One morning, you open your analytics dashboard and see something every marketer hopes for: Traffic is up, not by a few percent, it has doubled overnight.
For a moment, it feels like all your hard work has finally paid off. Maybe one of your blog posts has gone viral. Perhaps Google rewarded your latest SEO improvements. Or maybe someone influential shared your website.
Then you look a little closer and realise that sales haven’t increased. No extra leads have come through. Engagement has dropped sharply, while hundreds of new visitors seem to have appeared out of nowhere. Many land on the same handful of pages before disappearing. A surprising number of visits appear to come from countries you’ve never actively targeted.
At first, the spike in traffic looks promising. But if there’s no obvious reason for it, you start to wonder what’s going on. Nothing has changed except the traffic figures in your analytics platform.
Others have been seeing the same pattern. Throughout 2025 and 2026, thousands of Google Analytics 4 (GA4) users reported unexplained traffic spikes that didn’t behave like genuine visitors. Many described sudden increases in traffic from countries including Singapore and China, unusually high levels of Direct traffic, hundreds of users appearing in real-time reports and almost no meaningful engagement. Google later acknowledged that some properties were affected by unusual traffic and said it was working to improve its spam detection. (Source: Google Analytics Community)
Those reports sparked plenty of discussion about GA4, but they also highlighted a much bigger question: How much do you trust your analytics data?
Whether you use GA4, Matomo or another analytics solution, unwanted traffic can distort the reports your business depends on. Automated bots, web scrapers, ghost spam, tracking errors and fake requests can all make your website appear busier than it really is.
The consequences go far beyond inflated visitor numbers: Conversion rates fall and attribution becomes less reliable. Marketing campaigns appear less effective than they actually are. Teams start investigating problems that don’t exist while genuine opportunities become harder to spot.
For a website receiving millions of visits every month, a few hundred unwanted sessions might have little impact. But for a growing business, an ecommerce store or a B2B company where every lead matters, even relatively small amounts of polluted traffic can completely change the story your analytics is telling.
It’s easy to see why data quality has become such a priority: In our recent survey of 300 analytics professionals across the US, France and Germany, 55% ranked data accuracy and reliability among the three most important factors when choosing an analytics platform.
That makes sense. Analytics tells you what happened, but its real value is in helping you decide what to do next. If the data isn’t reliable, the decisions based on it become harder to trust too.
Why fake traffic is becoming a bigger problem
Bots have always been part of the internet:
- Search engines use automated crawlers to discover and index new pages.
- Website monitoring services regularly check that websites are online.
- Accessibility tools, social media previews and performance testing platforms all visit websites automatically.
Most of this activity is both expected and useful.
The challenge is that today’s automated traffic is becoming increasingly difficult to distinguish from genuine visitors.
Modern bots execute JavaScript, load pages like real browsers and trigger analytics tags just as a human visitor would. Some scrape content, while others search for vulnerabilities, collect training data for AI models or attempt credential attacks. At the same time, cloud infrastructure, VPNs and privacy technologies make it harder to identify where requests are really coming from.
Of course, not every unusual visit is malicious. But when activity that doesn’t reflect genuine customer behaviour gets into your analytics data, it can distort the reports you use to make decisions.
Knowing what kind of traffic you’re dealing with makes it easier to investigate unusual activity and avoid drawing the wrong conclusions.
Understanding fake and unwanted analytics traffic
Marketers often use “fake traffic” as a catch-all term, but it can refer to several different problems. Sometimes it’s automated bots visiting your website. In other cases, the traffic never reaches your site at all.
Legitimate services can also distort your reports unintentionally:
- Search engines crawl websites to index new content.
- Uptime monitoring services regularly check that websites are online.
- Accessibility tools, social media link previews and performance testing platforms also visit websites automatically.
Even real people may browse through VPNs, corporate networks or privacy-focused browsers, making their visits look unusual at first glance.
Problems arise when activity that doesn’t reflect genuine customer behaviour ends up in the data you use to measure your marketing. That’s when your analytics starts telling a different story from what’s actually happening on your website.
Understanding the different types of fake traffic makes it much easier to investigate unusual activity and avoid drawing the wrong conclusions from your analytics. Each type affects your data in a different way.
Bot traffic and crawlers
Bot traffic isn’t always a problem. Search engines use bots to crawl and index websites, while monitoring services check availability and SEO tools analyse pages. Much of this activity is legitimate and serves a useful purpose. Things get more difficult when bots are designed to look like human visitors.
Modern bots can browse websites almost exactly like real users. They execute JavaScript, trigger analytics events and move between pages in ways that make them much harder to detect than traditional web crawlers.
Google Analytics 4 automatically filters many known bots before they appear in reports. Like every analytics platform, however, it can only exclude traffic it can confidently identify. New bots appear constantly, and some are specifically designed to bypass automated detection.
