means reducing the leak, not sealing it. In 2025, fraud0's Unmasking the Shadows report found 21.2% of in-ad impressions invalid alongside the 21.3% onsite figure (search-engine crawlers excluded), so the waste shows up on both sides of the click. Detection plus exclusion is how you cut that drain going forward.
The logic is simple. After all, you can't exclude what you can't see, and platform-reported metrics filter some invalid traffic but not all of it. Onsite, first-party detection catches much of what platform filtering misses, then feeds exclusion lists back into your campaigns. The earlier you catch a known source, the less you pay. Even so, a brand-new bot's first click has no history to match against, so it can't be pre-blocked. That residual is exactly what the refund arc recovers.
In 2025, fraud0's Unmasking the Shadows report measured 21.2% of in-ad impressions as invalid and 38.5% average viewability, with 31.4% of impressions on made-for-advertising sites. Mitigating wasted ad spend starts with onsite, first-party detection that surfaces the invalid activity platform filtering leaves behind, then excludes it from future campaigns.
Where does invalid traffic actually drain your budget?
Wasted ad spend isn't a single leak. It shows up in four distinct places, and each one costs you differently. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded), 9.75% of conversions invalid, and 31.4% of ad impressions landing on made-for-advertising sites. Understanding where the waste lands tells you what to fix first.
Notably, the most visible drain is fake clicks burning budget directly. Every invalid click consumes spend that should have reached a real prospect. These visitors never convert, and the fraud0 data shows why: invalid users averaged just 1.2 page views and 26-second sessions, versus 181 seconds overall. They land, they cost you a click, and they leave.
Meanwhile, the second drain is fake leads polluting your CRM. This one hides longer, because the damage surfaces downstream. In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions invalid (7.82% confirmed bots plus 1.92% suspected). Those fake conversions don't just waste the click. They mislead your optimization, because the platform learns to chase the audiences that produced them.
The third drain is made-for-advertising placements harvesting impressions. MFA sites exist to farm ad revenue, not to reach real buyers. In 2025, fraud0's Unmasking the Shadows report found 31.4% of ad impressions landed on MFA sites, paired with just 38.5% average viewability. You're paying for placement on pages built for bots, not customers.
The fourth drain is analytics distortion that misdirects future spend. This is the quiet compounding cost. When invalid users pad your volume and drag down your engagement averages, every decision built on that data tilts wrong. The real damage of invalid traffic isn't only the wasted click. It's that polluted data teaches your bidding algorithms to buy more of the same. You optimize toward the audiences that look active but never buy, so the waste compounds campaign over campaign rather than staying flat. Cleaning the data is what stops that loop.
What does click fraud protection actually do?
Click fraud protection is software that detects invalid clicks and automatically excludes the sources behind them, so more of your budget reaches real people. It works per platform, using each platform's own tag or pixel, not one list that covers all of them. Where an audience-exclusion integration exists (Google Ads, Meta, Microsoft, DV360/CM360, Criteo), it writes negative-audience lists and IP exclusions back into that account. For platforms without one, like TikTok and LinkedIn, the lever is controlling whether their pixel or tag fires for flagged visitors. The goal isn't blocking everything, which no tool can promise. Instead, it reduces the activity that can't convert by excluding sources you've already seen.
However, choosing a tool is its own decision, and the category is noisy. Our click fraud protection buyer's guide walks through what to look for, how detection methods differ, and which questions separate genuine protection from IP-blocking with a dashboard.
How do you reduce invalid clicks on Google Ads?
Google Ads has its own invalid-click filtering, but it works at the platform level and doesn't see what happens once traffic reaches your site. Pairing platform filtering with onsite detection narrows that gap. You surface the invalid activity, then push exclusions back into the account so known sources stop draining spend. New sources still appear, which is why recovery runs alongside.
The mechanics matter here, and they're specific to each platform. Our guide to stopping click fraud on Google Ads covers the exclusion workflow step by step, from spotting suspect patterns to applying IP and audience exclusions.
What about Meta, Microsoft, and TikTok?
Furthermore, Google isn't the whole picture, and the risk profile shifts by platform. Paid Social carried the highest repeat-bot share in the fraud0 data, with 71.6% of its bot sessions coming from returning bots. Each platform needs its own detection and exclusion approach, because the traffic behaves differently and the controls differ too.
Protect Meta, Microsoft and TikTok campaigns breaks down cross-channel protection so you're not leaving three platforms exposed while you guard one.

Arc two: how do you get refunds for wasted ad spend?
Refunds are the recovery side of the equation: reclaiming budget already lost to invalid activity, with evidence. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded), which means some of the clicks you were charged for were never real. Where that invalid activity is detected and documented, you can pursue recovery through the platform's process.
Invalid traffic is the biggest source of recoverable spend, but not the only one. Billing errors, overdelivery, and out-of-geo serving are recoverable too. See ad-spend overbilling.
Importantly, this is the arc fraud0 was built around, and it's where honesty matters most. Refunds aren't automatic, easy, or universal. They depend on what invalid activity is actually detected and on each platform's review and approval process. They're also not a fallback for when prevention fails. Because no detection can pre-block a brand-new bot's first click, some invalid traffic always slips through, so refunds are a permanent part of recovery. What we can do is make the invalid activity visible and help you build the documentation a claim needs.
In 2025, fraud0's Unmasking the Shadows report found 9.75% of conversions invalid (7.82% confirmed bots, 1.92% suspected). Where invalid activity is detected and documented, advertisers can pursue ad-spend recovery through platform processes. Outcomes depend on the evidence and the platform's review, and platforms such as Google typically return money as account credit rather than cash.
How do ad-spend refunds work?
