What is recycled/stolen information - lead gen fraud - Impact
Close Technique Button

Lead gen fraud

Recycled/stolen information

Bad actors that defraud lead gen campaigns will submit either illegitimate information (a nonexistent person) or recycled/stolen legitimate information. In the latter case, real peoples’ personally identifiable information (PII) is bought or captured through fake lead forms and then recycled to collect cost-per-lead (CPL) payouts from multiple advertisers. This technique bypasses data validators and defrauds advertisers of their performance spend. It also damages their brand reputation among the real audience members whose information is stolen, especially when the advertiser attempts to contact a person whose PII was stolen or recycled.

Technique Left Arrow 2
Technique Right Arrow

How they do it

  1. Malicious publisher has registered for advertiser’s lead gen campaign
  2. Malicious publisher buys stolen information from a data breach on the black market
  3. Malicious publisher then sends bot traffic through their own webpage on to advertiser’s website
  4. Malicious publisher populates advertiser’s form fill with the stolen PII
  5. Malicious publisher’s bot traffic submits fraudulent lead
  6. Advertiser attributes credit to malicious publisher, even though they provided an illegitimate lead, and pays them a (generally high) percentage of revenue
  7. Malicious publisher uses the same user’s info to replicate this process across many CPL advertisers and amplify their earnings
Recycled/stolen information
Next

Get in touch