What Publishers Can’t See Can Cost Them: Exposing the Hidden Economics of Ad Safety
by on 15th Sep 2026 in News

In her latest column, mobile expert Peggy Anne Salz of MobileGroove looks at the importance of providing a safe ads in an in-app environment, and how the danger is sometimes carefully hidden...
App publishers and developers are learning to spot disruptive creatives and poor ad experiences. Now they have to address what happens underneath the ad and beyond the impression. Malvertising raises the stakes because the danger can be hidden in the code, redirect or landing page, leaving publishers exposed to risks they may not see until they show up in user trust, retention, and revenue.
In both cases, publishers may have clear policies about the advertising they allow in their apps, but setting those standards is only half the battle. It’s not enough to prohibit ads. Publishers have to double down on efforts to detect, verify, and stop ads they have ruled out before they reach users.
"Ultimately, publishers have a responsibility to protect their users," observes Alexandra Ryabova, head of operations at social discovery app Wizz. That commitment to ad safety underpins what Wizz calls "double validation". Clear rules for demand partners are backed by independent verification, giving Wizz a second check on what actually reaches its audience. The app, which counts more than three million monthly active users aged 18–24, has seen the payoff in better app reviews, longer conversations, and a whopping 4% increase in user retention.
"There’s a misconception that once you plug in a network, everything will always work as expected. That’s not necessarily the case," Ryabova says. "You need that second layer of validation." This approach sits within a much broader safety strategy that spans almost ten layers of detection and verification across the product and accounts for around 50% of Wizz’s operational costs.
Ryabova also cautions against treating enforcement as a game of whack-a-mole. Blocking one problem does not necessarily prevent another from emerging elsewhere in the ad supply chain. "You have to dig deeper and find the original issue," she says.
When the publisher takes the hit
Publisher policies and practices are evolving to address ad safety. But the pressure is on publishers to control the entire ad journey, a tall order when the real threat sits inside the ad, in its code, redirect behaviour or destination after the click.
For publishers, the challenge is stopping an attack designed to look harmless until it runs inside the user’s environment. And increasingly, attackers are optimising that behaviour for mobile and in-app advertising, where visibility and control are more limited.
Attackers are also timing campaigns to follow seasonal spending and high-intent traffic. In August, GeoEdge, a cybersecurity company protecting digital media and the advertising ecosystem, found attackers exploiting the back-to-school surge with cloned retailer sites, deceptive in-app ads, cloaked landing pages and malicious redirects. That puts publishers directly in the delivery path of scams built to capitalise on one of the year’s biggest spending periods.
The tactics are also becoming harder to trace. Researchers recently exposed a mobile campaign that used WebAssembly, server-side fingerprinting, and cloaked responses to hide fraudulent clicks and impressions behind a legitimate ad. The ad remained visible in the foreground while the fraud fired in the background, with clean content returned when attackers detected an automated scanner.
By abusing or spoofing app identities, attackers can make legitimate developers and publishers appear to be the source of the fraud they never initiated. It’s a form of misattribution that can expose publishers to audits, reduced demand, withheld revenue or network action.
The hidden risk is already at scale
Malicious ads are reaching users alongside the more familiar content and category risks publishers already manage, making ad safety as much a monetisation challenge as it is a security problem. Even worse, new research exclusive to ExchangeWire, based on an analysis of in-app traffic, reveals just how frequently those hidden risks are reaching audiences.
Drawing on in-app ad traffic analysed between March and May, AppHarbr, an in-app ad quality and security platform, found that one in 82 ads in mobile games was malicious, compared with one in 333 in non-gaming apps. What’s more, most observed malvertising exposure came through one of the most familiar formats. Banners accounted for 92% of exposure in mobile games and 99% in non-gaming apps, compared with 5% and 1% respectively for interstitials, while rewarded ads accounted for the remaining 3% in games.
The bottom line: banners are not the risk. However, familiar formats can carry threats publishers can miss. For users, whether it’s a phishing destination or malicious code, the damage is delivered through the app experience, and the publisher owns the fallout.
Malvertising is not one problem
That fallout can begin at very different points in the ad journey. Some threats activate before a user clicks anything, while others emerge after the interaction through redirects, downloads, browser windows or deceptive landing pages. The split between pre-click and post-click threats matters because the creative reveals only part of the risk.
Rona Lautman, director of product at AppHarbr, frames the wider ad experience in three connected layers.
- Content is what users see, including inappropriate or offensive material.
- Behaviour covers what the ad does to the experience.
- User safety encompasses malware, scams, malicious redirects, and deceptive destinations.
