Phia Shows Why Affiliate Networks Can’t Police Your Program For You. (#21)

September 8, 2026

Phia affiliate attribution controversy graphic showing why affiliate networks provide infrastructure, but merchants still need their own fraud controls, leakage reviews, and affiliate program governance.

TL;DR

Phia didn’t expose a new affiliate problem. It exposed an old and incorrect assumption. If a partner claims credit for a sale it didn’t influence, the network will catch it. In all likelihood, they won’t.

Major affiliate networks have fraud teams, compliance policies, transaction data, partner rules, and escalation processes. The best ones take fraud seriously. But no network can fully police every merchant’s program, as fraud detection and program governance are different jobs.

A network can identify clear policy violations, suspicious tracking behavior, fake orders, and prohibited software activity. What it can’t always know is whether a partner belongs in your program, whether that partner is incremental for your business, or whether it’s simply capturing credit at the end of a journey someone else created.

That’s the gap. Your affiliate network is infrastructure. It isn’t a substitute for active affiliate management.

Phia Wasn’t a Small, Obscure Case

The Phia controversy caught attention because it wasn’t an unknown affiliate working in the shadows. Phia is a high-profile shopping app and browser extension, co-founded by Phoebe Gates and Sophia Kianni, operating inside the modern affiliate ecosystem.

Business Insider reported that Phia was working with at least one affiliate network, Impact.com, to refund affected parties and correct attributions after attribution issues involving its browser extension. The same report said Phia had acknowledged its extension claimed credit for sales it had no part in, an issue the company blamed on a software update and said it had resolved.

People also reported Phia’s response, including the company’s statement that it was reviewing transactions, issuing reversals to brand partners for misattribution, and hiring a head of compliance.

Ben Edelman, who has been documenting affiliate software issues for more than two decades, published detailed posts about Phia’s alleged forced-click behavior and on-exit clicks and cookie refreshes. He argued the extension could invoke affiliate links in situations where the user hadn’t meaningfully clicked one.

Whatever the final commercial and legal outcome, the problem is clear enough. A browser layer can interact with a purchase journey. Tracking can be triggered. Commission can be claimed. And the merchant may only discover later that the tracked activity didn’t represent real partner influence.

That should make every affiliate manager uncomfortable.

We’ve Seen This Before

The reason Phia bothered me is that the pattern isn’t new.

I was dealing with versions of this in 2005. The names were different: 180solutions, ShopAtHomeSelect, Hotbar, Media Gateway, and TopMoxie-powered toolbars. The industry argued about toolbars, adware, shopping assistants, pop-ups, forced clicks, cookie overwriting, and parasiteware.

The mechanics varied. The commercial question didn’t.

Did the partner influence the sale, or did software appear at the right technical moment and claim credit?

Twenty years on, the UX is cleaner, the branding is better, and some of the tools have AI in the description. Underneath the wrapper, the old problem is intact. If software can put itself close to conversion and trigger affiliate credit, there’ll always be a commercial incentive to monetize that moment.

That’s why this keeps coming back.

For more on the history, see my article, Browser Extension Affiliate Fraud Isn’t New. I Was Fighting This in 2005.

So Why Don’t Networks Just Stop It?

Networks can reduce risk. They can’t eliminate it.

They operate at platform scale, across thousands of merchants, tens of thousands of partners, and millions of clicks. They build rules, detect patterns, investigate complaints, suspend partners, reverse commissions, and enforce platform policy. All of that is real work, and I’d rather run a program on a platform that does it well than one that doesn’t.

But they don’t sit inside your business. They don’t know your margin structure. They don’t know your internal view of incrementality. They don’t know which partners you want to encourage, which codes are genuinely private, which checkout behaviors you consider acceptable, or which partner types matter strategically to you.

That isn’t an attack on networks. It’s a division of responsibility. The network polices the platform. It can’t manage your program.

Fraud and Leakage Aren’t the Same Thing

This is the part merchants need to understand, as the two are treated as one problem and they behave very differently.

Fraud is usually clear: fake orders, stolen cards, bot traffic, forced clicks, cookie stuffing, malware, prohibited traffic, or behavior that breaks platform rules or program terms. A network fraud team can investigate that and stop it.

Leakage is messier. Coupon partners capturing customers who were already buying. Extensions activating at checkout. Creator codes leaking to voucher sites. Subnetworks obscuring the real traffic source. Cashback partners taking credit for existing customers. Partners earning commission because your rules permit it, even where the value is weak.

Leakage requires merchant judgment, and that’s precisely what a platform can’t supply. The network may catch obvious abuse. It has no way of knowing whether a partner is creating incremental value for your business.

Platform Approval Isn’t Program Approval

One of the biggest mistakes merchants make is assuming that a partner active on a major network must be safe for their program.

Being allowed on a network doesn’t mean a partner belongs in your program. It doesn’t mean they fit your economics or match your acquisition goals. It doesn’t mean they should be allowed to trigger tracking at checkout, use your codes, work through subnetworks, run paid search, or drive browser-extension traffic.

The network relationship creates access. You still have to decide whether that access should be granted inside your program, based on partner type, traffic source, conversion path, customer quality, incrementality, and brand risk.

This matters more than it sounds, as the platform is telling you something narrower than you think. Tracking records events: clicks, conversions, order values, partner IDs, timestamps, attribution outcomes. That’s the credit assignment. It isn’t the value assignment.

A transaction can track perfectly and be of low to zero value. A partner can win last click without creating the customer. A coupon partner can post an excellent conversion rate because it mostly touches people who were already close to buying.

Networks want healthy marketplaces, trusted tracking, and merchants who succeed. Those are good incentives, and they overlap with yours. They aren’t identical to yours. A network cares whether a transaction was valid under its rules. You should care whether it was worth paying for under your economics.