This is why teams need more control over how unwanted traffic is identified and filtered.
Matomo automatically filters known bots and spam, while also giving organisations additional tools to reduce unwanted traffic before it reaches reports. Depending on how analytics is implemented, Tracking Spam Prevention can block requests from known cloud providers, headless browsers and server-side libraries. Organisations can use these controls to reduce unwanted traffic in their analytics data. Bot detection is never perfect. If filtering is too aggressive, it can remove legitimate visits along with the unwanted bot traffic.
Rather than trying to eliminate every bot, organisations need enough information and control to decide what belongs in their analytics.
Ghost spam
Ghost spam is different because the visitor may never have visited your website at all.
Instead, fake events are sent directly to an analytics property, making it appear as though someone interacted with your website when they didn’t.
Google Analytics 4 significantly reduced this risk by requiring a Measurement Protocol API secret for server-side event collection. Google also advises protecting these credentials carefully because exposed secrets can be abused to send arbitrary or spam data into a property.
Matomo approaches the problem differently by giving organisations greater control over which tracking requests are accepted in the first place. This reduces the chance of unwanted data making its way into reports.
A sudden traffic spike doesn’t necessarily mean ghost spam. Automated testing, a tracking implementation issue or bots making genuine requests to your website can produce similar patterns.
That’s why investigation should always come before assumptions.
Referral spam
Referral spam has frustrated marketers for years. It places misleading websites in acquisition reports to encourage curious analysts to visit the advertised domain.
Sometimes it’s deliberate spam, other times it’s caused by legitimate services such as payment providers, authentication platforms or redirects receiving credit for traffic they didn’t actually generate. Either way, attribution becomes less reliable.
Fake direct traffic
Many marketers assume Direct traffic only includes people who typed a URL into their browser or used a bookmark. In reality, analytics platforms classify visits as Direct whenever they can’t confidently identify another traffic source.
A spike in Direct traffic doesn’t automatically mean you’ve been affected by bots: Broken campaign tracking, missing UTM parameters, redirects, automated requests and other attribution problems can all contribute to an unexpected increase. But it should always prompt further investigation.
Traffic from cloud infrastructure
Many automated systems now operate from cloud platforms such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud and DigitalOcean.
That doesn’t make every visitor from those networks suspicious, as businesses, VPN providers, SaaS platforms and legitimate applications all rely on the same infrastructure.
Cloud hosting is therefore only one clue. It becomes more meaningful when it appears alongside other unusual patterns, such as very low engagement, repetitive browsing behaviour, unexpected locations or no corresponding increase in conversions.
None of these signals proves that the traffic is automated. Taken together, however, they can be a good reason to investigate further.
What the China and Singapore traffic spikes can teach us
Reports from GA4 users in 2025 and 2026 described unexplained traffic from China and Singapore. The countries themselves weren’t the issue. What stood out was how difficult it had become to tell genuine visitors from automated activity, a challenge that affects every analytics platform.
In 2025, WIRED reported that website owners across multiple industries were seeing large volumes of suspected bot and scraper traffic, much of it appearing to originate from China. The consequences went far beyond inflated visitor numbers. Organisations also reported higher bandwidth costs, distorted analytics and challenges for advertising-supported websites.
Traffic from China, Singapore or any other country shouldn’t be treated as suspicious based on location alone. Geolocation only indicates where an IP address appears to be located.
It may belong to a cloud data centre, VPN, proxy service or other internet infrastructure rather than a person browsing from that country. Businesses with international customers can, of course, receive entirely legitimate traffic from these regions.
What matters is why the traffic looks different. A sudden spike in one location might reflect a successful marketing campaign or growing international interest. It might also point to automated traffic, a tracking issue or an infrastructure change. Looking at the surrounding data can help you tell the difference.
Compare engagement rates, landing pages, devices, browsers, referral sources and conversions alongside geography. If multiple signals point in the same direction, you’ll build a much clearer understanding of what’s happening than geography alone can ever provide.
Matomo lets you investigate unusual traffic in more detail. You can segment reports by country, region or city, then combine those segments with dimensions such as campaign, referrer, browser, device type or custom dimensions.
That makes it easier to see not just where the traffic came from, but how it behaved and what else it had in common.
How fake traffic leads to bad business decisions
Fake traffic can do more than inflate visitor numbers. It can distort the picture your analytics gives you and lead to poor business decisions.
If your website suddenly receives thousands of automated visits, those visits may add to your traffic without contributing anything meaningful. They don’t buy products, complete forms, subscribe to newsletters or become customers.
Your conversion rate immediately falls, not because your marketing has become less effective, but because fake visits have diluted the numbers.
