How to detect click farms

Last updated on July 27, 2026 · 9 min read
A click farm is one of the more physical shapes online fraud takes: a room, sometimes a warehouse, filled with racks of real phones and tablets, each running real apps on real networks, operated by people or scripts to manufacture engagement that never came from a genuine user. The output is fake app installs, fake signups, fake reviews and star ratings, inflated likes and follows, and paid clicks that drain an ad budget without a real person behind them. Journalists have documented these operations for years: in 2017, a police raid in Thailand seized about 474 phones and roughly 350,000 SIM cards from a single click-farm operation, and the pattern is always the same, many devices, many accounts, one operation. The fake engagement they manufacture is not a fringe problem: in 2024 the Federal Trade Commission finalized a rule banning the sale and purchase of fake reviews and bot-generated followers, with civil penalties for each violation.
This guide explains what a click farm is, how phone farms work, why each fake account looks so ordinary on its own, and how to detect click-farm activity, including the device-identity signal that pulls a crowd of independent-looking signups and sessions back into a single cluster.
Key takeaways
- A click farm, also called a device farm or phone farm, is a physical bank of real phones and accounts used to mass-produce fake engagement: installs, signups, reviews, follows, and paid clicks.
- Because the devices and networks are real, each fake install or account passes a shallow check, which is why farms scale so well against per-account rules.
- Click-fraud and ad-verification tools filter the invalid traffic hitting your ads, and bot management slows automated scripts; the device-identity layer adds what those miss, linking the accounts that trace back to one operation.
- The tell is the shared footprint beneath the farm: many accounts operated from one device, many accounts sharing one local network, or many spoofed device fingerprints from a single setup, a shape that ordinary users almost never produce.
- The signal that clusters the operation is the device behind each account, which is far harder to rotate than an email, a phone number, or an IP address.
What is a click farm?
A click farm is a physical operation that uses many real devices and accounts to generate fake online engagement at scale, such as app installs, account signups, product reviews, social likes and follows, and clicks on ads or links. Click farm, device farm, and phone farm all name the same thing: a bank of handsets, often mounted on racks and driven manually or by scripts, made to look like a crowd of separate users.
Farms exist because engagement has value. An app that looks popular ranks higher and wins more organic installs, a listing with hundreds of five-star reviews converts better, a social account with a large following sells influence, and a competitor can burn a rival's pay-per-click budget by sending fake clicks its way. Because the phones, SIM cards, and networks involved are genuine rather than emulated, the activity a farm produces is unusually hard to tell apart from the real thing one event at a time.
How click farms work
A farm's advantage is authenticity of the raw materials. Each phone is a real device with a real operating system, each SIM is a real number, and each connection often routes through residential or mobile IPs that look like ordinary home users. On top of that hardware, operators layer the tricks that keep any single account from repeating: fresh email addresses, rotated phone numbers, VPNs and proxies, and anti-detect browser setups that reset or randomize the identifying details a site would normally read.
The work itself splits into a few recognizable jobs:
| Tactic | What the farm does |
|---|---|
| Fake app installs | Installs an app across hundreds of devices to inflate download counts, climb store rankings, and trigger install-based ad payouts |
| Fake signups and account creation | Registers many accounts to farm signup bonuses, free trials, referral rewards, or verified-user status |
| Fake reviews and ratings | Posts reviews, star ratings, and testimonials from many accounts to lift or sink a listing's reputation |
| Engagement inflation | Manufactures likes, follows, shares, and views to make an account or post look more popular than it is |
| Pay-per-click and ad fraud | Clicks on ads or affiliate links to drain a competitor's budget or collect fraudulent ad and affiliate revenue |
These jobs look different from the outside, but they run on the same underlying resource: far more devices and accounts than any one real person would ever control. That surplus is the thread detection can pull.
Why click-farm activity is hard to catch
A single fake install or signup from a farm is almost indistinguishable from a real one, and that is by design. The device is real, the network looks residential, the email is valid, and the behavior can be scripted to mimic a human pace. Checked one account at a time, nothing breaks a rule, so the controls most teams reach for first tend to slide right off.
The usual defenses each leave a gap. Blocking duplicate emails is trivial to beat with disposable or plus-addressed inboxes. Blocking duplicate IPs both misses a farm that rotates residential proxies and punishes real households and offices that legitimately share a connection. Rate limits per account do nothing when the operation simply spreads across more accounts. What all the farm's accounts genuinely have in common is harder to fake and easier to overlook: the devices behind them and the network they share. This is the same multi-accounting shape, many accounts run from one device or many accounts sharing one local network, that drives promo abuse and self-referral, here scaled up into a room full of phones.
How to detect click-farm activity
No single check exposes a farm, so detection layers several signals and lets them corroborate each other. Each layer covers what the others miss:
- Filter the invalid traffic first. Click-fraud and ad-verification tools score the clicks and installs hitting your campaigns and strip out the ones that never came from a real user. This handles the ad-network side of the problem, upstream of the accounts a farm creates.
- Slow the automated jobs. Bot management and challenge steps keep scripted actions from racing through signup and checkout at machine speed, which raises the cost of running the farm's cheaper, fully automated work.
