Detection

Affiliate click fraud: how it happens and how programs detect it

By the ROAS365 team·9 min read

Click fraud in an affiliate program does not look like click fraud in search advertising. When you pay per click, fake clicks burn money and the bill shows it. When you pay per action, fake clicks cost nothing on their own — they do something else. They place a partner in the credit path for conversions that were going to happen anyway. The commission still gets paid, the dashboard still looks healthy, and the only thing that is wrong is who gets the credit — which is enough to steer the next round of budget in the wrong direction. This article covers the patterns programs actually encounter, the signals each one leaves behind, and how to turn detection into a routine that is repeatable and survives its own false positives.

TL;DR
  • Pay-per-click fraud damages spend; pay-per-action fraud damages attribution — and the second is harder to see, because nothing in the report looks broken.
  • The recurring patterns are a short list: click spamming, cookie stuffing, forced clicks, brand-term interception, incentivized and bot traffic, and attribution hijacking. Each leaves its own tell.
  • Detection lives in distributions and cohorts, not totals: time from click to conversion, refund rate, repeat-purchase behaviour, and whether device, geography and language agree with each other.
  • A single day's anomaly is not evidence. Collect records, compare against a peer baseline, rule out the ordinary explanations, then escalate in steps: ask, hold, restrict, terminate.

What affiliate click fraud actually means

Start by separating it from the search-advertising version. When you pay per click, one invalid click maps to one line of spend, and the loss can be added up click by click — that is the ordinary sense of click fraud. Affiliate programs settle differently: most pay on a sale, a signup or an install, and a click on its own costs nothing.

So fraud on the affiliate side is not about billing you for clicks. It is about occupying the attribution slot. Under last-click attribution, whichever partner recorded the most recent click before a conversion earns the commission. That turns the problem into a simple question: is there a way to get that record in first, at scale, on users who were going to convert regardless? There is, and there is more than one. The wider taxonomy is in the main types of ad fraud; this article stays on the affiliate branch.

Key point

The test for affiliate fraud is not whether a human clicked. It is whether the partner had anything to do with the conversion. Plenty of fraudulent traffic comes from real devices and real people — people who have no idea a click was recorded on their behalf.

The patterns programs actually see

A short list recurs. Recognise the shapes first, then the signals.

1. Click spamming. Click records are generated for large numbers of users who never knowingly clicked anything — typically from low-quality sites, extensions or apps. It does not rely on any single click working. It relies on volume: if anyone in that pool converts on their own inside the attribution window, the credit lands. This is what terms like click spamming and false clicks usually point at.

2. Cookie stuffing. A visitor merely opens a page, the page quietly loads affiliate tracking links in the background, and the attribution cookie is written. The user saw no ad and clicked nothing. It usually carries one giveaway: nearly all of that partner's clicks come from invisible loads rather than from visible landing-page sessions.

3. Forced clicks and auto-redirects. Pop-ups, pop-unders, full-page redirects, or a click target laid over another control, so the user triggers an affiliate link while trying to do something else. The interaction is genuine; it is just not the interaction the user intended.

4. Brand-term interception. A partner bids on your own brand terms, intercepts users who were already searching for you, and hands them over with a commission attached. It is not always technical fraud, but most program terms prohibit it, because what it buys is demand that was already yours.

5. Incentivized and bot traffic. Rewards exchanged for clicks or signups, and traffic produced outright by scripts. The first brings people who will never buy again; the second brings people who do not exist. Telling them apart is a behavioural question — see detecting bot traffic — and the measurement definitions are in GIVT and SIVT.

6. Attribution hijacking. A last click inserted at the moment a conversion is about to happen — on the checkout page, or on a coupon page reached mid-purchase. This is the hardest to catch, because the conversions it claims are real. Everything in the data is fine except the column that says where it came from.

Why the affiliate model attracts this

Three structural reasons. First, last-click attribution turns a record into money, and records are far cheaper to produce than conversions. Second, programs usually run dozens or hundreds of partners, so any one partner is small enough for an anomaly to disappear into the total. Third, verification lags payment: refunds, chargebacks and cancellations come back a settlement cycle later, by which point the commission may already be out the door.

Together they explain a familiar picture: program-level return looks acceptable, but broken out by partner, a few of them bring customers who are visibly worse than everyone else's — while their share of commission keeps rising.

