This Is Not Just Another Fraud Story

Phia’s shopping app allegedly opened a hidden tab on people’s phones, fired affiliate links that nobody ever clicked, and billed merchants for sales it did nothing to earn.

It did this quietly for seven months. Right through the holiday season.

If you work in affiliate marketing and you scrolled past this story, you need to scroll back. Because what Phia allegedly did is not the same as what Honey was accused of doing. Honey was accused of hijacking an existing click and taking credit for someone else’s work. Phia allegedly manufactured clicks that never happened. Real money out of merchants’ pockets. Commissions stolen from publishers who actually earned them. And one more crack in the trust that the entire affiliate channel runs on.

I pulled three people into the Nerditorium who have more combined experience catching this kind of fraud than anyone else I know. Ben Edelman caught Phia’s hand in the cookie jar. Dan Sweeney spent years cleaning up messes like this inside the networks before building tools to catch them faster. And Madeline Sullivan is building a legitimate shopping app in this exact space and wanted to go on record about what compliant behavior actually looks like.

This is the breakdown.

Meet the Panel

Ben Edelman — Affiliate Misconduct Researcher

Ben has been hunting this exact behavior since before most affiliate managers had their first login. He was involved in the eBay cases that ended in prison sentences. He reported on Honey before MegaLag’s video hit 19 million views. And he found Phia’s violations by doing what he always does: installing the apps on test devices, reading the source code, and following the evidence wherever it goes. He did the entire Phia investigation for free.

Connect with Ben on LinkedIn

Dan Sweeney — Founder, Coleman Digital

Dan is an old friend from my CJ days, 17 years ago. He was the guy inside the networks cleaning up exactly these kinds of messes. Now he runs Coleman Digital, where he helps advertisers and agencies police SEM and software compliance. He has seen more skeletons in the closet than most people in this industry want to admit exist.

Connect with Dan on LinkedIn

Madeline Sullivan — Founder and CEO, Shopping with Scout

Madeline spent just over eight years at Forbes building and nurturing commerce partnerships before joining Scout three months ago. Scout is a consumer AI startup helping people make better purchasing decisions across the internet. She brought this topic to me because she builds in the same space as Phia and wanted to go on record about how a legitimate operation runs.

Connect with Madeline on LinkedIn

And the panel host is Dustin Howes.

What Phia Actually Did: Phia Affiliate Fraud Explained

A shopping extension, whether it runs on Chrome or Safari, is a zip file with JavaScript inside it. That code runs inside your browser. It can open tabs. It can close tabs. And if the people writing it decide to do something with that access, most users will never know.

Here is what Ben found when he tested Phia’s iOS Safari extension.

When you visited a merchant, Phia would open a second tab in the background. On a mobile browser, you do not see your other open tabs. Every pixel on a phone screen matters, and the hidden tab is completely invisible to you. In that hidden tab, Phia fired an affiliate link. Five seconds later, the tab closed itself. No trace. No visible click. But the affiliate tracking system recorded it.

“It’s forced clicks, and it’s a lead stealing concept. The merchant should have gotten that traffic for free, maybe thanks to SEM or thanks to ads on a billboard or the side of a bus, or just word of mouth. It converts traffic that shouldn’t be affiliate traffic into traffic that is.” — Ben Edelman

Ben also found stand-down violations on the first three test runs. Three for three. Stand-down is the rule that says if another affiliate’s cookie is already on that session, you do not overwrite it. Phia’s telemetry data showed they could see that another affiliate’s cookie was present. They fired their link anyway.

This is not a gray area. They knew. They documented it. And they kept going.

the Phia affiliate fraud scandal

Phia vs. Other Known Affiliate Fraud: How the Violations Compare

Fraud TypeHow It WorksWho Gets HurtIs Phia involved?
Forced clicks (auto-drop)A hidden tab fires affiliate link with no user interactionMerchant pays for free traffic; publishers lose commissionsYes, on iOS Safari
Stand-down violationAn affiliate fires link even when another affiliate’s cookie is already presentThe publisher who drove the actual click loses creditYes, found 3 of 3 test runs
Cookie stuffingAffiliate link dropped without any user action or visit intentThe merchant pays for sales it earned organicallyCore of the Phia allegation
Click hijacking (Honey-style)Takes credit for an existing user-initiated click by overwriting at checkoutThe publisher who initiated the sale loses commissionNo, Phia did not hijack existing clicks
Sub-affiliate opacityA software publisher hides inside a super affiliate; merchant cannot see who is really in their programMerchant loses visibility into who they are payingYes, many merchants did not know Phia was in their program
Coupon bait (false codes)The plugin shows “code found” with no actual working coupon to trigger an affiliate linkMerchant overpays on commissions for zero valueMentioned in Honey case, not core Phia allegation

The distinction between Honey and Phia is significant. Honey was accused of showing up at checkout and swapping out the affiliate who drove the sale. Phia allegedly created the tracking event from nothing. That is a different order of problem.

Why the “It Was a Bug” Explanation Does Not Hold Up

Phia called the auto-drop behavior a bug limited to a recent release. Ben was not buying it.

The feature had a name. It had an entry in a feature flag system, which is a server-side switch that turns product behaviors on or off for specific users based on criteria like device type, geography, or time of day. The auto-drop feature turned on when the user agent identified a Safari mobile browser and turned off for desktop Chrome. That is not a bug in the traditional sense. That is a targeted configuration decision that happened to benefit Phia every single time it fired.

