How to Detect and Prevent Affiliate Fraud

Jamal Brooks·6 min read
Security dashboard showing fraud detection alerts

Key Takeaways

  • Most affiliate fraud is theft of attribution rather than theft of money: partners claiming credit for sales that were happening anyway
  • The most diagnostic metric is the ninety-day behaviour of the customers each affiliate refers, compared against your organic baseline
  • You cannot detect an anomaly without a baseline, so establish your own medians before setting any thresholds
  • Paying on completed, non-refunded orders after a thirty-day hold removes the incentive behind most schemes at almost no cost to honest partners
  • Contact a partner before accusing them: a meaningful share of anomalies turn out to be a misconfigured pixel

Affiliate fraud is not usually a dramatic heist. It is a slow leak: a partner whose conversion rate is a little too good, traffic that arrives at three in the morning in perfect uniformity, a spike of signups that never buy anything. By the time it is obvious, you have paid out for months.

The useful mental model is that affiliate fraud is theft of attribution rather than theft of money. Almost nobody manufactures a fake sale, because a fake sale gets refunded and reverses the commission. What they do is claim credit for sales that were going to happen anyway. That distinction changes everything about how you detect it, because the revenue looks completely normal. Only the attribution is wrong.

The types, and what each one actually looks like in your data

The most common and the hardest to see. The fraudster drops your affiliate cookie on visitors who never clicked an affiliate link, typically through hidden iframes, image pixels, or a browser extension they control. Anyone who later buys from you is credited to them.

What it looks like: a very high conversion rate paired with very low engagement. Thousands of clicks, almost no time on site, and conversions that skew heavily toward your existing customers and branded search traffic. The tell is that their "referred" customers behave exactly like your organic customers, because they are your organic customers.

Detection: compare the referring URL on click events against the affiliate's declared properties. A stuffing operation generates clicks with no plausible referrer, or referrers on domains that have nothing to do with the partner. Also check the interval between click and conversion. Genuine affiliate traffic clicks and buys within a session or over days. Stuffed cookies produce conversions seconds after a "click" the user never made.

Click fraud and bot traffic

Automated clicks to inflate metrics, either to hit a volume bonus, to build a plausible-looking traffic history before the real fraud, or to exhaust a competitor's budget in a pay-per-click program.

What it looks like: uniformity. Real human traffic has a shape, with peaks in the target market's waking hours and troughs overnight. Bot traffic is flat across twenty four hours. Device and browser fingerprints repeat far more than they should. Click intervals cluster around suspiciously round numbers.

Detection: plot clicks by hour of day for each affiliate against the distribution of your organic traffic in the same geography. The difference is usually visible without any statistics.

Fake leads and incentivised signups

Relevant if you pay per lead or per signup rather than per sale. The partner generates accounts that satisfy your payout condition and nothing beyond it.

What it looks like: a cohort that converts to paid at close to zero, disposable email domains, sequential or templated names, and signup timestamps clustered into bursts.

Detection: cohort every affiliate's referred users and track them forward past the payout event. Any partner whose cohort has an activation rate far below your baseline is producing leads that satisfy your metric and not your business.

Brand bidding and coupon hijacking

A partner bids on your brand name in paid search, or ranks a page for "yourbrand coupon", intercepting customers who were already coming to you and were typing your name.

What it looks like: conversions with extremely short click-to-purchase intervals, concentrated on branded terms, from users who had already visited you before.

Detection: this one requires a policy first. If your terms do not prohibit brand bidding, it is not fraud, it is a partner exploiting a gap you left open. Write the rule, then enforce it with paid search monitoring.

Self-referral

A partner buying through their own link for the discount, or recruiting friends to do so.

Detection: match payment fingerprints, shipping addresses and account details between the affiliate and their referred conversions. Modest in volume, easy to catch, and worth catching because it is usually an early signal about the partner.

Building detection that actually runs

Manual review does not scale past a couple of dozen partners. What works is a small set of automated checks that flag for human attention.

Baseline first. You cannot detect an anomaly without a normal. For your program, establish the median and spread of:

  • Conversion rate per affiliate

  • Time from click to conversion

  • Refund and chargeback rate on referred orders

  • Repeat purchase rate of referred customers at ninety days

  • Geographic distribution of clicks relative to conversions


Then flag on deviation, not on absolute numbers. A five percent conversion rate is excellent for one program and impossible for another. What matters is the distance from your own baseline.

The single most useful metric is the one most programs never look at: the ninety-day value of the customers each affiliate refers. Fraudulent attribution produces customers who behave like your average organic customer, because they are. Genuinely incremental affiliate traffic produces customers who look slightly different, often with a different product mix. A partner whose referred customers are indistinguishable from your organic base, at high volume, is a partner worth investigating.

Prevention that does not scare off good partners

Every anti-fraud control has a cost in partner experience, and a program nobody wants to join has solved fraud by having no affiliates.

Worth doing, low friction:

  • A holding period before payout. Thirty days covers most refund windows and costs honest partners nothing but patience. Communicate it clearly at signup so it is not a surprise.

  • Pay on completed and non-refunded orders, not on order placement. This alone removes the incentive for most fake-sale schemes.

  • Verified payout details. Requiring a verified payment method before the first payout blocks the throwaway-account pattern entirely.

  • Written program terms covering brand bidding, coupon sites, incentivised traffic and cookie duration. Most disputes come from rules that were never written down.


Worth doing, moderate friction:

  • Manual approval for new partners, with a look at their actual properties. Two minutes per application removes a large share of the problem.

  • Tiered trust. New partners get a longer hold and a lower cap; established partners get faster payouts. This rewards the people you want and constrains the people you do not.


Usually counterproductive:

  • Blanket geographic blocking, which removes legitimate partners along with the problem.

  • Aggressive automated suspension without review, which destroys relationships with good partners over a single unusual week.


What to do when you find it

1. Freeze the payout, do not delete the data. You will need the history to size the exposure and to defend the decision.
2. Quantify the period. Look for the point where their metrics diverged from baseline, which is usually well before you noticed.
3. Contact the partner before accusing them. A meaningful share of anomalies turn out to be a misconfigured tracking pixel or a legitimate traffic source you did not know about. The conversation costs you nothing and occasionally saves a good relationship.
4. If it is genuine fraud, reverse and document. Reverse the affected commissions under your written terms, keep the evidence, and remove the partner.
5. Then fix the gap that allowed it. Fraud that succeeded once succeeded because of a specific structural weakness. Close it before the next partner finds it.

The tracking foundation

Everything above depends on having click and conversion data you actually trust. If your attribution is built on third-party cookies, a growing share of your traffic is already invisible, and fraud detection on partial data produces both false positives and missed cases.

First-party tracking, where the click is recorded on your own domain and the conversion is stamped server-side at the point the payment settles, gives you a dataset where the anomalies are real. It also gives you the click-to-settlement timeline that makes cookie stuffing visible.

For the broader picture of building a program where these controls fit naturally, see the guide to starting an affiliate program, and for the payout mechanics that reduce fraud exposure, the affiliate payout strategies piece covers holding periods and thresholds in more detail.

The uncomfortable summary

Most programs lose more to attribution theft than to outright fake sales, and most programs do not measure attribution theft at all. If you only do one thing from this article, cohort your affiliates by the ninety-day behaviour of the customers they refer. The partners claiming credit for sales you would have made anyway will stand out immediately, and they are almost certainly costing you more than the obvious fraudsters ever will.

fraudsecurityaffiliate-marketingtracking

Written by Jamal Brooks

Jamal is a product engineer at Affiliateo who writes about payments, integrations, and technical best practices.

Frequently Asked Questions

Related Articles