Pixalate Blog

Pixalate’s July 2026 CTV Bundle ID Fraud Mechanics Report

Written by Pixalate | Aug 18, 2026, 1:00:00 PM

This report analyzes the 50 highest-traffic fraudulent Connected TV (CTV) bundle IDs, as measured by Pixalate and ranked in its Ad Fraud Indicators of Compromise Database (AdFraud IOC-DB).

LONDON, August 18, 2026 -- Pixalate, an ad fraud and privacy compliance platform, today released the July 2026 CTV Bundle ID Fraud Mechanics: Spoofing and ID Manipulation in Programmatic CTV Report. The report covers Apple TV, Roku, Samsung Smart TV, and Amazon Fire TV CTV app stores.

The rankings are based on ad traffic volume across the open programmatic ecosystem from the month of July 2026.

Flagged bundle IDs show signs of spoofing known apps, malformed or missing app-store mappings, or platform mismatches, including mobile bundle IDs appearing in CTV bid streams. It is based on Pixalate’s AdFraud Indicators Of Compromise (IOC)-Database, the ad industry’s first open-source intelligence feed designed to aid fraud researchers, developers, and system administrators in the fight against Invalid Traffic (IVT).

Key Findings

  • Brand Spoofing: 80% of the fraudulent bundle IDs identified on Roku spoof a specific, recognizable brand, more than any other platform by percentage.
  • Format Mimicry: 67% of the fraudulent bundle IDs identified on Amazon Fire TV follow the platform's native ID conventions, including ASIN codes and ".amz/.amzn" suffixes.
  • Multi-platform Profileration: 100% of the fraudulent bundle IDs identified on Apple TV also appear on three or more other platforms, the strongest overlap patterns Pixalate identified.
  • Exposure: 24 of the 50 highest-traffic fraudulent bundle IDs were identified on Amazon Fire TV
  • Numeric ID Mimicry: 74% of fraudulent bundle IDs identified on Samsung Smart TV mimic the platform's numeric ID format
  • Multi-platform Profileration: 60% of fraudulent bundle IDs identified on Roku are also found on three or more other platforms, the highest overlap rate Pixalate observed

Download the July 2026 CTV Bundle ID Fraud Mechanics: Spoofing and ID Manipulation in Programmatic CTV Report.

 

LEARN MORE → Visit Pixalate’s AdFraud IOC-DB

 

What is the AdFraud IOC-Database?

The publicly available AdFraud IOC-Database is Pixalate's open-source, weekly-updated list of the top 50 highest-risk ad fraud Indicators of Compromise (IOCs). AdFraud IOC-DB is powered by Pixalate's MRC-accredited ad fraud detection engine, which analyzes 183 billion global data points daily. It filters massive datasets down to the 50 most critical threats, allowing sysadmins to easily integrate high-risk blocklists without overwhelming their infrastructure. The AdFraud IOC-DB reveals the top 50 IOCs observed across multiple supply-path touchpoints, including IP addresses (both IPv4 and IPv6), device IDs (mobile and CTV), datacenters, fraudulent Bundle IDs, MFA publishers, and delisted apps.

How can I access the complete list of IOCs?

The AdFraud IOC-DB is available for free on Pixalate's website, where users can see the weekly top 50 IOCs across 11 risk categories.

About Pixalate

Pixalate is a global platform specializing in privacy compliance, ad fraud prevention, and digital ad supply chain data intelligence. Founded in 2012 and recognized by UNICEF, Pixalate is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is accredited by the MRC for the detection and filtration of Sophisticated Invalid Traffic (SIVT). pixalate.com

Disclaimer

The content of this press release, and the CTV Bundle ID Fraud Mechanics: Spoofing and ID Manipulation in Programmatic CTV Report (the ‘Report’), reflect Pixalate's opinions with respect to factors that Pixalate believes may be useful to the digital media industry. Any data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements. Pixalate's opinions are just that, opinions, which means that they are neither facts nor guarantees. Pixalate's opinions are just that, opinions, which means that they are neither facts nor guarantees. Pixalate is sharing this data not to impugn the standing or reputation of any entity, person or app, but, instead, to report findings and trends pertaining to programmatic advertising activity across in the time period studied. Per the Media Rating Council (MRC), “‘Invalid Traffic’ is defined generally as traffic that does not meet certain ad serving quality or completeness criteria, or otherwise does not represent legitimate ad traffic that should be included in measurement counts. Among the reasons why ad traffic may be deemed invalid is it is a result of non-human traffic (spiders, bots, etc.), or activity designed to produce fraudulent traffic.” Where the traffic characteristics are suggestive of deliberate intent to mislead, such IVT is often referred to as “ad fraud.” Also per the MRC, “'Fraud' is not intended to represent fraud as defined in various laws, statutes and ordinances or as conventionally used in U.S. Court or other legal proceedings, but rather a custom definition strictly for advertising measurement purposes.”