Loading summary
A
Foreign.
B
Welcome to an emergency pod of the Always Be Testing podcast. It's Saturday, July 11th and we are in the midst of the FIA fiasco, trying to make sense of what's happening, talking to none other than Ben Edelman, the lead detective on the case and probably an affiliate fraud in general. Ben, thanks for joining me.
A
Thank you, Ty, you're very kind.
B
Well, it's deserved. Ben has been at the center of understanding the technical nature of affiliate fraud for over 20 years. I've had the pleasure to work with him on a number of fraud protection and fraud catching cases in my career and in his. He can give all of that. But I think the goal of today's episode is to jump into the timely controversies and realities of what's happening with FIA and to try to unpack things for the audience to give a very clear common sense understanding of what's happening as opposed to the broader speculation and hysteria of some of the online commentary that starts to bubble up. Ben, maybe you can give us a sense of what has happened so far and what you've observed with fiat in the affiliate world as an affiliate versus the networks, the brands and make sense of just the facts that you have found so far and what's, what's happening for people so they understand what it is. Yeah.
A
So far the allegations against via have been in two categories, to be sure, somewhat more than just allegations. I mean there, there's evidence, there's, there's, there's meat to it. First and maybe most serious, certainly most surprising, furthest outside of the realm of typical affiliate misconduct that one catches when looking in the space is forced clicks. The FIA iOS Safari plugin. Yes, that's a thing. Yes. Safari Mobile has plugins extensions. The Safari extension forces clicks. Some people call it cookie stuffing. Anyway, there's no need for a user to click or tap on an affiliate link for the affiliate link to get invoked. They can do that automatically. Kind of nuts. That hasn't been allowed under affiliate network rules for quite a while. And they're doing it only on Safari in a place where a lot of people wouldn't think to look or wouldn't have the automation and the procedures to look at scale. And that goes for me too. Until a month ago, I wasn't checking Safari extensions for this kind of misconduct. Anyway, there's significant evidence that that's been going on for quite a while, like back to December 2025. So right through the holiday shopping season. Forced and clicks obviously takes money from merchants. Merchants who would have had that money drop straight to the bottom line transactions that would have been non commissionable, maybe they would have been SEM paid search transactions or sort of organic transactions thanks to merchants, brand building or return customers. These should be a merchant's most profitable transactions where they don't have to pay an affiliate fee and instead what Via was doing was making those commissionable. This is a familiar problem from cookie stuffing disasters of, you know, more than a decade ago. I looked back on my site the first time I wrote the webpage cookie stuffing targeting major affiliate merchants. The date on that web page is 2004. My examples begin in 2004. So that's 22 years ago. Kind of nuts to have things measured like that.
B
Yeah, I was estimating 2005 in my brain, so I was off by a year. Yeah. And for folks that don't understand. So in the affiliate world you have a network in between that is tracking and managing reporting pain. Not managing, tracking, reporting pain. You have the publisher, the affiliate. In this case Via is a publisher and affiliate that is promoting a brand, a lot of fashion and retail and E Comm in their current state. And so those are the players in the ecosystem, the brands, the retailers, the networks and then the publishers or affiliates. So for those that are new to it, not as familiar, Via is an affiliate, is a publisher. Depending on how you look at it, they have a browser extension, they are promoting a variety of e commerce brands and there has been evidence that they are essentially making pretty material violations to brand policy, network policy and good business practice. Candidly.