Ben put it this way: when United Airlines accidentally prices a flight at a dollar, that is obviously a mistake because it hurts them. When a shopping extension accidentally fires affiliate links that generate commissions for itself, that is a mistake that happens to be entirely in its favor. Those two things are not in the same category.

Phia has not provided any engineering specification, any vibe coding log, or any internal document showing the feature was supposed to do something else. Show the evidence that this was accidental. Without it, the explanation does not hold.

What Legitimate Shopping Tools Should Be Doing

Madeline building Scout inside this same space and knowing what she knows from eight years at Forbes gives her a clear baseline for what compliance actually looks like. She turned Ben’s report into a mandatory training document for her entire engineering team the week the story broke.

Here is what the panel agreed every compliant shopping tool should be doing:

  1. Honor stand-down without exception. If another affiliate’s cookie is on the session, do nothing. No spinner, no cashback notification, and no updated offer. Nothing.
  2. Only insert a cookie on an actual user-initiated click to a retailer site. Not on page load. Not on a visit. On a real click.
  3. Make behavior observable on the client side. Server-side feature flags that control compliance behavior make it nearly impossible for network quality teams to audit. If you have nothing to hide, put the rules where people can read them.
  4. Do not use sub-affiliate opacity as a cover. If you are generating meaningful volume with a merchant, go direct. Using a super-affiliate as a buffer to avoid line-item visibility is a structural red flag.
  5. Educate your engineering team on affiliate rules before they write a line of code. Madeline’s point on this was sharp: a lot of what happened at Phia reads like people who simply did not know what the rules of this game were. That is not an excuse. It is a reason to make affiliate compliance part of the product roadmap from day one.

What Merchants and Affiliate Managers Should Do Right Now

The Phia situation exposed something that a lot of programs do not want to admit. Many affiliate managers did not even know Phia was in their program. Phia was running as a sub-affiliate, buried inside another affiliate’s account. Zero visibility. Zero informed consent.

Here is where to start:

Download the major shopping extensions and install them on a test device.
You will immediately see which programs they are active on and what they are doing at checkout on your site.

Check whether any software affiliates in your program are running as sub-affiliates.
If they are generating volume but you cannot see them directly in your dashboard, that is a problem worth investigating.

Take a page from Capital One’s playbook.
Capital One sent a detailed email to every affiliate program they were connected with, flagging what Phia was doing and asking managers to investigate. You can send the same message. It costs nothing.

Ask your network what their software compliance policy actually is.
CJ has a dedicated network quality team. Awin has a soft-click policy. If you are on a SaaS platform like Impact or Partnerize, compliance enforcement falls largely on you. Know which situation you are in.

Read the Affiliate Code of Conduct that Ben Edelman and James Little have drafted.
It is publicly available and open for comment. If you run a program, reading it and building it into your software approval process is a reasonable starting point.

Why the Industry Keeps Producing This Problem

Ben framed that the Phia affiliate fraud as an economics problem, not a technology problem. And he is right.

OPM agencies want to see the number go up. In-house affiliate managers want to see the number go up. Networks earn more when the number goes up. Shopping extensions get paid when the number goes up. The only party in the room who wants advertising expenses to go down is the merchant’s CFO, and the CFO is rarely the one managing the affiliate program.

Network quality teams have a structural incentive not to find big problems. Finding something big means staying late. It means making your boss’s boss uncomfortable. It means potential litigation. Ben made the point that he would like to see network quality people paid on a piece rate rather than a salary because right now the incentive structure rewards going home at five.

MegaLag found what an entire industry of salaried professionals missed. One person. One video. 19 million views. That is a damning data point about how well the current system polices itself.

The fragmentation of where programs live makes it worse. A network like CJ has centralized standards and an enforcement team. A SaaS platform like Impact pushes compliance down to each individual program. From one program to the next, the standards for what software affiliates are allowed to do can be completely different. Madeline said it plainly: trust is all a brand has at the end of the day. Most affiliates recruited and invited to programs follow the rules. When incidents like this hit, the damage spreads far beyond the bad actor. Every legitimate shopping app, every compliant publisher, every affiliate manager trying to run a clean program gets painted with the same brush.

Wrap-Up: Where This Leaves the Industry

MegaLag found what an entire industry of salaried compliance professionals missed. One person. One video. 19 million views. That number should make every network quality team uncomfortable, because it means the current system is not working well enough.

Cookie stuffing, click hijacking, and forced clicks. The specific method changes. The incentive structure underneath it does not. Everyone in the affiliate ecosystem, OPMs, in-house managers, networks, and shopping extensions want the number to go up. The merchant’s CFO is the only party in the room who wants advertising expenses to go down, and the CFO is rarely the one managing the affiliate program. Until that misalignment gets addressed structurally, through piece-rate enforcement, client-side transparency requirements, and cross-industry software standards, we will keep having versions of this conversation.

Phia affiliate fraud is the story right now. The next version is already out there. Probably in an extension no one is testing yet. Probably on a device category or browser that compliance teams have not thought to check.

The best move you can make today is to be harder to fool. Know what software affiliates are in your program. Know whether any of them are hiding as sub-affiliates. Know what stand-down means and whether your tools are actually following it. And if you are a shopping app builder, take Madeline’s lead: turn the Phia report into a training document for your engineering team before someone turns your product into the next headline.

“Demanding transparency is one of the big items. If something looks too good to be true when you’re looking at your affiliate program and you can’t tell where anything is coming from, that should be a giant red flag. You should be able to know from your partners, especially the largest partners, where everything is coming from. And if they won’t share it, that is definitely a red flag.— Dan Sweeney

Keep on recruiting. But know who you are recruiting. Let Alfie do the hard work for you.