Competitor click fraud is the hardest kind to catch: a real person, on a real device, clicking a handful of times a day. Here is how to confirm it from your own account data, what Google will and will not do about it, and how to actually stop it.
The AdProtektor Team10 min read
Competitor click fraud is a rival repeatedly clicking your ads to exhaust your daily budget and push you out of the auction. It is the fraud type advertisers complain about most and the one automated filtering is worst at catching — because there is nothing automated about it. A real person, on a real device, clicking a handful of times a day leaves no bot signature to find.
This guide covers how to confirm it from your own account data, what Google will and will not do, and what actually stops it.
Why this one is different
Most click-fraud defenses are looking for volume: hundreds of clicks, superhuman timing, known bot signatures, data-center IP ranges. A competitor produces none of that. They click five to twenty times a day, from a real browser on a real device, sometimes scrolling the page a little to look plausible. To any filter built around volume or automation detection, they are simply a user who did not convert.
The economics are brutally simple
Suppose you bid on a keyword at $30 a click with a $300 daily budget. A rival clicking ten times — under a minute of effort — exhausts your entire day before lunch. Your ad stops serving; theirs runs unopposed for the rest of the day. They paid nothing. You paid $300 and got no leads.
This is why small budgets on high-CPC keywords are the most exposed. Legal services, insurance, locksmiths, HVAC, addiction treatment, B2B SaaS — anywhere a handful of local rivals compete over the same expensive terms and all know exactly who each other are.
How to confirm it from your own data
No single signal is proof. What identifies a competitor is the combination, and specifically the pattern over time:
Business hours only. Clicks cluster between roughly 9am and 6pm on weekdays and fall away at night and on weekends. Bots do not take weekends off.
Your most expensive keywords. The clicks concentrate on your highest-CPC terms — precisely the ones a rival is also bidding on.
Geographic proximity. Traffic from the city or region where a known competitor operates, that never turns into an enquiry.
Seconds on page, no scroll. They land and leave. No pricing page, no contact form, no click on the phone number.
Same behavior, new address. After a block they reappear from mobile data, a home connection, or a VPN — identical behavior, brand-new IP.
Google Ads reporting will not tell you who is behind a click. The invalid-clicks column shows only what Google already filtered, which by definition excludes the sophisticated cases. Confirming this requires visitor-level data from your own site — behavioral signals, repeat-visitor matching, and ideally session recordings that show whether there is any real human engagement at all.
What Google does — and where it stops
Google filters traffic it identifies as invalid and credits those clicks automatically, usually within days. That machinery is genuinely good at the obvious cases: duplicate clicks, crude bots, known bad networks. A person clicking manually a few times a day is not an obvious case.
You can open a support case and request a manual review. Those go better when you bring evidence: exact date ranges, the affected campaigns and keywords, repeat-source data, and recordings showing no human engagement. It is a request for review, not a guaranteed credit.
The refund misconception
Google does not refund the click that triggered a third-party tool’s detection. No protection product can make it. The value is in preventing the repeat clicks from that source, plus producing the evidence that makes an invalid-traffic claim credible.
Why IP blocking does not hold
Blocking the address is the intuitive first move, and it is worth doing — it will stop a lazy attacker. It will not stop a motivated one, for three reasons:
Switching networks is trivial. Office Wi-Fi to mobile data, or working from home for a day, produces an address your blocklist has never seen. A VPN does it in one click.
The cap is real. Google Ads allows 500 IP exclusions per campaign, and every entry on that list is an address that already cost you money.
You can block real customers. ISPs assign residential addresses dynamically. The address you block today may belong to a genuine prospect next week — and blocking whole ranges multiplies that risk.
The competitor changes networks, but not behavior. That asymmetry is the entire opening: identify the person rather than the address, and switching IP stops helping them.
What actually works
Because the attacker’s behavior is stable while their network is not, detection has to key on the behavior. Person-based detection builds a profile from how the visitor actually behaves — mouse movement, click timing, scroll cadence, device and browser characteristics, screen properties, language, timezone, navigation path — and clusters visits into one identified person across IPs, devices, and browsers.
