Last click is not a side issue here; it is the payment mechanism
Affiliate marketing pays on attributed conversions, and the attribution rule in almost universal use is last click. That combination creates a direct financial incentive to be the last click, whether or not the publisher did anything to cause the purchase. Every documented affiliate fraud pattern is a variation on that single theme, and it is why the analysis in these matters looks different from a general fraud analysis: the question is rarely whether traffic was real, but whether the credited click did any work.
That framing has a practical consequence counsel should hold onto. In an affiliate dispute, the program's own terms come first and the marketing analysis second. Whether a coupon extension that captured the last click committed fraud, breached the program agreement, or operated a permitted business model depends entirely on what the merchant's publisher agreement said about it. Many programs exclude or reduce commissions on coupon and loyalty traffic; many do not. An expert who begins with a view about who deserved the sale has skipped the document that decides it.
Cookie stuffing, and what the criminal cases actually established
Cookie stuffing — also called cookie dropping or forced clicks — sets an affiliate's tracking cookie in a visitor's browser without the visitor clicking any affiliate link, typically through an invisible frame, a 1x1 image, or a scripted redirect through the merchant's tracking server. If that person later buys from the merchant by any route, the last-click rule pays the stuffer.
The documented US prosecutions arose from a single investigation into an eBay affiliate program. In the first, a defendant was indicted on 24 June 2010 on five counts of wire fraud, pleaded guilty on 15 April 2013 to a superseding information charging wire fraud under 18 U.S.C. § 1343, and was sentenced on 4 August 2014 by U.S. District Judge Edward J. Davila to fifteen months in prison and three years of supervised release. In the Department of Justice's own description, the defendant ran free-application websites whose code "would cause the user's browser to receive a cookie with [the affiliate company's] ID number, even though the user did not click on an eBay ad or link."
The figures are worth getting right, because the ones in circulation are not the government's. Popular accounts describe a $35 million or $28 million eBay affiliate fraud. The Department of Justice states that eBay paid the defendant's company approximately $5.2 million in commissions between May 2006 and June 2007, and its sentencing release describes the fraudulent portion as between $200,000 and $400,000. Those are the numbers to use. An expert who repeats the $35 million figure in a report will be asked for its source, and there is not a governmental one.
A second defendant, the chief executive of a search-marketing firm and at one time eBay's highest-paid affiliate, was prosecuted in the same investigation and reported to have been sentenced in 2014 to five months and a $25,000 fine. That sentence is reported in the press rather than in a Department of Justice release, and there is no published opinion in the matter. It should be referred to as a federal prosecution in the Northern District of California, with the docket pulled before anyone puts it in a report — not cited as though it were reported case law.
The civil decision has an opinion, and it decided less than it is said to decide
The citable authority from the same conduct is eBay Inc. v. Digital Point Solutions, Inc., 608 F. Supp. 2d 1156 (N.D. Cal. 2009) (Fogel, J.), decided on motions to dismiss the first amended complaint. eBay alleged that the defendants "first placed software code on a web user's computer surreptitiously, without the user's knowledge" and directed the browser to eBay's site "without the user's knowledge or any affirmative action," causing affiliate cookies to be deposited and commissions to be paid on conversions the defendants had not generated.
What the court did: it allowed the Computer Fraud and Abuse Act claim under 18 U.S.C. § 1030 to proceed, rejecting the argument that a publicly accessible website cannot be a protected computer. It dismissed the RICO claim with leave to amend for insufficient particularity as to enterprise and pattern, dismissed the California Penal Code § 502 and common-law fraud claims under Rule 9(b), and found venue improper as to certain defendants under a forum selection clause in eBay's publisher agreement.
What the court did not do: decide anything on the merits, make any finding of fact, or hold that cookie stuffing violates the Computer Fraud and Abuse Act as a matter of law. It is a pleading decision. Marketing writing routinely describes it as a merits ruling, and an expert who repeats that description hands the other side an easy correction.