A
Right. So just to be super explicit about it, in affiliate marketing, you know, go back all the way to the basics. The affiliate presents an offer, the user clicks or taps the offer, the user makes a purchase. If all three of those things happen, then that's a commissionable event and money changes hands according to the terms of the contract. You can't skip any of those steps. If the user didn't really make a purchase, I don't know, they used a fake credit card number or it was some kind of a sham purchase that would not be a commissionable event. And if the user didn't click or didn't tap, the rules say that that's not a commissionable event. You could imagine something like a view through. And there are some display offers that have a view through concept. I'm not a huge fan of that because they tend to be non incremental for merchants. Basically a bad deal for merchants. If I were a merchant I wouldn't want to spend my money that way. It's all fundamentally A question of contract. And here all of the contracts say the user has to click or tap in order for money to change hands. And FIA decided to skip that step, putting themselves in pretty bad company. Back to the 2004 people I wrote up. And a lot of people immediately think of Sean Hogan and Brian Dunning, who were doing that scheme against ebay some years ago and ultimately faced criminal litigation. Both went to jail and paid back numbers in the eight digits. That's numbers between 10 million and 99. I think the numbers were in the 20s. Ultimately big numbers. They stole a lot that way. And that's not exactly surprising. Once you skip the step of the user clicking or tapping, it's easier to pull in a whole lot of money in a hurry, but you haven't earned it. And so there is a Piper waiting to be paid. When someone like me comes around and eventually notices what was going on, you're
B
basically taking credit in the digital clickstream, or lack of clickstream in this case, taking credit for traffic activity that, that you did not really generate. You did not against the agreement.
A
Right. Some companies might feel like, hey, this user is mine. I worked so hard to get the extension onto the user's device. Anything that this user does on this device, I am getting paid. And someone who has that view is way out of line. The user is not yours. You don't own the user, you don't own the device. You don't automatically get paid on every transaction. Read the contract. The contract doesn't say anything like that. The user has to actually get a benefit. The user has to actually click and tap your offer or else. And the or else is. Or else. When you get caught, everyone will be mad at you and you'll probably have to pay it back. And there'll be more complaining after that too.
B
Yeah, exactly. It's, it's, it's, you know, claiming a click that didn't happen, which is pretty wild. It's unfortunately, you know, that's something that AND has found that has been a material part of your ability to make sense of the world of digital fraud and things that are not right and tracking that down and identifying it and helping people make sense of it, which is what we're aiming to do here.
A
Well, Ty, there's a second set of problems that we haven't even begun to talk about. There are stand down violations from FIO also, on some level, the stand down violations are more normal. They're within the realm of malfunctions that we see from shopping plugins. Honey had some Widely publicized stand down violations. Last year I wrote an article about Microsoft Edge which had a shopping plugin really pre installed and it too had stand down violations. With any stand down violation, you have to look at it and ask, how widespread is this? Is there another explanation? Could the Shopping plugin have had trouble because the link was encoded in a certain way or the redirects happened too fast? The redirects didn't say afsrc. An interesting thing about FIA is that it noticed that there had been a prior affiliate link. In my testing, I posted the packet log of this to my site. It actually tracked an explicit detail. It tracked all of the redirect steps from the source link through to the affiliate network through to the destination. It correctly classified that as a prior affiliate link from what it called the competitor. It was right about that. And then it set a variable called should stand down equal to false. It's like, wait, wait, wait, you just tracked the stand down. You said you saw a link from another affiliate network. The correct answer is should stand down equals true. I tested two times in a row in my first test scenario after installing fia. And the first two tests, they both didn't stand down. So I'm sitting there thinking, what the heck is this? What kind of barrel am I shooting into where I caught fish the first two times? I mean, the expression of shooting fish in a barrel could hardly be more apt, right? I'm not accustomed to catching something on the first two tries. Usually I'm looking for some problem. I actually have to look. I might have to build automation to help me look more efficiently and at scale. And here it was incredibly easy. In fact, I have never personally seen via stand down. I just haven't seen that. Maybe other people have. Maybe there are scenarios where it does. There's all kinds of code pertaining to stand down. But does it ever actually activate? Does it ever do what it's supposed to do? I know there have been prior complaints to networks about this. Some of the complainants have been active on Twitter, have been talking about when they complained and how and what response they got. And so it looks like a pretty serious stand down violation that of course harms other publishers, where the forced clicks harm merchants in the first instance, stand down violations harm other publishers.
B
Yeah, and just to chime in, to give context for folks that are not as familiar, the stand down is essentially you've got, you know, potential and often likely multiple touch points before a purchase. Happens in a lot of cases in E commerce and affiliate marketing and a lot of the networks have A lot of businesses in our space have a rule which is known as a stand down, where if you are a browser extension and you're coming in at the end, if you, if there's other partners that are driving that behavior, you are to stand down, meaning you're not going to take credit for that action after the fact. Then is that your understanding of the stand down rule?
