By the early 2000s, spam had become ubiquitous in our everyday interactions with email and the internet. Promises of untold riches, cheap Viagra, and other hoaxes were everywhere. But were the spammers actually making money from their claims? To find out, Stefan Savage at UC San Diego, ICSI researcher Vern Paxson, and others teamed up to trace the value chain from false promises to fraudulent profits. 

In a fruitful collaboration from 2003-2015 with support from the Office of Naval Research, the National Science Foundation, and other funders, the group turned the tables on spammers by infiltrating the botnet systems they used to sell counterfeit products. In one project, the team altered commands within a botnet to direct spam click-throughs to a site set up by the researchers instead of to the spammers’ own sites. This experiment revealed that it took around 12.5 million spam emails to generate one purchase, and that the average amount paid was around $100. All told, they estimated that a typical spammer operating in this fashion could take in around $3.5 million per year, minus payments to affiliates providing the counterfeit products. 

The researchers later comprehensively mapped all of the steps involved in spam payments, documenting their findings in a paper recognized with the prestigious IEEE Security & Privacy “Test of Time” Award. This research revealed that almost all of the payments for counterfeit products sold online were processed by just three banks. Based on this insight, federal cybercrime organizations shifted their focus to stopping banks from processing purchases for certain products without a credit card present, a move that effectively demonetized many spammers’ schemes, causing them to fold up shop. 

This story was published in January 2026 as part of a retrospective series highlighting ICSI’s accomplishments and impacts over the years. To learn about our ongoing work, explore our Core Research Themes.