If you approve partners blindly because they’re already on a reputable network, you’re outsourcing judgment that was never the network’s to exercise.

Browser Extensions Need Extra Scrutiny

Browser extensions, shopping apps, coupon tools, cashback overlays, and AI shopping assistants deserve specific attention, as they operate close to the purchase event.

That doesn’t make them all bad. Some help customers compare prices, find valid offers, or complete an order.

But they can appear late in the journey. They can activate on your domain, interact with cart and checkout pages, trigger clicks, apply codes, and set or refresh cookies. They sit in exactly the part of the journey where last-click attribution is easiest to capture.

There’s a second problem, and it’s the one that makes the first hard to catch.

Going through extension monitoring data from Marcode recently, the pattern was consistent. Extensions frequently don’t appear in your reporting as extensions. They monetize through subnetworks and link-monetization platforms, which hold the network relationship on behalf of many publishers at once. Sovrn, Digidip, and CouponFollow all operate that model, as do others. It’s a legitimate structure, and it’s how a large part of the ecosystem works.

The consequence, whether anyone intends it or not, is that the extension itself is invisible to you. What reaches your report is the intermediary’s ID. You see a partner name you half-recognize, on a respectable conversion rate, and nothing that indicates a browser layer fired at checkout.

That’s why merchants tell me with complete confidence that they don’t work with extensions. They believe it, as their reporting agrees with them. The extension didn’t come through the front door. It came through a partner who was already approved.

So “we don’t allow extensions” isn’t a policy. It’s an assumption, and it’s usually untested. The only way to know is to look at what actually loads on your own site when a shopper who has those extensions installed reaches your checkout.

A browser extension shouldn’t be approved and forgotten. It should be tested, documented, restricted where necessary, and reviewed. If your affiliate manager can’t explain how an extension behaves inside your program, you don’t have control of it.

The Partners You’d Never Knowingly Approve

It’s worth being concrete about who this involves, as it isn’t only obscure software.

Several of the most widely distributed shopping extensions are attached to major consumer security brands: Norton, Avast SafePrice, AVG SafePrice, Avira Safe Shopping. They behave like any other shopping extension, activating on merchant domains and monetizing the moment closest to conversion.

The uncomfortable part is what that can mean for certain merchants. In February 2024, the FTC fined Avast $16.5 million and barred it from selling browsing data for advertising purposes, over conduct in which its browser extensions and antivirus software collected users’ browsing histories and a subsidiary sold them.

I’m not suggesting these extensions are doing anything improper in any program today. The point is narrower and harder to answer: most merchants running these partners never made a decision about them. Nobody evaluated the partner, weighed the brand risk, or concluded the behavior was acceptable. The partner arrived through a subnetwork, and the reporting never surfaced it as an extension at all.

If you sell privacy, security, or anything else where trust is the product, that isn’t a technical detail. It’s a question you should be able to answer about your own program, and most merchants can’t.

What I’d Ask Any Network About a Partner Like This

If a browser extension or shopping app were active in my program, I’d want specific answers.

How does the partner trigger clicks? Is user action required? Can the extension activate on the merchant site, or at checkout? Can it open background tabs? Can it overwrite an existing affiliate cookie? Does it have stand-down rules when another affiliate is present? Can the platform give me click timing and page-location data?

I’d also ask whether the partner operates through sub-affiliate relationships, whether its behavior changes server-side by user or context, whether it can fire events when a user dismisses a prompt, and whether anyone has tested it on desktop, mobile, and different browsers.

These aren’t nice-to-know questions. They determine whether a partner is creating value, capturing value, or misattributing it.

A merchant that never asks is relying on hope, and hope isn’t a compliance strategy.

What I’d Check Inside the Program

Review your own data too. Time-to-conversion, same-session sales, click-to-order windows, new versus returning customers, coupon usage, discount dependency, partner overlap, checkout-stage activity, unusually high conversion rates, low click volume against high order volume, and any partner that repeatedly appears after other partners have already touched the customer.

Then look for creator codes appearing outside approved channels, subnetwork transactions with no source transparency, extension partners converting almost entirely at checkout, and coupon partners with strong last-click numbers but weak evidence of demand creation.

None of those patterns proves fraud on its own. They tell you where to look.

Affiliate fraud and leakage rarely announce themselves. They show up as a partner that performs well, right up until someone asks better questions.

Don’t Wait for a Scandal

The worst time to review your affiliate governance is after the scandal blows up.

By then, the commissions are paid, the data is messy, partners are angry, finance is asking questions, the network is investigating, and your affiliate manager is reconstructing events from months or even years ago. That’s the expensive way to do it.

The better approach is to assume platform-level protection isn’t enough. Review your terms, your partners, your extensions, your coupon leakage, your subnetwork transparency, your attribution rules, your commission logic, and who is actually creating value.

This isn’t paranoia. It’s treating affiliate as a real commercial channel with real financial exposure.

Need Help Reviewing Affiliate Fraud and Leakage Risk?

Affiliate Manager Expert provides founder-led affiliate program management, audits, tracking reviews, compliance reviews, and program cleanup for SaaS, software, fintech, e-commerce, and digital product brands.

If you’re relying on your affiliate network to catch every problem, I can help you review where your program is exposed: browser extensions, coupon leakage, partner overlap, sub-affiliate opacity, attribution rules, program terms, commission logic, and partner quality.

Book a free affiliate program review, and I’ll help you understand whether your affiliate program is properly managed or just trusting the platform.

0 replies

Leave a Reply

Want to join the discussion?
Feel free to contribute!

Leave a Reply

Quote of The Week

“Trust, but verify.” ― Russian proverb, popularized by Ronald Reagan