In January 2021, Bob Hoffman aimed a short argument less at ad fraud than at the confidence of the people who insist it is handled. The SolarWinds breach had just been revealed — state-sponsored hackers inside roughly 250 US government agencies and companies, undetected by Cyber Command, the NSA, and the Department of Homeland Security. If systems defended at that level can be entered without anyone noticing, what should we assume about the software auditing a $300 billion ad marketplace that runs on machines?

He argues from logic rather than measurement, and says so — he is not a computer scientist, cannot read the code, and cannot settle the data fight from outside it:

  • The industry side — trade organizations, agencies, their security consultants — reports ad fraud as a minor problem that is being well defended and shrinking annually.
  • Independent researchers put it in the tens of billions, growing and getting harder to identify.
  • Both produce metrics. Hoffman’s move is to stop trying to referee them and reason from the parts nobody disputes.

His premises are mostly uncontested:

  • Online advertising trades over $300 billion a year through computer systems.
  • State-sponsored hackers have demonstrated the ability to penetrate some of the most “secure” systems in the world without detection.
  • Every person, business, or agency ever hacked had authoritative assurances that it was secure — until it turned out not to be.
  • Programmatic buying, roughly 80% of online ad activity, has been shown to be astoundingly simple to game.
  • There is no international governing authority for online ad fraud, and so no cross-border penalty for committing it.

The inference is short. Fraud detection is software; software defended by the NSA’s budget was beaten quietly; therefore detection can be fooled, and a lot of what it reports may just be what remains after the sophisticated actors have taken their share. Then add the incentive: billions available, a tiny chance of detection, no consequence if caught anyway. He does not argue that governments are inside the adtech ecosystem — only that it would be amazing if they weren’t.

His conclusion is an accusation of overmatch rather than of conspiracy. The commercial fraud-detection firms are seriously outmatched, and the trade bodies and agencies that vouch for them are no more reliable than the vendors they rely on — so ad fraud is probably both larger and harder to see than anyone thinks it is.

The spread in the essay’s own links is nearly the whole point. CHEQ’s 2020 report puts global digital ad fraud at $35 billion; the Type A Group report he cites puts it over $60 billion. Same year, same phenomenon, different estimator — and the “shrinking” side of the ledger comes from the ANA, the industry’s own trade body.

He closes with two questions that outlast the news that prompted them. If you were a bad guy who could easily steal billions with a tiny possibility of detection and no possibility of consequences even if you were detected, why wouldn’t you? And if you are a marketer spending substantially on digital advertising, what reason do you have for believing the metrics you are getting?