Mobile ad fraud: the lessons from Uber's own lawsuit
By UA Ledger staff — Archive date: 6 min read

Mobile ad fraud rarely needs sophistication to work, and Uber's own lawsuit against its marketing partners still teaches the clearest lesson on it.
The most instructive mobile ad fraud case most teams will read about this year is not new. It resurfaces periodically because it keeps teaching the same lesson better than any vendor benchmark deck. The dispute between Uber and its onetime marketing partners is closing in on a decade old, and the mechanics inside it still map cleanly onto the fraud risks a 2026 UA team is most likely to face.
The story surfaced through an unusual route. Phunware, a mobile app development and marketing agency, sued Uber over unpaid invoices. Uber responded with a cross-complaint alleging that Fetch, its primary marketing agency at the time, and the ad networks Fetch used had been running fraudulent traffic against Uber's install campaigns for years. The dispute never needed a sophisticated forensic breakthrough to make its point. It needed Uber to look at what happened to its own numbers once it stopped paying for the traffic.
Two mobile ad fraud techniques, neither exotic
The fraud alleged in the case took two familiar forms. The first was click spamming, sometimes called click flooding: generating large volumes of clicks unconnected to any real user interest in the app, then claiming credit for whichever installs happened to follow within an attribution window regardless of cause. The tell is rarely subtle once someone looks for it. Time-to-install distributions that cluster suspiciously, and click-through rates that resemble nothing close to genuine engagement, are the classic signatures, and they sat in plain sight in Uber's data.
The second was domain spoofing. Ads reportedly ran on low-quality and pornographic websites, then came back through the supply chain reported as if they had run inside legitimate, well-known apps such as Temple Run 2 and Sonic Dash. This is fraud that lives entirely in the reporting layer. The ad itself might have run somewhere real; the app it claims credit for running inside is a fabrication.
A UA team relying on aggregated network reporting rather than SDK-level, app-by-app placement data has little way to catch this from the dashboard alone.
The tell that made the case
What makes this mobile ad fraud case worth teaching over more technically elaborate ones is what happened after Uber cut Fetch loose. Organic installs rose by almost exactly the volume that paid installs fell. That is the signature of a channel manufacturing the appearance of paid volume rather than generating any of it. If an agency or network's traffic is real incremental demand, killing it should produce a net loss in total installs. If the traffic was fraudulent, cutting it barely moves total volume, because the paid installs were never additive to begin with. Counted, not caused.
This is the argument analyst Eric Seufert made when he wrote up the case at the time, and it holds up. The fraud here was not a technically sophisticated scheme run by criminal specialists; it was ordinary exploitation of weak oversight by a trusted vendor that faced no real accountability for the quality of what it delivered. Uber paid for a metric rather than an outcome, and the vendor supplied the metric.
Why this still matters in 2026
Attribution has changed considerably in the decade since the case began. SKAdNetwork and AdAttributionKit have closed off some of the crudest attribution manipulation on iOS. But the underlying failure mode, a team trusting reported numbers from a paid partner without an independent check, has not gone away, and if anything it has more surface area than it used to. Every new ad placement that Meta or Google or Apple opens adds another reporting path a measurement team has to trust or verify, and so does every new creative-generation pipeline that increases the volume of variants running at once. Verification does not scale automatically with volume; someone has to build it in deliberately.
A short audit any team can run this quarter
- Pull time-to-install distributions by source for the last full month and flag any partner whose curve looks unnaturally tight or fast.
- Check click-through rate against install rate by partner; a source with an implausibly high click volume relative to installs is a click-spamming candidate, not a targeting success.
- Cross-reference a sample of SDK-reported placement IDs against a partner's own claimed inventory list, rather than trusting network-level rollups.
- Run a genuine holdout: pause a mid-sized paid source for two weeks and watch organic volume. If organic rises by close to what paid falls, the paid source was not adding much.
- Put this audit on a recurring calendar rather than a one-off exercise triggered by a bad quarter.
None of these steps require new tooling or vendor spend. They require the same thing Uber's case ultimately came down to: someone willing to look past the reported number and ask what it would take to fake it, then check whether that is what happened.
Why old fraud patterns keep resurfacing under new names
It is tempting to treat mobile ad fraud as a solved problem in markets where SKAdNetwork and AdAttributionKit have limited the granularity of what a network can even claim credit for on iOS. That framing understates how much of the fraud in the Uber case was never really about the mechanics of attribution. Click spamming worked because Uber's team trusted volume numbers without checking the quality signals sitting right next to them. Domain spoofing worked because nobody cross-checked a network's claimed placement list against where impressions were actually rendering. Both failures are organisational rather than technical, and organisational failures do not go away when a platform tightens its attribution model. They simply move to whatever part of the funnel still relies on a partner's self-reported number.
That part of the funnel, in 2026, is increasingly the creative supply chain rather than the attribution layer. As more UA teams route a larger share of their variant volume through third-party AI creative vendors and network-managed automated bidding products, the number of self-reported performance claims a measurement team has to independently verify has grown, even as the attribution mechanics underneath have become more privacy-preserving and harder to manipulate directly. A vendor claiming a creative variant is driving strong incremental performance is making the same kind of claim Fetch made about its paid traffic: a number that sounds credible and is expensive to verify, unless someone builds verification into the process by default rather than treating it as optional due diligence reserved for when results look wrong.
The Uber case is worth re-reading periodically for exactly this reason. It is not a story about a uniquely sophisticated fraud scheme from a bygone era of mobile advertising. It is a story about what happens whenever a team stops asking a trusted partner to prove a number rather than simply report it, and that condition is just as easy to recreate today as it was back when the lawsuits started.
Related archive reading
These articles provide related context and remain subject to their stated review status.
Featured
Related posts
measurement
media buying
·2 min read
Murka: an attribution-window change is also a measurement change
measurement
media buying
·3 min read
MobilityWare: splitting UA and creative still requires a shared acceptance contract
measurement
media buying
·3 min read
Mamboo Games: define migration acceptance before celebrating a growth change
measurement
media buying
·3 min read
Magic Tavern: require placement evidence before making CTV a performance channel
More from the Measurement desk
measurement
platforms
·2 min read
AppLovin Ad Review drops user-level journeys for aggregate-only reporting
measurement
platforms
·2 min read
Apple adds an EU alternative ATT prompt from iOS 27.2 — mandatory in five markets
measurement
platforms
·1 min read
When to turn rewarded ads off for payers (and how to measure the loss)
measurement
platforms
·1 min read