HUMAN Security Disrupts Large-Scale CTV Ad Fraud Operation 'NewsJunkie'
Event summary
- HUMAN Security's Satori team identified and disrupted a coordinated CTV device spoofing operation called NewsJunkie.
- The fraud involved hundreds of millions to nearly two billion invalid CTV bid requests per day per seller at its peak.
- NewsJunkie exploited structural weaknesses in CTV advertising, including limited JavaScript signals for detection.
- Two techniques were used: SSAI-based spoofing and residential IP routing with forged device information.
The big picture
HUMAN Security's disruption of NewsJunkie highlights the growing complexity and sophistication of ad fraud in CTV environments. The operation exploited structural gaps in CTV advertising, where limited JavaScript signals make detection challenging. This case underscores the need for comprehensive supply chain visibility to ensure the integrity of digital advertising transactions.
What we're watching
- Fraud Evolution
- How threat actors will adapt their techniques in response to the disruption of NewsJunkie, particularly through migration to new app IDs and device strings.
- Industry Response
- Whether other security firms will enhance CTV fraud detection capabilities following this high-profile case.
- Supply Chain Visibility
- The pace at which the digital advertising industry adopts end-to-end supply chain visibility to prevent similar fraud operations.
Related topics
