Airbridge
Customers
Log InGet Started Free
Back to Glossary
D

Device ID reset fraud

A
Airbridge
May 20, 2024·Updated July 13, 2026·4 min read
CategoryMobile Ad Fraud
Also known asDevice ID spoofing, IDFA reset fraud
RelatedSDK spoofing, Click fraud, Install fraud, Phone farms, Click injection
AffectsAttribution accuracy, ad spend efficiency, fraud detection systems

What is Device ID reset fraud?

Device ID reset fraud is a mobile ad fraud technique in which a fraudster resets or spoofs the unique device identifier on a real or compromised mobile device to make it appear as a new, previously unseen device. This allows the fraudster to repeatedly bypass fraud detection systems that rely on device ID blacklists or install deduplication logic. The result is fraudulent installs, fake accounts, and illegitimate ad revenue generated from the same physical device cycling through multiple identities.

How it works

Device ID reset fraud exploits the way mobile attribution systems use device identifiers, such as GAID (Google Advertising ID) on Android and IDFA (Identifier for Advertising) on iOS, to track and attribute installs and in-app events.

Gaining Device Access

Fraudsters typically obtain root access to a device through rooting (Android) or jailbreaking (iOS). This elevated access allows them to bypass operating system restrictions and directly modify device-level identifiers. On Android, this can involve altering the GAID, IMEI (International Mobile Equipment Identity), or MAC (Media Access Control) address. On iOS, IDFA manipulation became more restricted after Apple introduced App Tracking Transparency (ATT) in iOS 14.5, making device-level spoofing harder but not impossible on jailbroken devices.

Cycling Device Identities

Once root access is established, the fraudster uses specialized software to reset or generate a new device identifier. Each reset produces what appears to attribution systems to be a completely new device. The fraudster then triggers an ad click, installs the target app, and potentially completes post-install events to claim a cost-per-install (CPI) or cost-per-action (CPA) payout. The cycle repeats continuously on the same physical hardware.

Operating at Scale with Phone Farms

Device ID reset fraud is frequently deployed in phone farms, where banks of physical devices are operated simultaneously. Each device can cycle through dozens or hundreds of fresh identities, generating a high volume of fraudulent installs from a relatively small number of devices. This makes the fraud difficult to detect through device-level signals alone, since each reset produces a seemingly legitimate new device fingerprint.

Detection Signals

Measurement platforms detect device ID reset fraud through several behavioral signals. Abnormally short click-to-install times (CTIT) indicate automated rather than organic behavior. Devices showing an unusually high number of first-time installs across a short time window are flagged as suspicious. Inconsistencies between device metadata, such as mismatched hardware fingerprints, OS versions, or IP address patterns, also reveal fraudulent resets. Duplicate IP addresses appearing across many attributed installs are a strong indicator of coordinated device ID cycling.

Why it matters

Device ID reset fraud directly inflates install counts and drains advertising budgets by generating payouts for installs that have no genuine user behind them. Advertisers paying on a CPI or CPA model lose budget to fraudulent conversions that will never produce real lifetime value. Beyond wasted spend, fraud skews campaign performance data, making it harder to identify which channels and creatives are genuinely effective. Attribution models fed with fraudulent install data produce inaccurate signals, leading to poor optimization decisions. Fraud detection systems that rely solely on device-level blacklists are rendered ineffective because each reset creates a clean identity. This is why modern fraud detection combines device signals with behavioral analytics, CTIT analysis, and anomaly detection to identify patterns that survive a device ID reset.

How to protect against device ID reset fraud

Protecting against device ID reset fraud requires a layered detection strategy that goes beyond simple device ID blacklisting.

1. Monitor click-to-install time (CTIT). Fraudulent installs triggered by automated scripts show abnormally short CTIT values, often measured in seconds rather than the minutes or hours typical of genuine users. Set CTIT thresholds and flag or reject installs that fall outside normal ranges.

