TL;DR
Cookie stuffing plants an affiliate cookie in a browser that never clicked an affiliate link, so the affiliate collects on a sale they did not cause [1]. Every detection method comes down to the same test: does the referral claim have a real browsing session behind it? Six signals are described below, each with what normal looks like and what the abusive version looks like, and all six are readable in data you already hold in your affiliate app, your Shopify orders and GA4. One caution before you start. A 2015 measurement study of this abuse found the practice real but rarely encountered by users, and less prevalent than earlier reports suggested [2], so treat every signal as a question to ask an affiliate, not an accusation to make.
Key Takeaways
- Cookie stuffing is a deceptive affiliate tactic that uses invasive techniques such as pop-ups to claim credit for sales the affiliate did not facilitate [1].
- The mechanics matter for detection: a 2015 measurement study gathered roughly 12,000 stuffed cookies from 11,700 domains; over 91% of those cookies were delivered by redirects (HTTP 301/302, Flash or JavaScript), and 84% arrived through at least one intermediate domain that obscured the true referrer [2].
- Because the cookie is set without a real visit, the strongest detector is a referral claim with no matching session in GA4 or in your Shopify order's landing data.
- Both tails of the click-to-conversion ratio are suspicious: enormous clicks with near-zero conversions, and an implausibly high conversion rate on an affiliate whose traffic you cannot otherwise see.
- Coupon codes complicate this. In UpPromote's documented rules, and in similar apps, a coupon code outranks the link cookie when the two belong to different affiliates, so leaked codes can look like performance.
- The behavior has been prosecuted as wire fraud in the United States, including an eBay affiliate case in which Shawn Hogan was convicted in 2014 and sentenced to five months plus a $25,000 fine [1].
- Detection is analysis you run. No tracking app scores affiliates for you, and complete event data is the precondition rather than the answer.
What cookie stuffing is, and how common it actually is
The definition is short. Cookie stuffing is a deceptive tactic in affiliate marketing where affiliates use invasive techniques, such as pop-up ads, to falsely claim credit for sales they did not facilitate [1]. Programs prohibit it. It costs the merchant money on commissions that bought nothing and costs honest affiliates the credit that should have been theirs.
The delivery methods are worth knowing because they are what leaves the forensic trace. Chachra, Savage and Voelker gathered roughly 12,000 stuffed cookies from 11,700 domains for their 2015 study of affiliate marketing abuse; over 91% of those cookies were delivered by redirects (HTTP 301/302, Flash or JavaScript), and 84% arrived through at least one intermediate domain that obscured the true referrer [2]. Other vectors in the same work: iframes embedding the retailer's site, script or image tags requesting the cookie-setting resource, and hijacked or malicious browser extensions [1][2].
Every one of those loads the affiliate's tracking URL without the visitor ever intending to visit your store. That is the exploitable property. A real referral produces a person arriving on a page. A stuffed cookie produces a cookie and nothing else.
It is also not an epidemic. The same study found that large affiliate networks were targeted disproportionately more than merchant-run programs, but users rarely encountered stuffed cookies overall [2], so the reasonable posture is a periodic check rather than a standing suspicion. What follows is a check.
Six signals, and what normal looks like for each
Pull three things first: your affiliate app's per-affiliate report for the last 90 days, your Shopify order list for the same window, and GA4 with source, medium and landing page available.
| Signal | What normal looks like | What stuffing looks like |
|---|---|---|
| Click-to-conversion ratio | Within a band around your program median | Either tail: huge clicks and almost no orders, or a conversion rate far above every other affiliate |
| Click-to-order timing | A spread across hours and days | Clustered in seconds before checkout, or smeared evenly across the whole cookie window |
| Session corroboration | A landing session with pageviews and cart events | Referred orders with no matching session at all |
| Coupon timing | Code applied in a session that started on the affiliate link | Code applied minutes after a first-ever click from that affiliate |
| New versus returning mix | Mix resembles the rest of your traffic | Overwhelmingly returning customers who arrived direct or on brand search |
| Commission trend | Moves with placements and campaigns | Rises with no new placements and flat program traffic |
1. Click-to-conversion ratio, read from both ends. A stuffer's clicks are forced impressions on unrelated pages, so blanket stuffing shows up as click volume with nothing behind it. The other tail is the one people miss. If the cookie is planted specifically on people already about to buy, for example through a browser extension that fires on cart pages, the affiliate's conversion rate goes far above your program median rather than below it. Compare every affiliate against that median in both directions.
2. Click-to-order time clustering. Legitimate referrals show a spread. Somebody reads a review, thinks about it, comes back the next evening. Stuffed cookies cluster at the extremes: seconds to minutes before checkout, which is last-click hijack on a buyer already in the cart, or uniformly across the full cookie window with no engagement in between, which is blanket planting.
3. Sessions that do not exist. This is the one to run first. A real referral produces a session with a referrer, a landing page and browse events. A cookie set by a redirect, an iframe or an image request produces none of that [2]. So take an affiliate's referred orders, look up those orders' sessions in GA4, and count how many have a landing page and a browse trail. A high referred-order count with no matching session trail is the strongest single signal available to you, and it follows directly from the delivery mechanics rather than from any threshold somebody invented. The event layer that both your payouts and your ad reporting read from is the same one, which we set out in affiliate attribution on Shopify. This check is that chain, inverted and used as a detector.