The same thing happens across the rest of your reports. Engagement rates decline because bots don’t interact like real people. Direct traffic appears to grow because the original source can’t be identified. Referral reports become noisier, making it harder to understand which campaigns are actually driving results.
Poor data leads to poor decisions. A sudden drop in conversion rate may prompt a team to pause a campaign that is actually performing well. A content team might invest more heavily in topics that attracted bots rather than readers, while product teams waste time investigating user experience problems that do not exist. Executives, clients and stakeholders then receive reports that no longer reflect genuine customer behaviour.
Unwanted traffic also brings direct costs. High volumes increase bandwidth consumption and infrastructure costs. Depending on the platform’s pricing model, they also increase analytics costs because the platform processes more events.
The dashboard may accurately report the data it received, but some of that data does not represent real people.
Clean analytics data supports accurate reporting and better business decisions.
How to recognise and investigate suspicious traffic
No single metric will tell you whether traffic is genuine. A better investigation looks for patterns across several signals.
If your website suddenly receives thousands of extra visitors, check whether anything else changed at the same time. Did sales increase? Were there more lead enquiries, support requests or revenue? Do your server logs show the same rise in traffic?
If none of those signals moved with the traffic, take a closer look. Common warning signs include:
- A sudden spike with no corresponding increase in conversions or revenue
- Unusually low engagement rates
- Visitors landing on the same small group of pages
- Repetitive browsing behaviour
- Unexpected concentrations of traffic from unfamiliar countries or cloud providers
- Unusual browser or operating system combinations
- Large increases in Direct traffic without an obvious explanation
- Identical behaviour repeated across hundreds or thousands of sessions
When several appear together, they often point towards automated activity.
Start with segmentation
Instead of looking at your reports as a whole, segment the traffic that’s behaving differently.
For example, create a segment for:
- Visitors from one country
- A specific landing page
- Direct traffic
- A particular browser
- A cloud-hosted network
- An individual campaign
Once you’ve isolated the traffic, compare it with the rest of your audience. Look at conversion rate, time on site, pages visited, triggered events and the channels the traffic appears in.
If those patterns differ sharply from your usual audience, you’ve got a stronger reason to investigate.
In Matomo, these comparisons can be made using Segments across virtually every report, making it much easier to understand whether unusual traffic reflects genuine customer behaviour or something else entirely.
Use AI to investigate suspicious traffic faster
Investigating unusual traffic often means comparing multiple reports, filtering by country, analysing visitor behaviour and looking for patterns across devices, referrers and campaigns. Depending on the size of your website, that can take time.
With Matomo MCP (AI connector), you can ask questions in natural language, such as:
- “Why did traffic from Singapore increase yesterday?”
- “Compare engagement for visitors from China against all other countries.”
- “Show me landing pages with unusually high traffic but no conversions.”
- “Which referrers are responsible for the recent spike in Direct traffic?”
Instead of manually building segments and reports, Matomo MCP can help surface patterns more quickly, making it easier to investigate whether unusual traffic reflects genuine customer interest, a tracking issue or unwanted automated activity.
AI won’t replace human judgement, but it can dramatically reduce the time it takes to move from “Something looks wrong” to “Here’s what’s actually happening.”
Compare analytics with other data
If GA4 or Matomo reports 20,000 additional sessions but your web server, CDN, ecommerce platform or CRM doesn’t show any corresponding increase, the issue may lie with your analytics implementation rather than your website.
On the other hand, if every system shows the same spike, the investigation should shift towards bot traffic, crawlers, cloud infrastructure or other automated requests.
The more evidence you compare, the easier it becomes to distinguish real business growth from polluted analytics.
Don’t rush to block traffic
When unusual traffic appears, blocking an entire country or cloud provider may seem like the quickest solution. But legitimate users also browse through VPNs, corporate networks and cloud-hosted infrastructure, so broad blocks risk excluding genuine customers along with unwanted traffic.
Start by looking for consistent patterns in the data. Once you know what sets the traffic apart, you can apply more targeted filters with greater confidence instead of relying on geography alone.
How GA4 and Matomo help protect your data
No analytics platform can guarantee perfectly clean data. Bots and spam techniques keep changing, and new forms of automated traffic continue to appear.
The aim is to reduce noise, investigate suspicious activity and base decisions on data you trust.
Google Analytics 4 automatically filters many known bots using industry bot lists and Google’s own detection systems. It also protects against common forms of spam, for example by requiring a Measurement Protocol API secret for server-side event collection.
For many organisations, those built-in protections cover the most common sources of unwanted traffic.
However, if your business regularly experiences large volumes of automated traffic or needs greater visibility into how data is filtered, you may want more control over what enters your reports.
Matomo combines automatic protections with configurable filtering, allowing organisations to tailor analytics to their own environment rather than relying entirely on predefined detection rules.