A
That's the rule. And it's there not as a piece of charity to other publishers, not as a gift. It's not there on a whim. It's there for specific business reasons. It's a judgment by merchants fundamentally and then by the networks that serve merchants, that the merchants need to offer some protection to the quote, unquote normal publishers, publishers who have a website, who deliver typically pretty incremental traffic, who write actual reviews, do hands on testing, make genuine endorsements. We need to help those guys. We need to help them because they're the little guys often compared to huge shopping plugins. We need to help them because their traffic is highly incremental and we need to help them because they're vulnerable because a shopping plugin that is on the user's device has this weird opportunity to claim commission on everything, to treat it like it's their user in their device, when really it's the user's own device and the user's own purchasing. So that's why merchants and the merchants choice of networks have this rule. Again, they embody it in contract. Ultimately the rule is what it is and we don't have to wonder why it's there or ask why it's there, just have to follow it like any, any good rule. Anyway, the rule is there and FIA is brazenly out of compliance with that.
B
Yeah. And jumping into maybe a new area of this where we've talked, we've talked about this a little bit in the past, but how do you think about the. The intent versus the intent from accident here? What are some signs that this is something where. Well, I didn't know this was happening because of XYZ release, which was discussed in your blog post, versus this was a known thing that was happening kind of similar to what we witnessed with Honey. Not to compare or pull them into one situ, one case because they're different, but to try to unpack the hysteria here. For people, what is accident, what is intent? What do people know and what do they not know? How do you kind of unpack that when you look at these situations?
A
Yeah, for Honey, there was extraordinary evidence of intent based on the application Logic that was embodied in the source code which I had and which I studied at great length in order to understand exactly what Honey was doing. Honey was very strategic. They were standing down when they thought they were being tested and they were not standing down when they were pretty sure no one was looking. Via is much less clever about it, even when they should have known they were being tested. First time user with name Ben Edelman logs into the app using my most standard email address that everybody knows and they still don't stand down even for me, even testing in my first minute after installation. So they're not being savvy about it like Honey. That doesn't mean that they should get some kind of a pass because they did it to everyone and didn't hide it quite right. Fact is they hid it in a different way. The worst misconduct we've talked about, the forced clicks, they hid it by only doing it in the iOS Safari extension, which hardly anyone tests. Honestly, a lot of people don't even know that there are iOS Safari extensions. That's only a five year old platform and kind of small. And so they were hiding in a different way. I suspect it will turn out that networks didn't know that this was going on. If we really needed to study the source code to look for evidence of intentionality, I think we'd find some evidence of intentionality in the source code in the config files. I haven't written anything about that yet. I'm kind of waiting to see what FIA's public statement is when they decide to respond to this, maybe in the coming Business week. Their statements to Bloomberg were conclusory. They said a recent bug and so forth, which really was unconvincing to me. As I described in my reply, for example, calling it recent. I don't know. Eight months is both a long time and a short time. But in the world of affiliate marketing misconduct, eight months is not recent. And to call it a bug seems pretty weird based on the software architecture that I'm looking at.
B
Yeah, yeah. And I think like, you know, you see a lot of the commentary and obviously there's, there's mistrust in. I talk a lot about, you know, the trust gap and mistrust in digital, mistrust in business, mistrust in so many, unfortunately so many areas of our, our lives now maybe versus, you know, where things were, you know, and you, you see the, the 30 for 30, you know, calling out, you know, Phoebe Gates and all this stuff. And I, and I think that our intention isn't to, you know, talk smack about individuals or be snarky about it. It's to kind of break down what happened at a very functional level, make sense for the world of affiliate and performance marketing and ultimately to educate so that we can be better at catching things that are not correct, not fair, not, not within terms of conditions, not within the rules of the game so that we can have a clean, well run, high performing industry and program and value for the brands that are relying on these rules to be valuable. Just as you. Like you said, there are hard working partners who are the currency of the ecosystem who have done all this work to put pieces of value in front of the users to go, oh, I do want to get my 10% value cash back or I do want to get a discount on this dress at, you know, Old Navy or whatever it might be. And so if that's being, you know, essentially taken and misattributed to another partner, you know, we, we want to understand that. We want to highlight, you know, highlight it. We want to understand how it happened to avoid it, you know, going forward.
