Case Study UA

High Installs, Hidden Fraud: Uncovering Fraudulent Traffic Sold by UA Agencies

Case study: 80%+ of installs sold by a reputable UA agency were SDK-spoofed. How the audit found it and won the client a significant refund.

Share on social media

High install numbers don't always mean successful user acquisition. In mobile marketing, one of the biggest threats isn't rising CPIs, it's paying for installs that were never genuine users in the first place.

In this case study, we show how a European mobile app discovered that more than 80% of attributed installs were likely fraudulent, despite campaigns that looked healthy on the surface. What makes this one worth reading is where the traffic came from: it was sold by a reputable French user acquisition agency, not by an obscure network nobody had heard of. Behind the encouraging dashboards, the business faced an entirely different reality: retention was steadily declining, engagement stayed low, revenue failed to keep pace with rising install volumes, and the quality of new users raised serious concerns.

To understand what was happening, Scalebay ran a comprehensive traffic audit that revealed widespread indicators of mobile ad fraud. This case study explains how analysing attribution data, user behaviour and traffic patterns uncovered fraudulent installs that conventional performance reporting had failed to identify, and how the audit ended with a significant refund for the client.

The challenge: strong numbers, weak business

Like many app businesses in their early growth stage, the client measured campaign success primarily through install volume and cost per install. The traffic came through a well-known French UA agency with solid references, so nobody had a reason to look further. Although the numbers suggested strong performance, several business metrics started moving in the opposite direction.

The first pass through the data surfaced four problems:

  • Declining Day 7 and Day 30 retention
  • Low engagement from newly acquired users
  • Limited downstream conversions
  • Paid acquisition growing without any corresponding growth in business metrics

The campaigns kept delivering installs, but those installs were creating less and less value. The question became simple: were the campaigns attracting real users, or simply generating install volume? We already knew something was wrong.

The audit: a deep dive by source

Rather than relying on attribution dashboards alone, we performed a source-by-source audit of the client's acquisition traffic, the same approach we apply in our data and KPI work. The investigation focused on behavioural signals that often reveal fraudulent activity hidden beneath standard performance metrics.

The audit covered:

  • Partner and sub-partner performance analysis
  • Install timing distribution
  • Geographic validation
  • Retention cohort analysis
  • Click-to-install behaviour
  • Installation spike detection
  • Cross-platform attribution comparison

Instead of asking "how many installs were generated?", we asked a far more important question: "do these installs behave like genuine users?"

What we found

The analysis uncovered multiple independent indicators of sophisticated mobile ad fraud. A single anomaly rarely proves anything, but several consistent patterns across multiple traffic sources painted a compelling picture.

1. Unnatural install timing

One of the earliest warning signs was the time of day. Nearly 70% of all attributed installs occurred between midnight and 8:00 a.m. For a consumer app, installs normally peak during the day and evening, when people actually browse the stores and see ads. Across several sub-sources sold by the agency, between 70% and almost 90% of installs consistently arrived overnight, a pattern that is flatly inconsistent with real user behaviour.

2. Install spikes that defied normal usage

Healthy campaigns produce a relatively steady flow of installs through the day. Here, multiple sources generated sudden bursts, with a significant share of the daily volume landing within a few minutes. These recurring spikes appeared across different partners and time periods, which points to automated activity rather than consumer demand.

3. Traffic outside the intended market

The campaigns were designed to acquire users in France. The audit found installs originating from countries outside the target market, which nobody had asked for or expected. Unexpected geographic distribution is a common marker of invalid traffic, especially combined with abnormal timing and the other behavioural anomalies.

4. Attribution discrepancies

The strongest evidence came from comparing the attribution platform's data against the app stores' own reporting. More than 80% of attributed installs could not be reconciled with official platform data. That gap between reported and verified installs was the clearest sign that a large share of the acquisition activity was simply not real.

Identifying the root cause: SDK spoofing

Taken together, these signals aligned closely with a known form of mobile ad fraud: SDK spoofing. Unlike click fraud, SDK spoofing fabricates install events by simulating the communication between an app's SDK and the attribution platform. To campaign dashboards, these installs look legitimate. In reality, no user may ever have downloaded or opened the app. Because the fake events satisfy the attribution rules, advertisers can keep paying for fraudulent traffic for months while performance quietly deteriorates.

The fact that the traffic was resold by a reputable agency did not make it cleaner. The agency was buying from sub-networks it did not fully control, and the spoofed installs passed through unchecked. This is exactly the blind spot that Adjust's Fraud Prevention Suite and AppsFlyer's Protect360 are built to close: both include SDK-spoofing detection based on signed SDK communication and anomaly patterns, and both reject suspicious installs before they are attributed and billed. In this case, neither had been activated on the account.

The results

The investigation identified several independent indicators of fraudulent acquisition, and both the client and our team were surprised by their scale:

  • 80%+ of reported installs showed significant attribution discrepancies
  • Nearly 70% of installs occurred during abnormal night-time hours
  • 70 to 90% of installs from multiple sub-sources followed the same suspicious timing patterns
  • Multiple traffic sources displayed recurring installation spikes consistent with automated behaviour
  • Geographic inconsistencies pointed to activity outside campaign targeting
  • Several independent fraud indicators converged on large-scale SDK spoofing

The audit report was shared with the agency. Faced with the evidence, the agency issued a significant refund to the client for the invalid traffic, and the affected sub-sources were cut. Beyond the refund, the client came out with a far clearer understanding of traffic quality, and now assesses partner performance on behavioural data rather than install volume alone.

Lessons for our team and for mobile marketers

Install volume is only one measure of campaign performance, and often the least informative one. Mobile growth depends on acquiring users who engage, retain and generate long-term value, which is why our user acquisition work is judged on real events and payback, never on CPI. This case leaves a few lessons worth keeping:

  • High install numbers do not necessarily indicate healthy user acquisition.
  • Low CPI can conceal significant traffic quality issues.
  • A reputable partner is not a guarantee: audit the traffic, not the brand that sells it.
  • Behavioural analysis is often more valuable than acquisition volume alone.
  • Regular traffic audits can identify fraud before budgets are wasted, and give you the evidence to claim a refund when they are.
  • Attribution data should always be validated against store data and broader performance signals, and the MMP's fraud protection should be switched on from day one.

The most successful mobile marketing strategies do not aim to generate the most installs, but to acquire genuine users who contribute revenue and sustainable growth. Mobile ad fraud keeps evolving with the ecosystem, which makes traffic validation an essential part of every acquisition strategy. As this case shows, campaigns that look successful on the surface can hide serious inefficiencies beneath standard metrics.

At Scalebay, we believe sustainable mobile growth starts with trustworthy data. By combining user acquisition expertise, attribution analysis and ongoing traffic validation, businesses can make better decisions, protect their budgets and scale with confidence. If your install numbers look better than your business, talk to us, or read how we approach attribution and retention on the blog.

Scalebay

Read the full article

Pop in your details and we'll email you a one-click link to unlock the rest of this guide — no password needed.

No spam — just the link to finish reading.

Sending your unlock link…

✓

Check your inbox

We just emailed you a link. Click it and the full article unlocks right here.

Unlocking your article…

Most popular