4. Coupon timing. Affiliate apps commonly resolve conflicts by letting a coupon code outrank the link cookie when the two belong to different affiliates. UpPromote documents that priority, and it is a sensible rule for genuine coupon partners. It also means a code that escaped to a coupon aggregator credits an affiliate who did not create the demand. Look for orders where the code was applied minutes after a first-ever click attributed to the same affiliate, on buyers whose GA4 session source was paid or organic. That is last-touch capture rather than fraud in most cases, and the fix is code hygiene rather than a fraud process.
5. New versus returning skew. Stuffed conversions ride purchases that were happening anyway, so they over-index on returning customers arriving through direct and brand search. An affiliate whose referred orders are overwhelmingly existing customers deserves a look. If you are not already splitting your reporting that way, new versus returning customer tracking sets it up.
6. Commission spikes without campaign changes. Payout growth while program-wide traffic stays flat and no new placements went live. Reconcile the affiliate's claimed orders against your Shopify order list as the denominator, which is the same reconciliation routine that catches ordinary attribution drift.
How to tell a signal from a coincidence
Two affiliates can produce identical-looking numbers for entirely different reasons, so run these three controls before you conclude anything.
Check the attribution window first. A long cookie window naturally produces long gaps between click and order, and a program that recently lengthened its window will show a timing shift that has nothing to do with anybody's conduct. Affiliate attribution on Shopify covers how long affiliate cookies can live. Attribution windows and reporting delays covers ad-platform windows and reporting delays.
Check whether your sessions are complete before you trust a missing one. Signal 3 depends on the absence of a session meaning something. If your GA4 property is losing browser events to ad blockers, to a consent configuration, or to an ITP-shortened cookie, then plenty of honest referrals will also show up with no session trail. Establish your baseline session-to-order coverage across all traffic first. If GA4 already fails to explain a large share of your ordinary orders, fix that before you read anything into a specific affiliate's gap.
Check the email channel. An affiliate placement in a newsletter can genuinely produce short click-to-order times and a returning-customer skew, because the recipient already knows you. Cross-reference against your sends before treating that shape as suspicious.
The honest position after all three controls is often "I have a question", not "I have a fraud case". That is the correct output. The purpose of a detection pass is to produce a short list you can ask about, and asking is cheap.
What to do with a flagged affiliate
Keep the response proportionate and procedural.
Tighten the cookie window in your affiliate app, which reduces the value of blanket planting without penalizing real referrers. Require session corroboration before approving payout on flagged orders, using the check in signal 3. Rotate coupon codes that have leaked to aggregators and issue per-partner codes so leakage is traceable to a source. Then escalate through the affiliate platform's own dispute process, which exists precisely for this and which handles the evidence-gathering norms better than an email from you will.
And keep the base rate in mind. Users rarely encountered stuffed cookies even in the study that measured the practice at scale [2], and the far more common explanation for a strange affiliate report is a coupon code doing what coupon codes do.
FAQ
How do I know if an affiliate is cookie stuffing?
Take their referred orders and check whether each one has a real session behind it: a landing page, a referrer, browse events. Cookie stuffing sets the cookie through redirects, iframes or image requests, which produce no session [2], so referral claims without session trails are the clearest indicator you can gather from your own data.
Can Shopify detect cookie stuffing automatically?
No, and neither can a conversion tracking app. Shopify records orders and your affiliate app records referrals. Connecting the two and spotting the mismatch is analysis you run, either yourself or through your affiliate platform's compliance process.
Is cookie stuffing illegal?
It has been prosecuted as wire fraud in the United States. In the eBay affiliate case, Shawn Hogan was convicted in 2014 and sentenced to five months in federal prison plus a $25,000 fine [1].
My affiliate's orders are all returning customers. Is that proof?
No. It is one of six signals, and email placements and loyalty partnerships produce the same shape honestly. Run it alongside the session check and the timing check before drawing any conclusion.
How often should I run this check?
Quarterly is enough for most programs, plus once after any commission spike you cannot explain from placements.
Every signal above depends on your order and event data being complete enough to trust. WeltPixel Conversion Tracking sends server-side purchase events from the Shopify order record across nine integrations, so an order still lands in your analytics when the browser event does not, and it attaches new versus returning customer type to GA4, Meta, TikTok and Google Ads events on the app's Plus plan [3]. It does not score affiliates, and no app should claim to.
Start with signal 3 on your three largest affiliates. If all three have session trails, you are done for the quarter.
Sources
- Wikipedia, "Cookie stuffing" (definition and pop-up technique; program prohibition; techniques including iframes, script and image tags, and browser extensions; 2015 finding that users rarely encounter it; eBay affiliate prosecution, Shawn Hogan convicted 2014, five months and $25,000 fine), en.wikipedia.org/wiki/Cookie_stuffing, accessed September 7, 2026
- Neha Chachra, Stefan Savage and Geoffrey M. Voelker, "Affiliate Crookies: Characterizing Affiliate Marketing Abuse", ACM Internet Measurement Conference, 2015 (roughly 12,000 stuffed cookies from 11,700 domains; over 91% of those cookies delivered by redirects; 84% arriving through at least one intermediate domain that obscured the referrer; large affiliate networks targeted disproportionately more than merchant-run programs, with users rarely encountering stuffed cookies), doi.org/10.1145/2815675.2815720
- WeltPixel Conversion Tracking, Shopify App Store listing, apps.shopify.com/weltpixel-conversion-tracking, accessed September 7, 2026