The network click log is the evidence, and it is not the commissions report
A commissions summary shows what was paid. It is the wrong document. The record that answers an affiliate fraud question is the raw click log, which typically carries, per transaction: publisher identifier, click identifier, click timestamp, landing page, referring URL, conversion timestamp, order value, commission, and the network's attribution decision — plus, on the click side, the source address, user agent and referrer for every click, not only the converting ones.
Against that log, stuffing and interception have a visible shape:
- clicks with no plausible referrer, or a referrer that is an unrelated site;
- click volume wildly disproportionate to any traffic the publisher's own properties could generate;
- click-to-conversion intervals measured in seconds, concentrated at the end of the path, on users who were already on the merchant's site;
- clicks recorded for sessions that never rendered a page on the publisher's property at all.
Getting the log is a separate problem from reading it. Where the client is the merchant, network reporting is contractual and available without process — but raw click logs are frequently not exposed in the standard interface and must be requested specifically, by name, in writing. Where the client is the publisher, it sees only its own data. Where the network itself is adverse, a subpoena is required. And retention is the unanswered question: I have not been able to confirm published click-log retention periods for the major networks, which is precisely why the retention period should be requested in writing early, in a form that can later be put in evidence. Amazon's associates program is a special case worth flagging early in any matter that involves it, because reporting is aggregated to the day and product level and individual click logs are not exposed to associates at all.
Incentive traffic, and why human traffic is the harder problem
The MRC's invalid-traffic standard lists incentivized human invalid activity and incentivized manipulation of measurement among its sophisticated-invalid-traffic categories. The distinction from bot traffic is the point: the visitor is a real person, using a real device, taking a real action, because they were paid or rewarded to take it. Nothing about the session is technically anomalous. The user agent is genuine, the device is genuine, the click is genuine, and the conversion may be genuine too.
That is why incentive schemes are harder to evidence than automation, and why the analysis moves away from session forensics toward pattern and source. What tends to be visible is concentration — a narrow set of placements, publishers or subsidiary identifiers producing volumes and conversion rates unlike everything around them; conversions that complete instantly and never repeat; cohorts that transact once at the qualifying threshold and never return; and traffic whose geography or device mix does not resemble the merchant's customer base. Each of those is comparative rather than dispositive, and a report should present them that way.
The standard's own placement of these categories under sophisticated invalid traffic carries the honest concession with it: by the MRC's definition, identifying them requires advanced analytics, multi-point corroboration and significant human intervention. It is not something a merchant's dashboard resolves, and it is not something an expert should claim to have resolved from one export.
Extensions, toolbars and attribution interception
The same last-click mechanism is available to anything running inside the browser. Content creators and affiliate publishers alleged that a widely installed coupon extension replaced their affiliate tracking with its own at checkout, taking the last click and the commission even where it found no coupon and contributed nothing to the sale. The consolidated federal litigation over that conduct was dismissed without prejudice following argument on 21 November 2025, with the court finding that plaintiffs had failed to plead injury traceable to the extension and had failed to plead facts showing they were entitled to the commissions in the first place. That account comes from defense-side reporting rather than from the order itself, a dismissal without prejudice is not a final judgment, and the state of the case should be checked from the docket before anyone relies on it.
What makes it instructive regardless of outcome is the ground. "Were you entitled to the commission under the applicable rule?" is exactly the question a marketing expert can answer from network data: what the program terms said about attribution, what the click log recorded, and whether this publisher would have been paid had the extension not acted. It is not answerable from a theory about who deserved the sale, which is what most affiliate disputes are argued on before the logs arrive.
The adjacent patterns share the same signature and the same analysis: typosquatting on the merchant's brand, bidding on the merchant's trademark in paid search to intercept navigational intent, toolbar and extension injection, forced clicks inside ad units, and adware that rewrites affiliate parameters. All of them produce conversions with implausibly short click-to-conversion intervals, concentrated at the end of the path, on users who were already on the merchant's site.
What the affiliate record does not settle
Who wrote the code. A click log establishes that clicks were recorded for a publisher account with a particular shape. It does not establish who controlled that account, who deployed the script, or whether a legitimate publisher's property was itself compromised. Attribution to a person generally requires payment records, account registration data, communications and hosting records, obtained through process — which is how the eBay prosecutions were made.
