Cookie stuffing
Why they do it: Drop a tracking cookie on as many visitors as possible, then collect commission on any later purchase — no promotion required.
How to spot it in your reports: Very short click-to-sale times, many conversions from the same IP range, blind or missing referring URLs.
How Sale Defend audits it: Flags sub-60-second click-to-sale as its own finding, groups conversions by shared IP subnet, and notes when traffic origin is missing.
Coupon hijacking
Why they do it: Coupon sites and extensions insert themselves at checkout to take last-click credit for sales someone else drove.
How to spot it in your reports: Referrers from coupon or extension domains, codes used by partners they weren't issued to.
How Sale Defend audits it: Checks referrers against known coupon/extension domains and matches every code against your approved and expired coupon list.
Leaked and expired codes
Why they do it: Private creator codes or retired promotions get posted publicly; whoever posts them earns commission.
How to spot it in your reports: Expired codes still converting, or a partner using another partner's code.
How Sale Defend audits it: Raises expired-code and unknown-code findings from your coupon list, with a per-partner breakdown.
Claiming the same sale twice
Why they do it: When a brand runs several networks or partners, the same order can be claimed more than once.
How to spot it in your reports: One order ID showing up in more than one claim.
How Sale Defend audits it: Reconciles claims by order ID and flags duplicates across partners and networks.
Manufactured volume
Why they do it: Fake or incentivised orders inflate commission before refunds catch up.
How to spot it in your reports: Sudden spikes paired with other tells — repeated order amounts, new partners surging, shared IPs, fast conversions.
How Sale Defend audits it: Compares each partner with the rest of your program. Volume alone stays Low; only combined signals raise severity, and your program profile explains planned peaks.