Glossary

Device ID reset fraud

Device ID reset fraud is a form of mobile ad fraud where fraudsters repeatedly reset a phone’s unique identifier to make it appear as if each install or action is coming from a new device. This trick creates the illusion of fresh user activity, fooling advertisers into paying for fake installs, clicks, and engagement that never come from real users.

Every mobile device has an ID that helps apps and advertisers recognize it without revealing personal information. Fraudsters discovered that if they reset this ID often enough, the same device could pose as thousands of new ones. What looks like an endless flow of new users is really one phone pretending to be many.

How device ID reset fraud works

  • Install and engage The fraudster clicks on an ad, installs the app, and performs basic in-app actions like opening it, completing a tutorial, or watching an ad.
  • Reset the identifier The advertising ID (IDFA on iOS, GAID on Android) is manually or programmatically reset. Some operations use specialized software or modified operating systems to automate this.
  • Uninstall and reinstall After the reset, the app is deleted and reinstalled. Because the ID has changed, attribution systems see the activity as a completely new device and reward the network for a “new user.”
  • Repeat at scale In organized setups, hundreds or thousands of devices go through this loop day and night. This is often called a reset marathon, and when operated by large groups, it is typically done through device farms.


Why this fraud emerged

Both Apple and Google introduced advertising identifiers to track engagement anonymously and gave users the option to reset them for privacy. That transparency also created an opening. When attribution systems rely on the ID alone, each reset looks like a clean, unique user. Fraudsters exploit this gap to fabricate installs and drain budgets while keeping the traffic technically valid in surface data.



Why it matters

  • Wasted marketing spend on installs and engagement that bring no real users
  • Polluted analytics that hide true performance and mislead optimization models
  • Distorted ROAS calculations, making weak campaigns look profitable
  • Damage to attribution accuracy, confusing re engagement versus acquisition
  • Risk of blacklisted sources if fraudulent activity is traced to the advertiser


Techniques fraudsters use

  • Automation tools that reset device IDs in cycles and simulate touch input
  • Rooted or jailbroken devices that allow full control over system identifiers
  • IP rotation and proxies to appear as new users in different regions
  • Device ID spoofing where the same phone cycles through many fake identifiers without an actual reset
  • Cloaking scripts that mimic normal user behavior to bypass basic anti fraud checks


How to detect device ID reset fraud

Look for unusual install patterns

A sudden surge in “new” users from the same subnet, device model, or OS version.

Monitor advertising ID churn

A high rate of new IDs that share other identical parameters such as IP or location suggests resets.

Compare post install metrics

Low day one retention and zero meaningful engagement signal fake installs.

Check click to install timing

If installs occur within seconds of clicks at a volume too high for real behavior, fraud is likely.

Audit attribution windows

Shorter click windows reduce opportunities for recycled devices to claim credit.



Prevention and mitigation

  • Use multi signal attribution Combine deterministic identifiers, engagement fingerprints, and consent based user data to reduce dependency on a single ID.
  • Integrate fraud detection tools Leverage SDKs and analytics that track abnormal patterns, rooted devices, or repeated ID resets.
  • Analyze retention and event quality Focus on meaningful engagement such as purchases, subscriptions, or advanced level completions.
  • Verify supply transparency Demand full reporting from ad networks and block placements that show inconsistent behavior.
  • Reward real value, not volume Tie payouts to quality metrics and long term outcomes instead of raw install counts.
  • Educate your partners Share findings with networks and attribution providers to collectively flag repeat offenders.


How grovs.io helps

Grovs detects device ID reset fraud by analyzing thousands of behavioral signals per session, from install depth to event velocity. Our models identify recycled devices, rapid ID churn, and repeated engagement loops. When grovs.io spots suspicious patterns, it flags the traffic, pauses spend, and alerts your team with transparent evidence. You gain verified installs, accurate attribution, and protection for every ad dollar.



Frequently asked questions

What is device ID reset fraud

It is a scheme where fraudsters repeatedly reset a phone’s unique advertising ID to make it appear as a new user with every app install or engagement.

Why is this considered ad fraud

Because it fabricates user acquisition data, wastes marketing budgets, and misleads advertisers about real campaign performance.

What are advertising IDs

They are unique identifiers (like IDFA for iOS and GAID for Android) used for attribution and targeting while keeping users anonymous.

How can marketers spot it

Watch for high install volumes with extremely low retention, identical device clusters, and repeat IP patterns behind “new” installs.

Can legitimate resets trigger false alarms

Occasionally yes, since real users can manually reset their IDs. The difference lies in the scale, timing, and repetitive nature of fraudulent resets.

What is a device ID reset marathon

It refers to continuous, automated cycles of reset and reinstall across large numbers of devices, often performed by organized device farms.

How can advertisers protect themselves

Use advanced anti fraud analytics, shorten attribution windows, monitor quality metrics, and work with transparent partners.



Related Terms