DoubleVerify has identified more than 100 cases of ads.txt manipulation since the standard launched in May 2017, highlighting escalating threats to digital advertising integrity. The software platform issued an industry alert on May 22, 2025 — one week ago — warning of sophisticated schemes that exploit the ads.txt system to divert advertising revenue from legitimate publishers.
Get the PPC Land newsletter ✉️ for more like this
According to DoubleVerify's analysis, fraudsters have developed increasingly complex methods to manipulate ads.txt files, which enable publishers to publicly declare authorized inventory sellers. "Bad actors are exploiting ads.txt and advertisers often have no idea it's happening," said Gilit Saporta, Head of the DV Fraud Lab. The company documented a significant increase in such schemes during recent years as criminals adapt to exploit industry safeguards.
The scale of deception extends far beyond simple manipulation. DoubleVerify's Fraud Lab uncovered Synthetic Echo, a network comprising over 200 AI-generated websites that monetize through multiple supply-side platforms and exchanges. These sites produce low-quality artificial intelligence content while using deceptive domain names such as espn24.co.uk, nbcsportz.com, and cbsnewz.com to mislead programmatic platforms and buyers.
Timeline
May 2017: IAB Tech Lab launches ads.txt standard to prevent unauthorized advertisement inventory sales
Late 2018: DoubleVerify identifies first major ads.txt exploitation scheme involving bot-generated traffic and content scraping
January 2025: DoubleVerify publicizes initial findings about Synthetic Echo network
January 15, 2025: Wired publishes investigation into AI-generated content mills, prompting legal responses from affected publishers
May 22, 2025: DoubleVerify issues comprehensive industry alert documenting over 100 cases of ads.txt manipulation since 2017
Technical sophistication reveals systematic approach
The Synthetic Echo investigation reveals sophisticated technical methods employed by fraudsters. According to DoubleVerify's detailed analysis, the network demonstrates near-identical ads.txt files replicated across multiple properties, exposing how criminals scale operations by cloning authorized seller lists. The investigation found that many Synthetic Echo sites copied ads.txt entries directly from reputable publishers, including CNN.com and Daily Mirror Sri Lanka.
This plagiarism represents what DoubleVerify terms "programmatic impersonation" — a multi-layered deception designed to trick supply-side platforms and demand-side platforms into recognizing fraudulent sites as legitimate networks. The copied ads.txt entries make these sites appear trusted by major advertising platforms, enabling them to divert advertising spend from authentic publishers.
The technical examination revealed specific operational patterns. Sites within the Synthetic Echo network employ consistent characteristics of automated content generation, including standardized formatting, repeated linguistic patterns, and systematic content aggregation methods. These indicators provide crucial data points for identifying similar operations across the digital advertising ecosystem.
Financial impact reaches major advertisers
The financial implications extend beyond direct monetary losses. When advertisements appear on fraudulent sites, they not only misappropriate advertising budgets but potentially damage brand reputation through association with untrustworthy content. Programmatic advertisements from prominent companies including Asana, Oracle, Net-A-Porter, Sephora, and Kalahari Resorts appeared on these deceptive sites during monitoring periods.
According to DoubleVerify's findings, the fraudulent properties distribute content through various sell-side platforms and exchanges with minimal human oversight. These sites frequently employ aggressive advertisement placement strategies, creating cluttered layouts that diminish user experience and campaign effectiveness while maximizing revenue extraction.
The discovery represents a significant milestone in understanding evolving digital advertising fraud. It demonstrates how technological advancement can be exploited for deceptive purposes while simultaneously providing insights into potential detection and prevention methodologies.
Historical context of ads.txt exploitation
The ads.txt standard launched in May 2017 by the IAB Tech Lab as a solution to prevent unauthorized advertisement inventory sales. Publishers host text files that transparently list companies authorized to sell their inventory, either directly or indirectly through resellers. Programmatic platforms process these files to qualify inventory purchases, checking publisher domains against ads.txt lists before completing transactions.