Whether the sale would have happened anyway. This is the question everyone wants answered and the affiliate record cannot reach it. Establishing that a commissioned click did not cause a purchase is an incrementality question, and incrementality is established by designed tests run before or during the campaign, not reconstructed from a conversion log afterward.
Whether a permitted model is fraud. A coupon site that captures a customer who had already decided to buy is doing something the program either allowed or did not. That is a contract question, and treating it as a marketing question puts the expert in the wrong role.
What the log no longer contains. Networks do not generally publish click-log retention periods, standard interfaces often expose only summarized data, and the merchant's own order records may not carry the click identifier at all. Where the underlying log has aged out, the commissions report that remains cannot substitute for it, and a report should say so rather than working around the gap.
Frequently Asked Questions
Is cookie stuffing a violation of the Computer Fraud and Abuse Act?
The one published decision on the point is narrower than it is usually described. In eBay Inc. v. Digital Point Solutions, Inc., 608 F. Supp. 2d 1156 (N.D. Cal. 2009), the court allowed a Computer Fraud and Abuse Act claim to proceed past a motion to dismiss, rejecting the argument that a publicly accessible website cannot be a protected computer, while dismissing the RICO and fraud claims as pleaded. That is a pleading ruling with no findings of fact. It did not hold that cookie stuffing violates the statute as a matter of law, and whether particular conduct does is a legal question for counsel.How much money was actually involved in the eBay affiliate prosecutions?
Far less than the figures in circulation. Popular accounts describe a $35 million or $28 million fraud. The Department of Justice states that eBay paid the convicted defendant's company approximately $5.2 million in total commissions between May 2006 and June 2007, and its sentencing release puts the fraudulent portion at between $200,000 and $400,000. The sentence was fifteen months in prison and three years of supervised release, imposed on 4 August 2014. A second defendant from the same investigation was reported to have received five months and a $25,000 fine, though that comes from press reporting rather than a government release.What does an affiliate network's click log contain, and can a merchant get it?
Typically the publisher identifier, click identifier and timestamp, landing page, referring URL, conversion timestamp, order value, commission and the network's attribution decision, plus the source address, user agent and referrer for each click. A merchant can usually obtain it contractually without process, but raw click logs are often not exposed in the standard reporting interface and have to be requested by name. A publisher sees only its own data, and where the network is adverse a subpoena is required. Retention periods are rarely published, so ask for them in writing early.Can a coupon site that takes the last click be described as committing fraud?
Not from the marketing analysis alone. A customer who has already decided to buy, searches for a discount code, lands on a coupon site, clicks through and purchases produces a last-click commission that the program either permits or does not. Many merchants exclude or reduce commissions on coupon and loyalty traffic; many do not. The program terms decide it, which makes this a contract question first. What the records can establish is the pattern: the interval between click and conversion, the referrer, and whether the visitor was already on the merchant's site.How do you distinguish incentivized traffic from ordinary traffic?
With difficulty, because incentivized traffic is human. The MRC's standard classifies incentivized human invalid activity as sophisticated invalid traffic precisely because the session looks genuine: real device, real browser, real person, real action. What is visible is comparative rather than forensic — concentration in a narrow set of placements or subsidiary identifiers, conversion rates unlike anything adjacent, cohorts that transact once at the qualifying threshold and never return, and a geography or device mix unlike the merchant's customer base. Those support an inference. None of them settles a single transaction.Did the coupon extension litigation establish that attribution interception is unlawful?
No. The consolidated federal cases were dismissed without prejudice after argument on 21 November 2025, on the grounds that plaintiffs had not pleaded injury traceable to the extension and had not pleaded facts showing an entitlement to the commissions. A dismissal without prejudice is not a final judgment and does not decide the underlying conduct either way. The account of the ruling that circulates comes largely from defense-side reporting, so the docket should be checked before the case is described in a report. Its useful feature is the ground: entitlement under the program's own rules.Published