Home Online Advertising Why The DOJ Finally Cracked Down On Ad Fraud

Why The DOJ Finally Cracked Down On Ad Fraud

SHARE:

Until now, if an ad fraud scam was uncovered, the criminals behind it would usually fade back into the shadows with impunity, and shortly thereafter, they’d be back at it again – the seemingly eternal game of Whac-A-Mole.

This time, there’s accountability.

Two global botnets, Methbot and 3ve, are no more, and there are real people facing charges.

On Tuesday, the Department of Justice unsealed indictments against eight men from Russia and Kazakhstan accused of running the schemes, which collectively sucked millions of dollars out of the advertising ecosystem over several years.

Three of the accused perpetrators are awaiting extradition, and the remaining five are still at large. They’ve been charged with 13 counts, including money laundering, wire fraud, computer intrusion and aggravated identity theft. [Read the indictment here.]

The Federal Bureau of Investigation collaborated with White Ops, Google and a group of other ad tech companies to dismantle the operations. Methbot was shut down in December 2016, close to the time White Ops went public with the more than 4,000 compromised IP addresses involved in the plot.

The 3ve botnet, which exploited a combination of counterfeit websites, malware, a fake ad network and seats on legit exchanges to do its bidding, was dismantled in October. (Fun fact: “3ve,” pronounced “Eve,” is a portmanteau of “three,” for the three sub-operations within 3ve, and the word “evasion.” Buzzfeed has a detailed report on 3ve’s crackdown.)

But the consequences of this ad fraud campaign are different, said White Ops CEO Sandeep Swadia: “There are handcuffs involved.”

But why now and why is the DOJ interested in this case? Ad fraud has been plaguing the ad industry since the Internet was born.

It came down to two factors: actionable data and a willingness to act, said Tamer Hassan, CTO and co-founder of White Ops.

After White Ops published its paper on Methbot in 2016, federal law enforcement decided it had enough data and materials for the FBI Cyber Division to start tracking other ad fraud operations.

The amount of money involved clearly also piqued the FBI’s interest. The 3ve investigation could shed light on where the cash goes once it’s been stolen.

“When you hack 1.7 million machines at any given time, what else can you do with it? When you make this kind of money, where else can you invest? That is TBD,” Swadia said. “But there are so many downstream possibilities that curbing that flow of money to these guys is the most important thing. That’s why the DOJ was very keenly involved in doing this at a global level.”

Another motivator was the “sheer sophistication and ambition” of the 3ve fraud scheme, which was “metastasizing across the entire ecosystem,” Swadia said.

Shutting down Methbot was a matter of publishing IP addresses to blacklist, but the 3ve case required bigger guns. Simply shutting it down would have tipped off the perps. That’s why killing 3ve required a coordinated effort between the FBI, cybersecurity experts and the ad industry.

And now that there’s a real deterrent against ad fraud, the ad industry has one of the most important tools it was missing to win the war against ad fraud.

“The key here is having consequences,” said Per Bjorke, a product manager for ad traffic quality at Google, who worked closely with the DOJ and White Ops on the takedown. “People are going to now think twice, because they could end up getting arrested and extradited out of their country.”

And now that the ball is rolling, we could see more activity in the year to come, said Amy King, VP of product marketing at fraud detection company Pixalate.

“This case sets a precedent for holding fraudsters accountable,” King said, “We believe there will be more to come in 2019.”

The DOJ did not respond to questions in time for publication.

Tagged in:

Must Read

Is Agentic Commerce An Oasis Or Mirage?

For companies like Shopify, Criteo and Instacart, and even for giants like Amazon and Walmart, all of which are all in on agentic commerce investments, figuring out if the agentic oasis is real and has a place for them is priority No. 1.

PubMatic’s Agentic AI Is Going Beyond Direct Deals

PubMatic has run more than 30 fully autonomous, end-to-end agentic campaigns through the SSP’s AgenticOS platform, in addition to more than 1,000 direct publisher deals.

The Trade Desk Has A Grand Vision, But Needs A New Breed Of CMO To Make It A Reality

TTD CEO Jeff Green laid out the DSP’s plan for winning in a new world of advertising that – AI aside – necessitates major changes in how marketers behave.

Privacy! Commerce! Connected TV! Read all about it. Subscribe to AdExchanger Newsletters

A Publisher Didn’t Get Its UID2 Setup Right. The Trade Desk Didn’t Notice. What Went Wrong?

TTD confirmed that this CTV publisher’s errors would have made its UID2s useless for ad targeting. But TTD also said it wouldn’t have had enough information to flag the issue.

Criteo Faces Tough Headwinds Until Agentic AI Ad Revenue Materializes

Criteo shares dropped by 20% Wednesday morning after the company reported shaky Q1 earnings and revised its guidance downward for the rest of the year.

Disney’s New CEO Is Focused On Two E’s: Engagement And ESPN

On Wednesday, Josh D’Amaro led his first earnings call as the new CEO of Disney. The company closed last quarter with $25.2 billion in revenue, a 7% year-over-year increase. Disney Entertainment advertising revenue rose 5% YOY, but ESPN ad revenue was down 2% YOY, although subscription and affiliate revenue was up 6%.