Once you have identified the person rather than the address, IP exclusion becomes useful again: it is a good enforcement action, applied after the fact, rather than a detection mechanism you are relying on to work.
A practical stack against a persistent competitor looks like this:
Tighten geo-targeting to presence rather than presence-or-interest, and turn off Search Partners and Display if they are not deliberate choices.
Add person-based detection so the same individual is recognized across networks and devices.
Apply click-frequency rules so repeat clicks from one person inside a window are blocked automatically.
Auto-sync confirmed sources to your Google Ads IP exclusion list so enforcement keeps up without manual work.
Keep session recordings and per-click classifications as evidence — for verifying your own blocks and for supporting invalid-traffic claims.
AdProtektor is built around exactly this: it scores every visit on 150+ behavioral and device signals, classifies each visitor as real, crawler, bot, competitor, or click farm, links multiple IPs and devices to one person, and syncs confirmed fraud sources to Google Ads IP exclusions and Meta exclusion audiences automatically. Legitimate crawlers are always whitelisted, and every decision is reviewable with session replay and reversible in one click.
Aggregated across the AdProtektor customer base, lifetime to date: 2.8M+ clicks analyzed, $840K+ of ad budget protected, 500+ active domains, and an 18% average fraud rate blocked.
Related reading
What is click fraud? — the full picture, including the other four attacker types.
You can start a free trial and see how much of your paid traffic is fraud — on your real campaigns, the same day you install it.
FAQ
Frequently asked questions
How do I know if a competitor is clicking my Google Ads?
Look for a cluster of signals rather than any single one: clicks concentrated during business hours and dropping off at nights and weekends, focused on your highest-CPC keywords, from a location where a known rival operates, with only seconds of time on page and no scrolling — and never a conversion. Google Ads own reporting will not identify who is behind a click, so confirming it requires visitor-level data from your own site: behavioral signals, repeat-visitor matching, and ideally session recordings that show whether there is any genuine human engagement.
Is it illegal for a competitor to click my ads?
It sits in a legal grey area that varies by jurisdiction. Deliberately clicking a rival’s ads to exhaust their budget can potentially constitute fraud, tortious interference, or a computer-misuse violation in many countries, and large-scale operations have been prosecuted. This is not legal advice. In practice, enforcement is rare because proving who was behind a specific click is very hard, so nearly all advertisers treat it as a budget-protection problem to solve technically rather than a case to litigate.
Will Google refund clicks from a competitor?
Sometimes, but do not count on it. Google automatically filters traffic it identifies as invalid and credits those clicks, but its filtering is conservative and retroactive — and a competitor clicking manually a few times a day looks like a normal user to it. You can open a support case and request a manual review with evidence, which is more likely to succeed when you can supply timestamps, repeat-source data, and session recordings showing no human engagement. Critically, Google does not refund the click that triggered a third-party tool’s detection; the savings come from preventing the repeat clicks.
Can I just block their IP address?
You can, and it is worth doing as a stopgap, but it rarely holds. Google Ads allows up to 500 IP exclusions per campaign, and a competitor only needs to switch from office Wi-Fi to mobile data, work from home, or connect through a VPN to arrive from an address you have never seen. Worse, blocking a broad residential range risks blocking genuine customers whose ISP later assigns them the same address. IP exclusion works best as an enforcement action applied after something else has identified the person.
AP
The AdProtektor Team
Ad-fraud researchers & engineers
AdProtektor builds person-based AI click-fraud protection for Google Ads and Meta. This article is written by the same team that ships the detection engine — engineers and analysts who look at invalid-traffic patterns across millions of ad clicks every week.
See how much fraud is hiding in your traffic — in 5 minutes.
Most accounts find that 10–20% of paid clicks are bot, click-farm, or repeat-offender traffic. Start your free trial — the first numbers come back the same day you install.