A
I certainly agree with that. To me it calls for some soul searching to have incidents of this size and frequency. To have this and honey and Microsoft Edge, you know, trillion dollar company rather than your routine billion dollar company. To have those three inside of 12 calendar months to me suggests that whatever testing and compliance the networks are doing is not meeting expectations needs to get better. We need a better test suite. There have been some efforts down this path. I drafted new conditions for merchants to perhaps deploy a set of rules and protections that I hope will make shopping plugins easier to test. We can reduce the attack surface by simplifying the rules. There is a recent effort by Rakuten to provide a standard JavaScript library to handle stand down to the extent that one thinks the problem is stand down rather than some other kind of misconduct like the forced clicks we're seeing here. Racutent standard library could again reduce the attack surface. Use this library, follow it, don't play games and you'll automatically comply with stand down rules. That's kind of nice. Stand down library is not perfect. A bug in the standardized library would have even bigger problems because everyone would be using it. So there's a set of concerns there too. But ultimately I do think something has to change in order to retain merchant confidence in this and keep merchants wanting to spend their money in affiliate.
B
Yeah, you risk a lot if you're not having the integrity and the clarity around it and the rules being followed and enforced. You Talked a little bit about the stand down versus you know, the force clicks cookie stuffing and trying to kind of T shirt size. How big of an issue this is for business people, for people in performance marketing, for people in affiliate marketing. How much of it is a stand down issue versus the force clicks issue in your assessment?
A
The force clicks violation is a more surprising violation. You see it a lot less often in part maybe from the serious penalties that have been imposed for others. In part because the nature of the violation, it's not something that could reasonably happen by mistake. Maybe some stand down violations could happen by mistake and others couldn't. You have to look at them to figure it out. Stand down violations move money from one affiliate to another but do not increase a merchant's overall expense for the affiliate channel versus forced clicks. Move money from a merchant's bottom line profit into affiliates pockets. So they hit merchants in a very different way. They should make merchants angrier. They also move a larger amount of money on a per user, per device basis because you're turning all traffic into commissionable traffic versus stand down violations. Turn affiliate A's traffic into affiliate B's traffic but don't affect commissions. Well, non commissionable transactions at all. So I do think the numbers are going to be kind of big here. On the flip side, FIA isn't, you know, isn't as big as Honey. For example, the number of users who have FIA is smaller than the number of users who have Honey, but still pretty big. You look at the Apple App Store category rankings, you know they, they peaked I think in the top 20 of shopping plugins. Maybe at one point they were getting installs even faster than that. I haven't studied those numbers in great detail. Look, this is a shopping plugin that does have market acceptance. There's a set of users who like it, or think they like it, who have been installing it. It's not exactly my demographic or yours, but some people have this and the more users have it obviously the bigger the problem is for merchants.
B
Yeah, and what do we know about the players involved that have been kind of named or, or you know, that we can share in terms of the, the affiliate and performance marketing ecosystem. Who, who else is involved in it currently that we know that, that we can share?
A
Impact announced that they have suspended. I don't have a full understanding of what that means. Does that prevent them from getting paid for the recent work that they purportedly did? Suspending clearly isn't a clawback. We'd have a different word, a word like clawback for Trying to reclaim amounts previously paid. I haven't heard anything from the other networks. I imagine they're all looking at it, evaluating the evidence, seeing what they can see in their own systems, their own network, quality tests, records of traffic complaints, that kind of thing. Another thing to bear in mind for merchants is that FIA has quite a history of working as a sub affiliate. So you don't necessarily see them in their own name in your program. You might see them in someone else's name and might not even have the word FIA anywhere in your dashboard waiting to be found because you don't necessarily get the names of your sub affiliates. Oh, how I hate sub affiliates. I mean, cause a lot of problems for merchants. Anyone good should just apply directly. What are we doing here? But anyway, Via is often in a merchants program as a sub affiliate. And here's a twist which some of your team actually alerted me to ty. Via can both be an emergence program as a sub affiliate and as a direct relationship. And so when you find them in your program for the direct relationship, that's not necessarily all their traffic. It's not necessarily even a high fraction of their traffic. You might find it, think you found it. And actually most of their traffic is coming in a different way. Again. Oh, how I hate sub affiliates.
