A Field Guide to Affiliate Fraud: Eight Schemes and the Tells That Expose Them
Self-referrals, cookie stuffing, coupon leaks, click spam, stolen-card laundering — what each scheme looks like in your data, ranked by how often small programs actually meet them.
Most affiliate fraud writing is network-scale — botnets, attribution hijacking at millions of clicks. A self-hosted store program meets a humbler set of schemes, and knowing their shapes turns fraud review from anxiety into pattern-matching. Here's the field guide, ordered by how often small programs actually encounter each; the operational playbook covers what to do about them.
The everyday three
1. Self-referral. The partner buys through their own link, converting your commission into a personal discount. The most common scheme because it barely feels like one — many first-timers assume it's a perk. Tells: matching emails or payment names, referral and purchase from the same address, a partner whose only referrals are occasional and personal-sized. Handle by policy (blocked, stated in your terms) and by software that flags identity overlaps automatically. First offense is usually education, not expulsion.
2. Friends-and-family rings. Self-referral with extra steps: a small circle buys through each other's links, sometimes refunding after commissions clear. Tells: a tight cluster of new customers appearing together, similar order patterns, refund timing that hugs your maturity window. The fix is less detection than economics — a maturity period outlasting your refund window makes the scheme unprofitable.
3. Coupon leaking and scraping. A partner publishes codes never assigned to them — support-gesture codes, another partner's exclusive, an internal promo — or a deal site scrapes and monetizes them. Costs you margin and misroutes attribution. Tells: a code redeeming far beyond its intended audience, spikes from traffic sources that make no sense for the code's owner. Prevention is structural: per-partner codes as the only commission-bearing codes, and the coupon-site rules in writing.
The occasional three
4. Cookie stuffing. Forcing your referral cookie onto visitors who never meaningfully clicked — hidden iframes, redirect chains, auto-firing scripts — so the fraudster collects credit for organic sales that were coming anyway. Tells: a partner with implausible click volume, conversion rates below organic (they're claiming everyone), and no visible content that could produce the traffic. Ask where the traffic comes from; real partners answer easily.
5. Brand-jacking traffic. Search ads on your own brand name, typosquatted domains, or social profiles impersonating your store — all reselling you your own demand. Tells: too-clean conversion rates, referral bursts matching ad schedules, and what your monthly incognito search reveals.
6. Application fraud. Fake or stolen identities applying at volume — bots hunting weak programs, or one person amassing multiple accounts to dodge a ban or double-dip a bonus. Tells: disposable-email domains, boilerplate answers, several applications sharing infrastructure fingerprints. A review-before-approve policy plus CAPTCHA at the application form filters most of it at the door.
The serious two
7. Stolen-card laundering. Referred "sales" placed with stolen payment details; the commission is the fraudster's cash-out, and the chargebacks arrive after payout. Tells: a new partner producing rapid orders from mismatched geographies, high-value carts, rush of first-time customers who never return. This one involves real third-party victims — when it appears, freeze payouts immediately, document everything, and treat it as the payment-fraud incident it is, not a program dispute.
8. Return fraud at scale. Systematic buy-earn-refund cycles across enough identities to look like separate customers. Rare against stores with sane maturity windows, but the reason your window and your negative-balance policy exist as written policy rather than improvisation.
The meta-lesson across all eight: fraud leaves patterns, and patterns need records. A program whose every referral carries its origin, timing, and history — and whose review queue explains why something was held, the way Affiliate Factory WP's explainable review does — turns each scheme above into a recognizable shape instead of a bad feeling. The demo shows what held-with-reasons looks like; the prevention playbook picks it up from there.