- Pay-per-click fraud damages spend; pay-per-action fraud damages attribution — and the second is harder to see, because nothing in the report looks broken.
- The recurring patterns are a short list: click spamming, cookie stuffing, forced clicks, brand-term interception, incentivized and bot traffic, and attribution hijacking. Each leaves its own tell.
- Detection lives in distributions and cohorts, not totals: time from click to conversion, refund rate, repeat-purchase behaviour, and whether device, geography and language agree with each other.
- A single day's anomaly is not evidence. Collect records, compare against a peer baseline, rule out the ordinary explanations, then escalate in steps: ask, hold, restrict, terminate.
What affiliate click fraud actually means
Start by separating it from the search-advertising version. When you pay per click, one invalid click maps to one line of spend, and the loss can be added up click by click — that is the ordinary sense of click fraud. Affiliate programs settle differently: most pay on a sale, a signup or an install, and a click on its own costs nothing.
So fraud on the affiliate side is not about billing you for clicks. It is about occupying the attribution slot. Under last-click attribution, whichever partner recorded the most recent click before a conversion earns the commission. That turns the problem into a simple question: is there a way to get that record in first, at scale, on users who were going to convert regardless? There is, and there is more than one. The wider taxonomy is in the main types of ad fraud; this article stays on the affiliate branch.
The test for affiliate fraud is not whether a human clicked. It is whether the partner had anything to do with the conversion. Plenty of fraudulent traffic comes from real devices and real people — people who have no idea a click was recorded on their behalf.
The patterns programs actually see
A short list recurs. Recognise the shapes first, then the signals.
1. Click spamming. Click records are generated for large numbers of users who never knowingly clicked anything — typically from low-quality sites, extensions or apps. It does not rely on any single click working. It relies on volume: if anyone in that pool converts on their own inside the attribution window, the credit lands. This is what terms like click spamming and false clicks usually point at.
2. Cookie stuffing. A visitor merely opens a page, the page quietly loads affiliate tracking links in the background, and the attribution cookie is written. The user saw no ad and clicked nothing. It usually carries one giveaway: nearly all of that partner's clicks come from invisible loads rather than from visible landing-page sessions.
3. Forced clicks and auto-redirects. Pop-ups, pop-unders, full-page redirects, or a click target laid over another control, so the user triggers an affiliate link while trying to do something else. The interaction is genuine; it is just not the interaction the user intended.
4. Brand-term interception. A partner bids on your own brand terms, intercepts users who were already searching for you, and hands them over with a commission attached. It is not always technical fraud, but most program terms prohibit it, because what it buys is demand that was already yours.
5. Incentivized and bot traffic. Rewards exchanged for clicks or signups, and traffic produced outright by scripts. The first brings people who will never buy again; the second brings people who do not exist. Telling them apart is a behavioural question — see detecting bot traffic — and the measurement definitions are in GIVT and SIVT.
6. Attribution hijacking. A last click inserted at the moment a conversion is about to happen — on the checkout page, or on a coupon page reached mid-purchase. This is the hardest to catch, because the conversions it claims are real. Everything in the data is fine except the column that says where it came from.
Why the affiliate model attracts this
Three structural reasons. First, last-click attribution turns a record into money, and records are far cheaper to produce than conversions. Second, programs usually run dozens or hundreds of partners, so any one partner is small enough for an anomaly to disappear into the total. Third, verification lags payment: refunds, chargebacks and cancellations come back a settlement cycle later, by which point the commission may already be out the door.
Together they explain a familiar picture: program-level return looks acceptable, but broken out by partner, a few of them bring customers who are visibly worse than everyone else's — while their share of commission keeps rising.
The signals that expose it
No single metric decides anything. What works is reading several signals together, and always against a peer baseline rather than a threshold someone picked by feel.
| Signal | What it looks like when something is wrong | Innocent explanations to rule out first |
|---|---|---|
| Time from click to conversion | Spread flat across the whole attribution window, sometimes rising toward the end — the click and the conversion are not causally linked | High-consideration, high-ticket categories genuinely convert late |
| Click volume versus conversion rate | Clicks surge while conversion rate collapses to a fraction of peers | A new upper-funnel placement, or a brand campaign that drives reach |
| Customer quality (refunds, chargebacks, repeat purchase) | That partner's cohorts refund more and almost never buy again | A discount push or coupon promotion lowers quality on its own |
| Coherence of device, geography and language | Geography, language, timezone and device model do not agree — or repeat far too uniformly | VPNs, corporate proxies and genuinely cross-border users exist |
| Visibility of the traffic source | The partner cannot name the placement, or the referring page is unreachable or unrelated to what was described | Some sources genuinely strip referrers (in-app, encrypted redirects) |
| Movement against direct traffic | A partner scales while direct and organic fall by a matching amount | Seasonality and big promotions move several channels at once |
That third column is not a courtesy. The most common mistake programs make is not missing fraud — it is treating ordinary variance as fraud and cutting a partner who was genuinely producing. Every signal gets the ordinary explanation tested first.
Turning detection into a routine
Ad-hoc investigations do not catch persistent problems; only a fixed cadence does. Four things make a routine sufficient.
- Keep raw records. Per-click rows you can query: timestamp, source, device, geography, destination, and whether a conversion followed. With aggregates only, none of the later analysis is possible.
- Baseline per partner. What normal looks like is defined by a partner's own history and by comparable peers — not by the program-wide average.
- Look back by cohort. After the settlement cycle closes, revisit those customers' refunds, chargebacks and repeat purchases, and reconcile what was paid against what it turned out to be worth.
- Fix the review cadence. Trends weekly, cohorts monthly, and new partners reviewed more closely for their first two settlement cycles. An anomaly counts only if it holds across several periods.
The platform's own invalid-traffic filtering is a separate system and will not reconcile line by line with your judgment — that difference is unpacked in how invalid clicks get classified. Exposure also varies a great deal by vertical; see click fraud risk by industry.
What to do once a partner trips a signal
Escalate in steps, each demanding harder evidence. Step one: ask. Request the specific placements, referring pages and method. An inability to describe the source is itself information. Step two: hold. Put the commission in review without ending the relationship, and preserve the raw records. Step three: restrict. Narrow the permitted traffic types or methods and observe for one full settlement cycle. Step four: terminate. Only on documented, reproducible evidence.
The ladder is worth taking slowly because the costs are asymmetric: one extra cycle of commission can often be recovered, while a productive partner you cut usually cannot. Whether the partner's own pages are compliant, and whether the destination matches what was described, is a separate line of verification — covered in partner page compliance monitoring.
Measurement hygiene underneath all of it
All of the above rests on one assumption: that your own data is trustworthy. Three baseline requirements. First, attribution windows and definitions are written down and shared, so partners and you are reading the same rules. Second, conversions are reported server-side where possible, rather than depending on client-side signals that are easy to rewrite. Third, every visitor gets the same landing-page URL and the same content — a consistent destination is what makes click records comparable in the first place, and it is also the least effortful compliance position.
One clarification worth making: malicious clicks do not only come from partners. Competitor-driven clicking against paid campaigns is a different problem with different handling — see competitor click fraud.
FAQ
Want a clear record of every visit?
ROAS365 provides visitor routing with a per-visit record of what happened, so you can check every arrival by device, geography and source.