Technology
mFilterIt study reveals how Samsung and LG connected TV’s account for 81.7% of all ad fraud

mFilterIt finds two CTV environments account for 81.7% of frequency-cap violations, raising fresh questions about whether advertisers are paying for audiences that never existed
What happens when you switch off your television? For most people, the answer is simple: the screen goes dark, the programme ends, and the TV goes to sleep.
For advertisers, however, the picture may be rather different. A new investigation by digital trust and ad-fraud intelligence platform mFilterIt has found that Connected TV environments can continue generating advertising activity even when there may be no one watching. More strikingly, the problem appears to be heavily concentrated. Two CTV environments alone accounted for 81.7% of all frequency-cap violations identified in the investigation.
One environment (namely Samsung) accounted for 53.35% of the violations, while a second (namely LG) contributed another 28.35%.
That concentration matters because it suggests that CTV ad fraud may not simply be a diffuse problem scattered across thousands of publishers, apps, and devices. Some of the most serious vulnerabilities could sit within specific device and app ecosystems, making them both potentially repeatable and scalable.
When the TV sleeps, the ads may not
At the centre of mFilterIt’s findings are proxy-sharing capabilities embedded within certain smart-TV app software development kits, or SDKs.
These mechanisms can allow background network activity to continue making advertising requests even when an application is not being actively viewed. In some cases, mFilterIt says, the activity can continue even when the television screen itself is switched off.
Technically, an ad request can still look legitimate. An impression can still be registered. And, crucially, that impression can still be billed. That creates a particularly uncomfortable problem for CTV, an advertising category whose appeal rests heavily on the quality of its audience.
CTV has been positioned as a premium environment because it brings together the impact of television with the targeting, optimisation, and measurement capabilities of digital advertising. But those advantages depend on a fairly basic assumption: that an impression represents a genuine opportunity for someone to see the ad. If a device can repeatedly generate impressions without a viewer being present, that assumption starts to weaken.
As Amit Relan, CEO and Co-Founder of mFilterIt, puts it, “CTV has emerged as a premium inventory for advertisers because of its ability to combine the impact of television with the precision of digital”. He adds that a premium inventory cannot be evaluated only by whether an ad call was successfully made or if an impression was counted. When the same device repeatedly generates impressions beyond expected viewing behaviour, advertisers need to ask whether there was a genuine viewer and a real opportunity for the ad to be seen”.
The frequency-cap problem
Frequency caps exist for a straightforward reason. Advertisers do not want to spend their budgets showing the same person the same message endlessly. The objective is to control repetition and push campaigns towards incremental reach.
When a compromised device repeatedly generates impressions, however, the mathematics can begin to work against the advertiser. A campaign can appear to have delivered substantial reach when a disproportionate share of that delivery is actually coming from the same devices. At the same time, every additional impression consumes media spend.
The result is potentially a double distortion: reach can be overstated while budgets are being consumed by repetitive exposure. And because the activity can still appear as valid delivery in campaign reporting, the problem may remain invisible until someone examines the underlying behaviour.
That is what makes the concentration uncovered by mFilterIt significant. If more than four-fifths of detected frequency-cap violations are coming from two environments, advertisers have a clear reason to scrutinise where their CTV inventory is actually coming from.
Policy can close the door. Measurement has to police the room.
There are obvious reasons for platforms and app ecosystems to tighten controls around proxy-sharing capabilities and residential proxy SDKs. Such measures can make it harder for new bad actors to enter the system.
But that does little to answer a more immediate question for advertisers: What happened to the impressions they have already bought? That is where independent validation becomes important.
Brands and agencies increasingly need to know whether an impression came from legitimate viewing behaviour, whether the device activity suggests the presence of a real viewer, whether frequency thresholds were breached, and whether the impression contributed to incremental reach.
This points towards a broader shift in digital advertising. The industry has spent years getting better at measuring whether an ad was served. The harder question is whether that served impression represented something valuable.
For CTV, that distinction is becoming increasingly important. Premium inventory carries a premium price because advertisers believe the environment delivers premium attention. If devices can continue generating advertising impressions after the viewer has walked away, or even after the screen has gone dark, the industry will need to rethink what exactly it means by a premium impression.
The lesson from mFilterIt’s investigation is therefore bigger than two CTV environments. It is a reminder that as television becomes increasingly digital, advertisers may need to bring the same level of scrutiny to CTV that they have learned to apply elsewhere in the programmatic ecosystem.
Because ultimately, a counted impression is only useful if there was someone there to count it for.