- Link the accounts and installs that claim to be separate. A strong check is whether many "different" accounts, signups, or sessions trace back to one device or one shared local network, the shape a real user base never produces. A pure phone farm runs one account per real phone, so it leans less on device reuse and more on the shared network and anonymity signals beneath it.
- Watch anonymity and network signals. A burst of activity behind VPNs, proxies, and anti-detect browser setups, or a wave of installs from connections dressed up to look residential, is a strong operation signal, because genuine users rarely arrive from many masked connections at once.
- Watch velocity and timing. Hundreds of installs or registrations in a short window, or engagement that spikes in tight bursts, points to a coordinated operation rather than organic growth.
- Review before rewards ship. Holding suspicious or high-velocity signups for a quick check catches the obvious farm activity before a bonus, payout, or verified badge is granted.
Run together, these keep genuine installs and signups flowing while making a farm far harder to operate at a profit.
How ShieldLabs detects the accounts behind click farms
ShieldLabs reads the device and network behind every signup and session to link the accounts a farm operates. You add one JavaScript snippet to your flow, and each visit returns persistent identification, built from device fingerprinting signals, that survives cleared cookies and a rotated IP. When dozens of "different" accounts resolve to one device or share one local network, the pattern that hides a farm is surfaced directly instead of left for your team to reconstruct after the fact.
We ran a bank of accounts the way a farm would, spreading them across devices and resetting cookies, emails, and addresses between each, and the device identifier still pulled the ones sharing a machine into a single cluster. Where accounts shared a device, the many-accounts-on-one-device pattern surfaced from that linkage, not from any single account looking wrong on its own. A pure phone farm is the harder case: one account per real phone means many distinct device identifiers that never trip that check, so the shared local network the phones sit behind, the anonymity signals, and the velocity of registrations carry the read instead. That physical surplus of hardware is what farms have always run on, the same shape behind phone-farm raids that have seized hundreds of phones and hundreds of thousands of SIM cards.
Alongside it, each visit returns a risk score from 0 to 100 and the named anonymity signals, VPN, proxy, Tor, and anti-detect browser use, that an operator leans on to make one room of phones look like a crowd of separate users. Click-fraud and ad-verification tools filter the invalid clicks hitting your campaigns, and ShieldLabs adds the device-identity layer that links the farm's accounts beneath them. The same device linkage carries into the broader ad fraud picture, where the accounts and installs a farm produces feed fake conversions downstream. ShieldLabs scores the session and names the evidence, and you read the pattern and the score through the API and webhooks so your own rules decide which signups to allow, limit, or review. The free tier covers your first 5,000 identifications.
Sources
- Wikipedia: Click farm
- BBC: Thailand click farm raid (about 474 phones and 347,000 SIM cards)
- Federal Trade Commission: Final rule banning fake reviews and testimonials (2024)
Frequently asked questions
- What is a click farm?
- A click farm is a physical operation that uses many real phones and accounts to mass-produce fake online engagement, such as app installs, signups, reviews, likes and follows, and clicks on ads or links. It is also called a device farm or a phone farm. Because the devices, SIM cards, and networks are real rather than emulated, each fake action is hard to tell apart from a genuine one when checked on its own.
- How do click farms work?
- A farm runs racks of real handsets, each with a valid SIM and often a residential or mobile IP, driven by hand or by scripts. Operators layer fresh emails, rotated phone numbers, VPNs, proxies, and anti-detect browser setups on top so no single account repeats its details. That surplus of devices and accounts, far more than any one person would control, lets the operation manufacture installs, signups, reviews, and clicks that each look ordinary in isolation.
- Are click farms illegal?
- It depends on where you are and what the farm does. The activity itself, manufacturing fake reviews, inflating engagement, and generating fraudulent ad clicks, breaks the terms of nearly every platform and can cross into fraud. In the United States, the FTC has moved against fake reviews and deceptive endorsements, and click fraud that misappropriates ad spend can carry civil and criminal liability. Enforcement varies by country, but the buying and engagement tactics behind a farm are where most of the legal exposure sits.
- How do you detect click-farm activity?
- By finding what the supposedly independent accounts share rather than what each one shows. The strongest signal is a shared device or a tight device cluster linking many accounts, signups, or sessions back to one operation, followed by anonymity signals like VPN, proxy, or anti-detect browser use, and behavioral links such as install velocity or bursts of activity in a short window. No single check is conclusive, so detection correlates several signals to expose one operation behind many accounts.
- How does ShieldLabs help against click farms?
- ShieldLabs surfaces the device and anonymity signals behind the accounts and installs a farm creates, in particular the many-accounts-on-one-device and shared-local-network patterns that give a farm away, rather than verifying ad clicks itself. It returns persistent identification plus a risk score with the named signals, so your own rules decide which signups to allow, limit, or review. It adds the device-identity layer that links a farm's accounts beneath click-fraud and bot tools rather than replacing them, and the free tier covers your first 5,000 identifications.
Related articles

New vs returning visitors: what a good ratio is, and why the number is only as good as your cookies
What a good new vs returning visitor ratio is, why the cookie-based count in analytics is wrong, and how returning visitors are recognized without cookies.

How to detect invalid traffic (IVT): types, causes, and signals
How to detect invalid traffic (IVT): the GIVT vs SIVT split, what causes it, and the signals advertisers use to catch the traffic draining ad budgets.

How website visitors are counted: Google Analytics, Vercel, and ShieldLabs compared
Why your visitor counts never match across tools. How Google Analytics, Vercel, and ShieldLabs each identify a visitor, and which count is closest to the truth.