Ads opening the SHEIN site on their own — the cause, what didn't work, and what we're doing now
Published: October 8, 2026 / App: iCap / Status: in progress
Summary: this is not a bug in the app. Some of the ads shown in the app were built to open their link without being tapped.
Most cases between September 23 and 27 came from ads delivered by Unity Ads, and they almost stopped on September 28. Reports kept coming in October, though, likely through a different route. Between October 6 and 8 I set each ad network to stop SHEIN ads, and I'm checking whether it works.
Correction and apology: In the in-app news, the guide article and replies to reviews, I said that the settings added on September 30 and October 4 "stopped these ads from being shown" or "excluded them". In fact, those settings only detect matching ads and mark them as "needs review"; they do not stop the ads from being served. Stopping them required a separate block request to the ad network (confirmed with the ad network on October 8). I gave you incorrect information, and I'm sorry.
What happened
While people were simply using the app, without tapping anything, Safari opened and went to the SHEIN (online fashion store) site. Reports say it happened, for example, "the moment the ad at the bottom turned into SHEIN while I was watching a saved video" or "while a video was being saved" — times when the screen wasn't being touched.
The addresses people sent me contained a number showing the page was opened from an iCap ad slot (iCap's App Store ID), which confirmed it came from an ad shown in iCap.
How often it happened
The ad management dashboard has a report that counts "how many times ads opened their link by themselves" for some ad networks (Auto Redirects Report). These are the numbers for iCap's banner ads.
| Date | Auto-redirects (via Unity Ads, iCap) |
|---|---|
| Sep 7–21 | iCap 1–208 per day |
| Sep 23 | iCap 911 |
| Sep 24 | iCap 1,180 |
| Sep 25 | iCap 985 |
| Sep 26 | iCap 1,511 |
| Sep 27 | iCap 1,575 |
| Sep 28 | iCap 2 |
| Sep 29 | iCap 1 |
| Sep 30 – Oct 7 | iCap 0 |
On the worst day, September 27, there were 1,575 auto-redirects against roughly 760,000 Unity Ads banner impressions — about one in every 480 impressions. However, this report covers only some ad networks. AppLovin Exchange, which accounts for roughly 75–80% of iCap's ad revenue, is not included (confirmed with the ad network on October 8). So "0 since September 30" means 0 via Unity Ads, not that it stopped happening altogether.
Cause
App developers don't pick each ad one by one. The app provides an ad "slot", and the ad network decides what goes in it each time. Today's ads are shown as small web pages and can contain code. An ad should open its link only when tapped, but some ads were built to "pretend they were tapped" and open the link as soon as they were shown. The app itself does not open the site, and such ads break the ad networks' own rules.
- The surge on September 23–27: SHEIN banner ads delivered by Unity Ads (one of iCap's ad networks). The ad log (Ad Review) also recorded Unity Ads SHEIN banners during this period.
- Reports since October 3: These don't appear in the Unity Ads numbers. The ad log contains one ad via AppLovin Exchange that "looks like another company's ad but is registered as a SHEIN ad". I think this route is likely, but it is not confirmed (an assumption).
- The opened addresses went through a click-tracking redirect before reaching the SHEIN site.
Other app developers have reported the same kind of problem for a long time; it can happen in any app that shows ads.
What I did, and whether it worked
| Date | Measure | Did it work? |
|---|---|---|
| Sep 30 | Registered shein.com and m.shein.com as "risky destinations" in the ad log tool (AppLovin Ad Review) | It did not stop serving. The feature only detects matching ads and marks them as "needs review"; stopping them requires a separate block request. The Unity Ads cases had already stopped two days earlier (September 28) |
| Oct 4 | Added onelink.shein.com (a click-tracking redirect) to the same feature | Same as above (did not stop serving) |
| Oct 6 | Asked AppLovin to stop the ads; shein.com, m.shein.com and onelink.shein.com were blocked on the account | Works for AppLovin ads, but only for ads whose registered destination matches. Ads with an empty destination slip through. One more report came in around 0:30 on October 7 (JST) |
| Oct 8 | In Unity Ads, blocked the SHEIN ads individually and blocked the advertiser (SHEIN's app and site) | Checking |
| Oct 8 | AppLovin blocked ads promoting SHEIN's iOS app at the app level (AppLovin Exchange, AppLovin Bidding, AppLovin Network) | Checking. Expected to also catch ads with an empty destination |
The drop on September 28 was not the result of my settings. It stopped before the September 30 registration, most likely because the advertiser ended the campaign or the ad network stepped in (an assumption). At first I linked "I added a setting" with "it stopped", and I also misunderstood what the setting did.
Current status (as of October 8)
- The two ad networks that make up most of iCap's ad revenue (AppLovin and Unity Ads) now have settings to stop SHEIN ads.
- The remaining network (Meta, a few percent of revenue) has not been handled yet.
- I can't say it has stopped yet. I'll add the results here after looking at reports and the ad log from October 9 on.
If it happens to you
- Don't enter anything on the page that opened (login, address, card details).
- Close the Safari tab and go back to the app with "◀︎" at the top left, or from the Home Screen. A page simply opening does not normally install anything or read your data.
- There's no need to delete the app (deleting it may also delete what you've saved).
- If it happens again, please send roughly when it happened and the address of the page that opened (or a screenshot) from the app's Settings tab → About this app → Email a bug or request. It's the best clue for finding which ad network served the ad.
What comes next
- Stopping these ads comes before ad revenue. umebo's free apps are funded by ads, but ads that make you do something you didn't intend have no place in them.
- For each new report, I'll identify the ad network from the time and address, then block and report the ad there.
- There are reports that shorter ad refresh intervals mean running into such ads more often. I'll review the interval too.
What I learned
- "I added a setting" and "it stopped" are different things. From now on I'll confirm what a setting actually does — from the official documentation and the ad network — before announcing it.
- The auto-redirect report covers only some ad networks. A zero there doesn't mean it isn't happening elsewhere. Reports from you (time and address) are essential.
For how it works and what to do when it happens in other apps, see Why app ads send you to SHEIN on their own (in Japanese).
Terms
- Ad network: a company that decides which ad goes into an app's ad slot and delivers it. iCap receives ads from several networks, including AppLovin (MAX, Exchange), Unity Ads and Meta.
- Ad Review: AppLovin's tool for logging and reviewing ads shown in an app. It logs a sample of ads, not all of them.
- Auto Redirects Report: the part of Ad Review that counts how often ads opened their link by themselves. It covers only some ad networks.
Sources: AppLovin Ad Review Auto Redirects Report (iCap, Unity Ads Bidding, banner; checked October 7, 2026), the ad log (Creatives), and replies from AppLovin support (October 6 and 8). These numbers do not include the number of users, so I can't say what percentage of users were affected.