Consequently, ad-spend refunds follow a process, not a complaint. You identify the invalid activity, document it with onsite evidence, and submit a claim through the platform's defined channel. The platform reviews it against its own standards, and where the activity qualifies, it issues an adjustment. There's no shortcut around that review.
The full mechanics, timelines, and what a strong submission looks like live in our ad-spend refund guide. Start there if recovering past spend is your priority.
What are the steps in the refund process?
The recovery process moves through five realistic stages, and none of them can be skipped. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded), so the invalid clicks you were charged for are usually there to document. Turning that into recovered budget is a sequence of detect, document, claim, review, and credit. Here's what each stage actually involves.
Step one is detect. You can't claim what you haven't found, so the process starts with onsite, first-party detection that flags invalid activity as it happens. This is where platform filtering falls short, because it doesn't see what traffic does once it reaches your site. Real-time detection captures the activity at the source.
Step two is document. However, detection on its own isn't a claim. You need a record showing what the invalid activity was, when it occurred, and how it was identified. Strong documentation captures the attributes that separate a bot from a buyer, logged at the time rather than reconstructed later from a platform report.
Step three is claim. With evidence in hand, you submit through the platform's defined channel, not an informal complaint. Each platform has its own process and its own standards for what it will review. The claim presents the documented invalid activity and ties it to the spend you're asking the platform to reconsider.
Step four is platform review. This is the stage outside your control, and it's why we never guarantee outcomes. The platform evaluates your submission against its own criteria, on its own timeline. A well-documented claim gives the review something concrete to assess, but the decision rests with the platform, not with you or with us.
Step five is the credit. Where the platform agrees, it issues an adjustment. As covered above, Google typically returns this as account credit toward future spend rather than cash back to your card. In our experience supporting these claims, setting that expectation early is what keeps the process honest. Stakeholders who expect a cheque are disappointed by a credit, even when the credit is a genuine win. The outcome is real recovery, just recovery that shows up as lower future media cost.
The honest framing holds across all five steps. A claim is only as strong as the evidence behind it, and even a strong claim depends on platform review. We make the invalid activity visible and help you document it. We don't, and can't, promise what the platform decides.
What evidence do you need for a refund claim?
Evidence is the difference between a claim that's reviewed seriously and one that isn't. A platform can't act on a hunch. It needs documentation showing the invalid activity, when it happened, and how it was identified, ideally from first-party, onsite detection rather than after-the-fact guesswork.
In our work supporting recovery claims, the strongest cases share a pattern: the invalid activity was logged onsite, in real time, with the attributes that distinguish a bot from a buyer, rather than reconstructed weeks later from a platform report. That's what turns a suspicion into something a review process can actually evaluate. Our guide to documenting invalid traffic as refund evidence shows exactly what to capture.
Is it a refund or a credit?
This trips people up, so let's be precise. Google Ads typically returns money for invalid activity as an account credit toward future spend, not as cash back to your card. The terms "refund" and "credit" get used loosely, but they mean different things for your books and your cash flow.
The credit-versus-refund distinction isn't a technicality. It changes how you value recovery internally. A credit reduces your future media cost rather than topping up the bank, so the win shows up as efficiency, not a cash refund. Framing it accurately keeps stakeholders from expecting a cheque that won't arrive. Our invalid-activity credits versus refunds explainer untangles the terminology in full.
What does ad spend recovery look like in practice?
Recovery isn't theoretical. In fact, real advertisers run both arcs and see measurable change. Consumer-health brand Uriach worked with fraud0 to clean up its campaigns and secure ad refunds, combining the mitigate-the-risk and recover-the-loss motions into one program. Where invalid activity was detected, evidence supported the recovery process.
The point of a case study isn't to promise the same outcome. It's to show the mechanism working end to end: detect, exclude, document, recover. Results depend on what invalid activity is present and on the platform processes involved.
Consumer-health advertiser Uriach worked with fraud0 to clean up its paid campaigns and secure ad refunds, running both the prevention and recovery motions together. Where invalid activity is detected and documented, advertisers can reduce future waste and pursue recovery of past spend, with outcomes dependent on the evidence and platform review.
Read the full story in our Uriach ad-spend recovery case study, including how the campaigns were cleaned up and what the recovery process looked like.
How is recovery different for agencies?
Agencies sit in a unique spot. Specifically, they manage budgets they don't own, and they answer to clients who expect every dollar to work. Surfacing invalid traffic isn't a confession that something went wrong. It's proof the agency is protecting client spend proactively, which is exactly what builds trust.
Ad-spend recovery for agencies covers how to run both arcs across a client portfolio, report on them transparently, and turn recovery into a reason clients stay.
How do you start recovering wasted ad budget?
Start by making the invalid traffic visible, because you can't fix or recover what you can't see. In 2025, fraud0's Unmasking the Shadows report found 21.3% of onsite traffic invalid (search-engine crawlers excluded) across 1.2 billion sessions, yet most of that waste never appears on a standard dashboard. First-party, onsite detection is the entry point to both arcs.
From there, the path is straightforward: detect the invalid activity, exclude the sources to reduce future waste, document what hit your campaigns, and pursue recovery where the evidence supports it. Prevention and refunds reinforce each other. The same detection that cuts tomorrow's waste builds the evidence for yesterday's, and for the residual that detection can never fully pre-block.
A quick reality check: not every account has a large recoverable loss, and not every claim succeeds. The first step isn't a refund request, it's measurement: find out how much of your traffic is actually invalid, then decide which arc matters more for your situation.
That's the job fraud0 was built for. We make wasted ad spend visible through onsite, first-party detection, then support evidence-based recovery where invalid activity is found. No guarantees on the outcome, just clarity on the problem and a documented path to act on it. If you suspect you're paying for traffic that can't convert, the honest next move is to look. To see your own numbers, contact the fraud0 team for a traffic assessment.




