HUMAN Security Disrupts Large-Scale CTV Ad Fraud Operation 'NewsJunkie'

  • HUMAN Security's Satori team identified and disrupted a coordinated CTV device spoofing operation called NewsJunkie.
  • The fraud involved hundreds of millions to nearly two billion invalid CTV bid requests per day per seller at its peak.
  • NewsJunkie exploited structural weaknesses in CTV advertising, including limited JavaScript signals for detection.
  • Two techniques were used: SSAI-based spoofing and residential IP routing with forged device information.

HUMAN Security's disruption of NewsJunkie highlights the growing complexity and sophistication of ad fraud in CTV environments. The operation exploited structural gaps in CTV advertising, where limited JavaScript signals make detection challenging. This case underscores the need for comprehensive supply chain visibility to ensure the integrity of digital advertising transactions.

Fraud Evolution
How threat actors will adapt their techniques in response to the disruption of NewsJunkie, particularly through migration to new app IDs and device strings.
Industry Response
Whether other security firms will enhance CTV fraud detection capabilities following this high-profile case.
Supply Chain Visibility
The pace at which the digital advertising industry adopts end-to-end supply chain visibility to prevent similar fraud operations.