Depending on your deployment, Matomo can help reduce unwanted traffic by:
- Filtering known bots before they appear in reports
- Blocking spam tracking requests
- Identifying traffic originating from known cloud providers
- Detecting requests from headless browsers and server-side libraries
- Allowing organisations to customise filtering rules based on their own requirements
Rather than treating every organisation the same, Matomo gives you the flexibility to decide which traffic should be included in your analytics and which should be excluded.
What GA4 users can do
GA4’s automatic bot filtering is always active, but it won’t catch every form of unwanted automated traffic.
Teams still need a mix of secure data collection, investigation and reporting controls.
Start by auditing your implementation. Check that tags fire only on approved environments, review duplicate events and protect Measurement Protocol credentials. Then use comparisons and reports to isolate suspicious traffic while investigating its cause.
Use GA4’s internal traffic controls for known employee, agency, testing and office traffic. Test any exclusions before you activate them, as data filters only affect future collection and won’t repair historical reports.
Treat unwanted referrals separately from bot traffic. GA4’s unwanted referral settings help preserve session attribution across payment gateways, authentication systems and related domains, but they don’t work as a general bot blocker.
In reports, comparisons and explorations can help isolate suspicious countries, landing pages, sources, devices and engagement patterns. They won’t remove polluted historical data, but they give you a cleaner view while you investigate the underlying cause.
If the traffic is genuinely reaching your website, controls at the CDN, firewall, reverse proxy or server usually work better than trying to fix the reports afterwards. Rate limiting, bot-management services and targeted network rules can stop unwanted requests before they consume resources or trigger tracking.
Keep broad country or cloud-provider blocking as a last resort. It risks excluding legitimate visitors and hiding genuine demand.
Matomo’s approach to spam and bot traffic
Matomo has treated referral spam as a data-quality issue for more than a decade.
In May 2015, the Matomo team (then operating under the Matomo name), published an open, community-maintained list of referrer spammers. The list was released into the public domain so that other applications and websites could use and contribute to it.
That early work remains relevant because analytics cleanliness can’t depend on a single static list. Attackers, crawlers and infrastructure continually change.
Today, Matomo maintains referrer-spam protections on its core platform and provides additional configurable Tracking Spam Prevention capabilities. Depending on the deployment and configuration, teams can block tracking requests from cloud-provider networks, headless browsers and server-side libraries, restrict countries, and limit excessive actions within a visit.
Organisations define unwanted traffic differently. A public website using browser-based JavaScript tracking might safely reject many server-side or headless requests. An application that intentionally sends events through a server-side SDK needs to accept that traffic or it will lose valid data. That’s why Matomo doesn’t enable every aggressive protection by default. Its guidance recommends testing filters and checking real-time visits so legitimate tracking stays intact.
Bot detection will never be perfect. New automated traffic can imitate normal browsers, compromised devices can use residential networks, and a rule that works well for one organisation might block genuine customers for another.
Teams can adjust Matomo’s collection rules to fit their audience and setup. As traffic patterns change, they can refine those rules without relying on a single detection system to identify every unwanted request. The aim is to give organisations enough visibility and control to understand what they’re collecting and keep known sources of unwanted traffic out of their reports.
Keeping your analytics data clean
Fake traffic isn’t something you fix once and forget about. Keeping your analytics reliable takes regular checks and the occasional bit of investigation.
A few things can help:
- Review sudden traffic spikes instead of assuming they’re real.
- Compare analytics with server logs, CRM data or ecommerce platforms where possible.
- Protect Measurement Protocol credentials and other tracking secrets.
- Use campaign parameters consistently to reduce unnecessary Direct traffic.
- Regularly review referrers, countries and landing pages for unusual patterns.
- Apply bot and spam filtering that matches your organisation’s needs.
- Segment suspicious traffic before deciding whether it should be excluded.
- Periodically audit your analytics implementation to identify tracking errors or duplicate events.
Most importantly, don’t rely on a single metric. Traffic, engagement, conversions, attribution and user behaviour all tell part of the story. Looking at them together provides a much more accurate picture than any individual report ever can.
Conclusion
A spike in traffic should be a good sign. If sales, revenue or engagement don’t move with it, it’s worth finding out why.
Fake traffic now covers much more than obvious spambots. Crawlers, automated browsers, server-side requests and AI agents all add complexity, and they’re getting harder to separate from genuine customer behaviour. The answer isn’t perfect detection. What matters is having enough visibility to spot unusual patterns, understand where they come from and keep them from distorting your reports.
That gives you a clearer picture of the people actually using your website, and better data to base decisions on.
Matomo combines configurable spam protection, powerful segmentation and AI-assisted investigation tools to help you understand what is really happening on your website, so you can make decisions based on cleaner, more trustworthy data.
Start a free Matomo trial and see how it works with your own data.