Skip to main content

Compliance

Cookie Stuffing (Affiliate Fraud)

A form of affiliate fraud in which a publisher sets affiliate tracking cookies on consumers' browsers without those consumers clicking the publisher's affiliate link, allowing the publisher to earn commission on purchases the consumer would have made regardless of any publisher involvement. Cookie stuffing is the most prevalent form of affiliate fraud by commission damage volume. How cookie stuffing works: publisher embeds code on a website, in a browser extension, or in other digital property that automatically fires affiliate tracking URLs when consumers visit; these tracking URLs set affiliate cookies in the consumer's browser without any visible affiliate link click; when the consumer subsequently purchases from the brand (through direct navigation, search, or any other channel), the affiliate cookie attributes the sale to the cookie-stuffing publisher; the publisher earns commission on a conversion they had no role in driving. Detection signals: click-to-conversion timing where conversions occur within seconds or minutes of the 'click' (because the cookie is dropped during an active checkout session); abnormally high conversion rates (5-20%+ in programs with 1-3% averages); publisher generates large commissions but has no verifiable traffic source. Cookie stuffing is a violation of every major affiliate network's terms of service and US computer fraud laws (Computer Fraud and Abuse Act); confirmed cookie stuffing warrants publisher termination, commission reversal, and potentially legal action. Network detection: Impact Protect, Awin's compliance tools, and CJ's fraud detection all include cookie stuffing detection; brands should activate these tools and review flags before reversing commissions to avoid false positives.