2. Analyze post-install behavior. Fraudulent installs rarely exhibit meaningful post-install engagement. Tracking in-app events and comparing engagement rates across traffic sources reveals sources with high install volume but near-zero downstream activity, a strong indicator of device ID reset fraud.

3. Check for duplicate IP addresses. A single IP address or IP range generating a disproportionate share of installs suggests coordinated fraud from a phone farm. Cross-reference install IP addresses against known data center ranges and flag concentrated sources.

4. Use device fingerprinting as a supplementary signal. Even when device IDs are reset, hardware-level attributes such as screen resolution, CPU type, and OS build may remain consistent. Comparing fingerprints across installs helps identify devices cycling through multiple identities.

5. Partner with an MMP that includes fraud detection. A mobile measurement partner such as Airbridge provides real-time fraud detection that combines CTIT analysis, behavioral scoring, device intelligence, and anomaly detection. This multi-signal approach catches fraud that survives a device ID reset, protecting attribution integrity and ad spend.

6. Maintain and update blocklists. Even though device ID reset fraud bypasses static blacklists, publisher-level and sub-publisher-level blocklists remain a useful layer. Combine them with behavioral rules to build a more resilient defense.

Related concepts

Term Relationship Description
SDK Spoofing See also Simulates installs at the SDK level without a real device, often used alongside device ID manipulation.
Click Fraud See also Fraudulent clicks generated to exhaust ad budgets or claim attribution credit, often coordinated with device ID cycling.
Install Fraud Parent The broader category of fraud that produces illegitimate app installs, of which device ID reset fraud is a specific method.
Phone Farms See also Physical banks of devices used to execute device ID reset fraud at scale.
Click-to-Install Time (CTIT) Detection A key detection signal for device ID reset fraud, as automated installs produce abnormally short CTIT values.

Put these concepts into practice

See how Airbridge helps teams implement mobile attribution strategies at scale.

Get Started FreeView Case Studies

Related Glossary Terms

Expand your understanding with related concepts.

SDK spoofing

SDK spoofing is the creation of fake installs which can consume the advertising budget without actual value.

Click fraud

Click fraud is ad fraud that intentionally inflates mobile app install or in-app event numbers by repeatedly clicking on ads or using automated scripts to create fake clicks.

Install fraud

Install fraud is artificially inflating the number of mobile app installs through technical methods such as bots, fake accounts, and incentivized downloads, misleading advertisers.

Phone farms

Phone farms are a collection of smartphones or mobile devices that are controlled remotely and used to perform automated tasks.

Click to install time (CTIT)

Click to install time, or CTIT, measures the time elapsed from the moment a user clicks on an ad to when the user installs and opens the respective app. This metric is often used by marketers to detect mobile ad fraud such as click spamming and click injections.

GAID (Google Advertising ID)

GAID is a unique and anonymous identifier used in Google’s advertising services to track ad performance and offer personalized ads.

Airbridge

Stop paying for ads that don't perform. Know which ads actually drive revenue.

Ask AI for a summary of Airbridge

Plans

  • Compare All Plans
  • Core
  • Growth
  • Pricing

Features

  • Airbridge AI
  • Marketing Analytics
  • Fraud Protection
  • Web & App Attribution
  • ROAS Measurement
  • iOS & SKAN
  • Deep Linking
  • Data Export
  • Audience Manager
  • Signal Hold

Resources

  • Blog
  • Case Studies
  • Glossary
  • Library
  • Academy
  • Marketers Guide
  • Developer Guide

Company

  • About Us
  • Terms of Service
  • Electronic Payment Terms
  • Privacy Policy
  • Information Security
  • GDPR
  • System Status

Customers

  • Fizz
  • Planfit
  • Loyal Foundry
  • UNNI
  • Wasabi
  • Rapchat

© 2026 AB180 Inc. All rights reserved.

AB180 Inc. | Business Registration: 550-88-00196