However, DoubleVerify documented various exploitation methods since the standard's inception. In late 2018, the company identified a network designed to generate high volumes of non-human traffic across hundreds of websites. That scheme involved bots scraping content from legitimate websites to create spoofed sites with URLs designed to appear original, then selling fraudulent advertisement slots through authorized resellers listed on legitimate publishers' ads.txt files.
The evolution of these schemes demonstrates increasing sophistication. Early exploitation focused primarily on simple spoofing techniques. Current methods involve complex artificial intelligence content generation, systematic ads.txt plagiarism, and coordinated network operations spanning hundreds of properties.
Industry response and detection challenges
The identification of Synthetic Echo prompted legal responses from affected publishers. After DoubleVerify publicized information about the network in January 2025, a Wired report prompted several news publishers whose brands were misused to announce plans for legal action against the fraudulent operators.
Detection challenges persist as fraudulent operations adapt to existing safeguards. Static prevention methods such as manual blocklists prove insufficient against rapid deployment capabilities of modern fraudulent operations. The investigation underscores the necessity for dynamic, automated detection systems capable of identifying and blocking fraudulent domains in real-time.
DoubleVerify emphasizes that ads.txt manipulation occurs through multiple vectors. Fraud often enters through direct publisher relationships, where criminals posing as legitimate companies persuade publishers to add them as authorized resellers by promising unique technology or exclusive demand. Publishers focused on maximizing yield may accept these claims without full visibility into potential risks.
Bloated files create vulnerability pathways
The problem compounds when publishers add new lines to ads.txt files without removing outdated entries, causing files to become bloated. This complicates verification processes and allows unauthorized sellers to persist in the ecosystem, increasing fraud risk. Legitimate resellers with inadequate vetting standards unknowingly enable bad actors to operate across their networks, allowing fraud to scale.
Publisher networks face particular challenges when ads.txt files are copied across multiple properties. While standardization streamlines operations, it amplifies risk when networks include questionable resellers in ads.txt files. That reseller automatically appears across other publishers in the network, and programmatic platforms bulk ingest ads.txt files for efficiency, allowing fraudulent sellers to spread unchecked.
Best practices emerge from investigation
DoubleVerify's analysis led to comprehensive best practice recommendations for publishers and programmatic platforms. Publishers should limit ads.txt entries to trusted partners, maintaining only direct sellers or verified resellers with clear contractual relationships. Regular auditing and validation of ads.txt files helps identify syntax errors and unexpected changes.
The company recommends using ads.txt alongside Sellers.json for additional security and transparency. Publishers should recognize that ads.txt alone does not constitute complete protection against sophisticated fraud schemes attempting to bypass these safeguards.
Programmatic platforms should verify ads.txt integrity before ingestion, cross-checking entries for duplicate or suspicious listings while flagging unexpected resellers or excessive intermediaries. Detection and blocking of copied or manipulated ads.txt files helps identify cloned files across multiple domains, a common fraud signal.
Why this matters
The discovery of systematic ads.txt exploitation carries significant implications for marketing professionals. The revelation that over 100 cases of manipulation have occurred since 2017 indicates that current verification systems may have blind spots that sophisticated fraudsters actively exploit.
Marketing teams must reassess their media buying strategies, particularly regarding programmatic advertising. The Synthetic Echo case demonstrates that fraudulent sites can successfully attract major brand advertisements, suggesting that existing brand safety measures may be insufficient against evolving threats.
The financial implications demand attention from marketing leadership. When advertising budgets flow to fraudulent sites, return on investment calculations become fundamentally flawed. Campaign performance metrics become contaminated with artificial data, making optimization decisions based on false information.
Marketing professionals should consider implementing multiple layers of verification rather than relying solely on single-point solutions. The investigation suggests that combining ads.txt verification with additional authentication methods such as Sellers.json and OpenRTB SupplyChain Object provides more comprehensive protection.
The revelation also highlights the importance of working with independent advertisement fraud vendors for additional verification. As fraudulent operations become more sophisticated, relying exclusively on platform-provided safeguards may prove inadequate.
Discussion