Cookie Stuffing

Cookie Stuffing

Cookie stuffing is a fraud scheme in online marketing: an advertising identifier is secretly placed in a website visitor's browser, even though they never clicked on an ad. If they later make a purchase, the fraudster collects the referral commission for a recommendation that never actually happened.

Many online shops pay money to websites that send them customers. So that the shop knows who referred a customer, the browser stores a small file with an identification number when the ad is clicked. Such files are called cookies. With cookie stuffing, this identification number is set secretly, without the visitor ever having clicked on an ad. If they later happen to buy something in that shop, it looks as if the fraudster referred them. The shop pays out a commission for a recommendation that never took place.

Who ends up paying the commission

The business model behind this is called affiliate marketing. A blog recommends headphones, links to a shop, and receives a few percent of the price on a purchase. This is a huge market: Amazon alone works with millions of such partners. The entire system relies on the stored identification number genuinely representing a real recommendation.

Cookie stuffing destroys exactly this foundation. The shop pays for customers who would have come anyway. Honest partners additionally lose their money, because the planted identification number often overwrites the real one. This is because, as a rule, whoever sets the cookie last gets the commission.

The damage caused is considerable. A well-known case from the USA involved two men who defrauded eBay of around 28 million dollars over the years. One of them was sentenced to prison. Cookie stuffing is therefore not merely a violation of terms of service, but can constitute fraud in the criminal sense.

The invisible click in the background

Technically, no real click is needed. It is enough for the browser to simply call up the address of the affiliate link. Fraudsters build in image elements for this purpose that are only one pixel in size and therefore invisible. The browser loads them automatically when the page is built, the shop registers the call, and sets the identification number.

A second variant uses so-called iFrames, i.e. small windows that embed a foreign page within another one. They can be shrunk to zero pixels in size. Redirects also work: the page briefly loads the affiliate link and immediately jumps back, faster than the eye can follow.

Browser extensions, i.e. small add-on programs within the browser, are particularly effective. A seemingly harmless coupon finder can set an affiliate identifier in the background every time a shop is visited. Because the extension was installed with the user’s permission, this is barely noticed. This should be distinguished from the cookie banner annoyance on websites: that is about consent to data storage, whereas cookie stuffing is about the theft of commissions.

How shops and networks are fighting back

Large affiliate programs today automatically evaluate how clicks and purchases relate to one another. A partner with millions of clicks but a tiny purchase rate is conspicuous, for example. A lack of dwell time between click and purchase is also a warning sign. Such accounts are blocked, and commissions already paid out are reclaimed.

In the news, the topic usually appears in two contexts. On one hand, in trials against fraudsters, and on the other, when Google or Mozilla remove extensions from their stores that secretly set affiliate links. Such removals have already affected extensions with millions of installations.

For you as a user, the direct damage is minor, since you don’t pay a single cent more. Nevertheless, caution is worthwhile: extensions that promise you discounts make their money somewhere. Regularly deleting cookies and taking a critical look at installed add-on programs are sensible measures. Incidentally, such an extension also reveals which shops you visit.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.