← All resources

Guide

Why affiliates commit fraud (and how to spot it)

Most partners are honest and valuable. A few learn that the way programs pay creates easy shortcuts. Understanding the incentive makes the evidence much easier to read. For the detection process itself, see our affiliate fraud detection guide.

Where the cookie actually lands

Step through one hijacked order, second by second.

Cookie dropped in the background

A shopping extension fires a click while the checkout page is open. Nothing is shown to the shopper.

The incentives behind it

Last-click pays the last touch

Most programs pay whoever touched the sale last. That rewards being present at checkout more than persuading anyone to buy.

Commission is paid on your sales, not their effort

If a partner can attach themselves to purchases your customers were already making, they earn with almost no cost.

Short review windows

Commissions usually lock 30–90 days after the sale. Many brands never check before then, so bad claims simply get paid.

Low odds of being caught

Network reports are long and a single partner is a small line item. Without cross-checking, patterns stay hidden.

Common schemes and their tells

Cookie stuffing

Why they do it: Drop a tracking cookie on as many visitors as possible, then collect commission on any later purchase — no promotion required.

How to spot it in your reports: Very short click-to-sale times, many conversions from the same IP range, blind or missing referring URLs.

How Sale Defend audits it: Flags sub-60-second click-to-sale as its own finding, groups conversions by shared IP subnet, and notes when traffic origin is missing.

Coupon hijacking

Why they do it: Coupon sites and extensions insert themselves at checkout to take last-click credit for sales someone else drove.

How to spot it in your reports: Referrers from coupon or extension domains, codes used by partners they weren't issued to.

How Sale Defend audits it: Checks referrers against known coupon/extension domains and matches every code against your approved and expired coupon list.

Leaked and expired codes

Why they do it: Private creator codes or retired promotions get posted publicly; whoever posts them earns commission.

How to spot it in your reports: Expired codes still converting, or a partner using another partner's code.

How Sale Defend audits it: Raises expired-code and unknown-code findings from your coupon list, with a per-partner breakdown.

Claiming the same sale twice

Why they do it: When a brand runs several networks or partners, the same order can be claimed more than once.

How to spot it in your reports: One order ID showing up in more than one claim.

How Sale Defend audits it: Reconciles claims by order ID and flags duplicates across partners and networks.

Manufactured volume

Why they do it: Fake or incentivised orders inflate commission before refunds catch up.

How to spot it in your reports: Sudden spikes paired with other tells — repeated order amounts, new partners surging, shared IPs, fast conversions.

How Sale Defend audits it: Compares each partner with the rest of your program. Volume alone stays Low; only combined signals raise severity, and your program profile explains planned peaks.

A signal is not a verdict

Spikes, fast sales and repeated amounts all have honest explanations too. Sale Defend's AI-assisted review weighs the evidence and your program context, and your team decides before any reversal or dispute is raised.