The signals that expose it

No single metric decides anything. What works is reading several signals together, and always against a peer baseline rather than a threshold someone picked by feel.

Signal What it looks like when something is wrong Innocent explanations to rule out first
Time from click to conversion Spread flat across the whole attribution window, sometimes rising toward the end — the click and the conversion are not causally linked High-consideration, high-ticket categories genuinely convert late
Click volume versus conversion rate Clicks surge while conversion rate collapses to a fraction of peers A new upper-funnel placement, or a brand campaign that drives reach
Customer quality (refunds, chargebacks, repeat purchase) That partner's cohorts refund more and almost never buy again A discount push or coupon promotion lowers quality on its own
Coherence of device, geography and language Geography, language, timezone and device model do not agree — or repeat far too uniformly VPNs, corporate proxies and genuinely cross-border users exist
Visibility of the traffic source The partner cannot name the placement, or the referring page is unreachable or unrelated to what was described Some sources genuinely strip referrers (in-app, encrypted redirects)
Movement against direct traffic A partner scales while direct and organic fall by a matching amount Seasonality and big promotions move several channels at once

That third column is not a courtesy. The most common mistake programs make is not missing fraud — it is treating ordinary variance as fraud and cutting a partner who was genuinely producing. Every signal gets the ordinary explanation tested first.

Turning detection into a routine

Ad-hoc investigations do not catch persistent problems; only a fixed cadence does. Four things make a routine sufficient.

The platform's own invalid-traffic filtering is a separate system and will not reconcile line by line with your judgment — that difference is unpacked in how invalid clicks get classified. Exposure also varies a great deal by vertical; see click fraud risk by industry.

What to do once a partner trips a signal

Escalate in steps, each demanding harder evidence. Step one: ask. Request the specific placements, referring pages and method. An inability to describe the source is itself information. Step two: hold. Put the commission in review without ending the relationship, and preserve the raw records. Step three: restrict. Narrow the permitted traffic types or methods and observe for one full settlement cycle. Step four: terminate. Only on documented, reproducible evidence.

The ladder is worth taking slowly because the costs are asymmetric: one extra cycle of commission can often be recovered, while a productive partner you cut usually cannot. Whether the partner's own pages are compliant, and whether the destination matches what was described, is a separate line of verification — covered in partner page compliance monitoring.

Measurement hygiene underneath all of it

All of the above rests on one assumption: that your own data is trustworthy. Three baseline requirements. First, attribution windows and definitions are written down and shared, so partners and you are reading the same rules. Second, conversions are reported server-side where possible, rather than depending on client-side signals that are easy to rewrite. Third, every visitor gets the same landing-page URL and the same content — a consistent destination is what makes click records comparable in the first place, and it is also the least effortful compliance position.

One clarification worth making: malicious clicks do not only come from partners. Competitor-driven clicking against paid campaigns is a different problem with different handling — see competitor click fraud.

FAQ

How is affiliate click fraud different from ordinary PPC click fraud?
PPC costs you money per click, so the damage sits on the spend side and the bill shows it. Affiliate models pay per action, so clicks usually cost nothing directly; the damage sits in attribution — commission paid to a partner that did not cause the conversion, and reporting that credits the wrong channel. One inflates a bill, the other quietly misdirects budget.
What is click spamming in an affiliate context?
It means generating click records in volume for users who never knowingly clicked, so that any conversion happening later inside the attribution window is credited to that partner. The tell is a very large click count with a very low conversion rate, plus a click-to-conversion time distribution spread flat across the window instead of clustering in the first minutes and hours.
Can I detect affiliate click fraud from platform reports alone?
Rarely with confidence. Reports give you totals, while the identifying evidence lives in distributions and cohorts: click-to-conversion timing, refund and chargeback rates split by partner, whether that partner's customers ever buy again, and whether device, geography and language agree. All of that needs per-click records you can group and compare, not one aggregate row.
What should happen when a partner trips a detection signal?
Collect evidence before acting. Preserve the raw records, compare the partner against peers over the same period, and check whether an ordinary explanation fits — a new placement, seasonality, a tracking change. Then escalate in steps: ask, hold the payout for review, restrict, and terminate only on documented evidence. Acting on one day's anomaly is the main way programs lose good partners.

Want a clear record of every visit?

ROAS365 provides visitor routing with a per-visit record of what happened, so you can check every arrival by device, geography and source.

← Back to all articles