Affiliate fraud is getting paid for results you did not really produce: fake clicks, fake sign-ups, or credit stolen for sales that would have happened anyway. It costs advertisers money, and when it is found the commissions are reversed and the affiliate is removed, sometimes with legal consequences.
Affiliate fraud covers any attempt to earn commissions for conversions that were not genuinely referred. There are three broad families. Fake actions: bot or form-filling leads, sign-ups with stolen or invented identities, installs from device farms. Attribution theft, in which a real conversion is claimed by someone who did not cause it: cookie stuffing on the web, click injection and click flooding in mobile apps. And disguised rule breaking: undeclared incentive traffic, forbidden brand bidding or cloaked ads.
The attribution tricks are worth understanding because they hide inside normal-looking numbers. Cookie stuffing drops affiliate cookies on a visitor’s browser without a real click, so later purchases are credited to the fraudster. Click flooding, also called click spamming, reports huge numbers of clicks that nobody made, hoping one of them is the last touch before an organic install. Click injection, an Android-specific technique, uses an app already on the device that detects a new installation and fires a click just before the new app opens.
Detection works in layers. Networks and advertisers examine click-to-conversion time distributions, conversion rates impossible for the traffic type, clusters of IPs and devices, data centre and proxy traffic, invalid or duplicated lead data, refund and chargeback rates and the mix of new and returning customers. Mobile measurement partners reject installs with known fraud signatures, and lead buyers verify phone numbers and emails. Confirmed fraud means reversed commissions, withheld payments and termination.
The consequences can be criminal. In the best-known case, two of eBay’s top affiliates were prosecuted for cookie stuffing after eBay worked with the FBI; both pleaded guilty to wire fraud and received prison sentences in 2014. For honest affiliates the practical lesson is to know where traffic comes from: buying from sellers who cannot explain their sources is the most common way legitimate partners end up associated with fraud.
In mid-2006 eBay began working with the FBI to look into affiliates whose results looked too good to be true. Investigators found that Shawn Hogan’s pages made visitors’ browsers load content from eBay’s servers in a way that set his affiliate cookie without any click, so purchases those people later made on eBay were credited to him. Brian Dunning’s company was prosecuted over a similar scheme.
| Defendant | Plea | Sentence |
|---|---|---|
| Shawn Hogan | guilty to one count of wire fraud | five months in prison, 25,000 USD fine, three years of supervised release (2014) |
| Brian Dunning | guilty to wire fraud (2013) | fifteen months in prison (2014) |
Coverage at the time reported that Hogan had received more than 28 million USD in eBay commissions. The case settled that cookie stuffing is not a grey area of affiliate marketing but fraud, and it made advertisers far more willing to audit even their largest partners.
How to judge traffic quality like an operator: spotting bots and fraud, reading engagement, comparing conversion and approval rate by source, sub-I...
Core · 11 min readRisk control for media buyers: capping downside on tests, account and ban risk, creative compliance, cash-flow and payment-term exposure, diversifi...
Advanced · 11 min readHow to diagnose affiliate tracking problems: which tracker, network and platform discrepancies are normal and which are alarming, plus broken postb...
Core · 9 min readHow to vet an affiliate network or program: reputation, payment reliability, tracking quality, offer range, support, minimum payout and the red fla...
Any attempt to earn commissions for conversions that were not genuinely referred, from fake leads and bot clicks to stealing credit for real sales.
Setting affiliate cookies in a visitor’s browser without a real click, so that purchases they make later are credited to the fraudster.
Mobile fraud techniques. Flooding reports masses of fake clicks to catch organic installs; injection fires a fake click on Android just as a new app is installed.
Commissions are reversed or withheld, the affiliate is removed from the program or network, and serious cases can lead to legal action.
References are listed as plain text on purpose; look them up by title and publisher. Updated: 2026-10-09.
Run them inside a network with real tracking, roughly 48-hour payouts and a dedicated manager.
Join the network