

Ever had someone show up to your wedding, eat the cake, take a picture with the bride, and then fake credit for arranging your marriage?
No, right? But that’s basically what people who do affiliate fraud want you to be okay with.
They want you to pay them a commission for introducing you to customers even when those customers were already going to buy from you. The affiliate just happened to show up at the right moment and put their name on the guest list.
And for brands running affiliate programs, this often happens because of one deceptively simple rule: last click gets the credit.
Think of it like a wedding where whoever talks to the couple last, gets credit for bringing them together, even if they had absolutely nothing to do with the romance. They just showed up five minutes before the vows because they heard there was an open bar.

That’s how affiliate fraud works. A customer might already be planning to buy from you, but a shady affiliate sneaks in at the last moment, takes credit for the sale, and collects a commission. Here’s the definition:
What is affiliate fraud? Affiliate fraud is when a partner in your affiliate program fakes or steals the credit for a sale so they can collect a commission they didn't earn.
This trick often involves cookies- the tiny files stored in a shopper’s browser that help track which affiliate referred them. They’re like those name cards at the reception. Swap the name card just before the wedding, and suddenly the gate-crasher gets the matchmaker’s seat, the applause, and the paycheck.
But why do they go through all that pain? Well, because crashing pays a lot better. One person who recently started working at a fraud-catching company vented it out with utmost clarity-
“The amount of ongoing fraud is unbelievable. Tens to hundreds of thousands of cases every day, affiliates not promoting anything and simply relying on stealing existing traffic from brands and legitimate affiliates, agencies protecting these affiliates and even flat out admitting that it is the way they work.”
The tricky part is that most affiliate marketing scams don't look like crashers at all. The orders and the customers are real, so your commission report looks like the program is still in its honeymoon phase. (Speaking of honey, we'll get to PayPal's coupon extension shortly.)
And eBay found this out the hard way. Its most celebrated guest turned out to be a cookie stuffer whose "referrals" made up 15% of eBay's total affiliate payout. His reception ended with five months in federal prison after he reaped $28 million from the brand.
So, if a company like eBay isn’t immune to affiliate fraud, what are your real options?

As it turns out: many! Let’s take a second look at your guest list.
This guide covers how affiliate program fraud works, how to spot the crashers, and how to prevent affiliate fraud before you pay someone for a match you made yourself.
Stealing credit cards to make sales, bidding on your brand’s keywords, hijacking your attribution, eating your cookies - affiliate fraud shows how creative humans can be when it comes to duping someone.
The affiliate drops their tracking cookie into a shopper's browser without the shopper ever clicking their link. eBay's top affiliate did exactly this with a free widget, and eBay's own complaint said it stuffed 650,000 cookies.
A browser extension (usually a coupon or cashback tool) pops up at checkout and overwrites the cookie of the affiliate who actually sent the shopper. The real matchmaker loses the commission, and you pay a stranger for a sale that was already walking down the aisle.
The affiliate buys from your store through their own link and pockets a commission on their own order. It’s like marrying yourself for the wedding gifts, then sending yourself an invoice for attending. Some affiliate platforms catch this trick by checking whether the buyer and affiliate share an email address or IP address. Sounds harmless when you still keep $85 of a $100 order, right? But that affiliate would very likely have bought anyway, so you’re paying a marketing fee for zero marketing, sometimes on top of the discount their code already handed them. Add a return after the commission clears, and you’ve paid someone to borrow your product.
The affiliate submits junk sign-ups or places orders with stolen cards so the commission triggers. Stolen credit card purchases are listed as among the most common tactics of affiliate fraud. For a merchant, this one stings twice because the chargeback lands on you weeks after the affiliate has been paid.
Bots and click farms can flood your affiliate links with fake clicks. Bots and click farms can flood your affiliate links with fake clicks. If you pay only for completed sales, this can distort your analytics and make it harder to measure genuine affiliate performance. But if you pay per click or lead, you could end up paying for traffic and sign-ups from people who were never real potential customers in the first place.
Some affiliates skip the matchmaking and buy Google ads on your brand name instead. A shopper searches for your store, clicks the affiliate's ad sitting above your own listing, and the affiliate collects a commission on someone who was already looking for you. And it is a pretty common practice in affiliate marketing. One SaaS entrepreneur even called it out on reddit:
“For a while I thought my affiliate program was working really well [...] But after digging deeper into the traffic sources, I realised that they were just brand bidding. They were running Google Ads on our brand name [...] So we ended up paying commission for users I would have already gotten.”
And the bill doesn’t stop at the commission. Google’s ad auction charges you roughly what it takes to beat the next-highest bidder, so when an affiliate bids on your brand name, you pay more per click on your own name just to keep the top spot. That’s two invoices for one guest who was already on the list.
Your private codes (staff discounts, influencer codes, veteran or friends-and-family offers) end up on coupon sites where anyone can grab them. Then the coupon site claims the commission on top of the discount. That's a double hit on margin. PayPal Honey did something similar. After the Honey scandal, trackers saw its user-sourced codes drop sharply, which linked to networks acting on harvested employee, friends-and-family and veteran codes.
But what really happened with Honey?
In December 2024, a YouTube investigation accused PayPal's Honey extension of swapping out creators' affiliate cookies at checkout. According to the creators now suing, Honey replaced their tracking cookie even when it found no coupon at all, so Honey took the last-click commission the creator had earned.
The juiciest allegation is about manners. Affiliate networks typically expect browser extensions to follow a stand-down rule, meaning they should back off when another affiliate has already referred the shopper. The complaint alleges Honey ignored that rule but knew when to behave. According to the allegations, Honey could detect when a network tester or auditor was watching, much like a wedding guest who behaves like an angel whenever the wedding planner walks past.
Still, the fallout came fast in 2026. Rakuten Advertising terminated Honey in January, while Impact.com and Awin suspended it in different ways. On June 22, 2026, the court denied PayPal's motion to dismiss. PayPal disputes the claims, and nothing has been proven yet. Still, Honey's merchant partners have fallen from about 35,000 to just over 28,000, according to third-party trackers.
So how can you identify and save your margins from scammers like these?
Here's where we'd start:
eBay found its cookie stuffers sitting right at the top of its affiliate list. Working with the FBI, eBay set up a sting called "Trip-Wire," a tiny image that only loaded for people who actually spent time on the site. The "referrals" from its two biggest affiliates mostly never tripped it.

You can run a homemade version in your own analytics. Pull your five highest-earning affiliates and compare their referred sessions with your store average. Watch for these warning signs:
If a top affiliate's guests never seem to be inside the venue, ask before you pay.
Affiliate fraud detection tools worth a look
Tools can help, but you need the right bouncer for the right kind of party crasher. Bot-detection tools can catch fake traffic, but they won’t do much about a coupon extension swooping in to steal credit for a perfectly legitimate sale. Here’s a shortlist to get you started.
Note: We’re not affiliated with any of these tools, so check their latest pricing and features before signing up.
Affiliate fraud survives on one assumption, that a sale is finished the moment it's tracked. Merchants know better. Returns, chargebacks, cancellations and support calls keep arriving long after the confetti is swept up, and every one of them changes what that sale was actually worth.
That's the part of the order we care about at SureBright. Our protection plans help merchants earn more from each sale and keep customers coming back after delivery, and that's revenue you never hand to a party crasher. So hold payouts until the vows are truly done, and audit your star guest before anyone else.
Want to see what protection plans could add to your store? Let’s calculate your earning potential on your SKUs.