That last layer is increasingly difficult to treat as a security issue alone. "When the consequences surface in trust, engagement, retention and revenue, ad safety becomes part of the publisher’s performance equation," Lautman explains. "It’s short-term revenue at the expense of longer LTV."
Where malvertising happens
| Pre-click threats | Post-click threats |
| Malicious code or URLs — malware embedded in the ad or loaded before the user interacts | Phishing — deceptive destinations designed to steal credentials or personal data |
| Automatic redirects — users are sent elsewhere without choosing to click | Malicious downloads — files, software or extensions triggered after interaction |
| Pixel stuffing and click fraud — hidden activity generates fraudulent impressions or clicks | Fake updates and security alerts — users are pushed towards bogus software or clean-up tools |
| Pre-click malware — malicious behaviour begins as the ad loads | Financial and gift-card scams — deceptive offers designed to extract money or information |
| Hidden ad behaviour — code or functionality is concealed behind an apparently legitimate creative | Cloaked or deceptive landing pages — the destination changes according to device, location or user behaviour |
The hidden tax on growth
How we define the damage to users may differ, but publishers pay for it all in the same currency: performance.
Fatma Güngör, head of apps and gaming partnerships, EMEA at Google, calls the fallout a "hidden tax" on publishers because it shows up in churn and across the metrics that determine business health.
For publishers, that puts ad safety at the core of the longer-term growth equation. Retention determines how much value a user can generate over time, which is why Güngör argues that sustainable scale depends on keeping users rather than simply replacing those who leave. "Scale is a very long-term game of retention and improved lifetime value within the app experience itself," she says.
Google’s own enforcement numbers put the scale of that challenge into perspective. In 2025, the company blocked or removed 602 million ads associated with scams, while its systems caught more than 99% of policy-violating ads before they reached a person. Google also identifies malvertising as a tool used by bad actors and says it combines AI with human review to identify and block ads and accounts that lead users to malicious software.
At this scale, policies and spot checks are not enough. Publishers need visibility across the full ad journey, automated detection, and the ability to act when something goes wrong.
That starts with looking beyond the creative. Güngör argues that publishers need to manage the "end-to-end, whole journey," from how ads are served to what happens after the interaction. For ad safety, that means following redirects, browser launches, downloads, and landing pages rather than assuming the impression tells the whole story.
A publisher playbook for safe growth
Publishers can’t eliminate every bad actor in the supply chain, but they can decide how difficult it is for one to reach their users. The practical starting point is turning ad safety from an expectation into an operating discipline.
#1. Turn policy into protection. Publishers need a clear definition of what they will not allow, including malicious ads, scams, deceptive redirects, and unsafe destinations. Lautman argues that those rules should be explicit and can vary by app, operating system or geography. "The first step is to know what you allow and what you don’t allow," she says. Anything malicious should be a hard line.
#2. Make the rules stick. A safety policy only matters if publishers can enforce it at scale. Lautman stresses that malicious ads, scams, and unsafe redirects should be detected, blocked, and reported automatically rather than left to manual review. Protection also needs to follow every format, geography, device, and demand source, closing the gaps attackers can exploit.
#3. Put safety on the payroll. Ad safety can’t be everyone’s responsibility and no one’s job. Ryabova says publishers need to allocate real resources, whether that means budget, people or both. "It could be monetary, but it could also be allocating a person responsible for holding networks accountable for the ads they deliver." That person also needs the mandate to act. For Ryabova, the job is not simply spotting a problem but taking the evidence back to partners, showing them where something went wrong and demanding accountability. It takes persistence, too. Her advice for anyone taking on the role is simple: "patience and a positive attitude".
#4. Don’t take safety on trust. Networks have their own policies and protections, but publishers still need an independent view of what actually reaches users. Wizz’s "double validation" approach gives Ryabova that second line of sight, checking delivery against the standards agreed with partners. Apply that to malvertising, and it’s clear verification has to follow the code, redirects, and destination as well, because the harmful behaviour may only reveal itself after the ad loads or the user clicks. The point is not to duplicate what partners already do, but to close the visibility gap between what should happen and what actually does.
The challenge for publishers isn’t only deciding what ads they are prepared to show. Today, publishers need to know what those ads do, where they take the user and whether the partners supplying them are enforcing the standards they promise.
Clearly, publishers can't control every malicious actor in the ad supply chain, but they can make it a lot harder for unsafe ads to reach users. That requires visibility across the ad journey, consistent enforcement, and clear accountability when something goes wrong. Because when a scam, redirect or malicious destination breaks the user experience, the publisher takes a hit where it hurts most: trust, retention, and revenue.




Follow ExchangeWire