B
Yeah. And I'm appreciative of your call out to the industry to suggest a new way to kind of handle and categorize sub affiliate. And I think that that movement, I'll call it, is starting to get more traction. It's something for a number of years we've been, you know, advocating for, to, to be more direct and transparent. It kind of is sort of related to, you know, for, for a marketer, for a brand to be measured really effectively, to be able to see, you know, referring URLs. Most certainly. That's a, that's a practice we are absolutely coaching our teams on and being aware of and trying to be very, very transparent about. This is the referring URL traffic you're getting with these types of partners that you're working with. And then even going further beyond that, being able to see impression and exposure data, which is not something you're able to see on all network cases and all browser examples. Unfortunately, it's something we would prefer to have that transparency in the future. And I think that's a big reason why this, why we're talking about this, why we're advocating the industry. I've had some very good recent conversations with pretty high leadership at, at the network level, Founder, CEO, C suite, Multiple networks and multiple very reputable publishers that are involved in this, in this case, that are trying to make sense of it. And they are big believers in trying to move in that direction. But we need to see more action here as well.
A
Yeah, I'm reminded of what ebay did on sub affiliates. This is again decade plus ago. The eBay diaspora is real. Ebay was very skeptical of the compliance problems that came from sub affiliates, which were huge problems. And yet ebay, being one big company, knew the world was huge and didn't want to have relationships directly with every single little affiliate in the world, at least in that moment. So they accepted the existence of sub affiliates, but they wanted every sub affiliate to be a first class member of eBay's IT platform. They wanted to be able to track the impressions, the clicks and the conversions and the click rate and the conversion rate separately for each sub affiliate. So what they did, and it's so simple, I mean, like many problems in computer science, you can solve it with a level of basically factoring. They said, look, if you're going to be a super affiliate with sub affiliates, fine, do that, but give each sub affiliate its own affiliate ID so we can track it individually. So if you need a thousand affiliate IDs, okay, you can have a thousand affiliate IDs, but in our database they're going to be a thousand separate entries, not one with subs. And then all of their analytics that we're analyzing partner by partner, were immediately able to handle that. Such a simple change didn't require a large amount of software engineering, didn't require a bunch of new reports or dashboards, and really made a big difference in terms of getting to the bottom of that problem. So I hope some networks can think about that solution today. Obviously there are even fancier solutions, but I'm not necessarily looking for some fancy solution. I'm looking for something that gets to the bottom of this and helps merchants understand who they're paying and why. Without the world being so complicated.
B
Yeah, what's new is old in some ways. And here we are going back to, not to like beat a chest or celebrate too much, but it's like this stuff that was done by you and then ebay in other areas was innovative. And here we are. This should be, this should have been done 10 years ago, but here we are. When we think about, you know, you have a great background in obviously digital forensics, you think about, you know, fraud, you think about, think about legal, you have expertise in those areas, which is pretty rare and special and unique. Which puts you in a very important position to speak on and help guide the industry and understand these issues. Not to get into a court case or deposition conversation, but what does it. If someone is to be okay, this is an example or evidence of force clicks. What does it typically mean from a legal perspective that you can share with people that are trying to make sense of how big of an issue this is, how much of a legal mess this is without, you know, speaking on terms we can't. We can't speak on.
A
Sure. Well, in terms of evidence, a chain of custody, forensically robust methods. I like screen capture video. There are ways to screen capture video even from mobile devices like iOS. I like packet logs. The packet log shows you exactly what was happening. There are ways to collect packet logs even from mobile devices. It's a little bit trickier than, you know, the non HTTPs web of 20 years ago. Life has gotten harder in the subsequent decades. But that's okay. The forensics are fine. Ultimately, the legal claim is probably first and foremost, breach of contract. There is a contract. The contract has been breached. Lawyers don't have to wake up too early in the morning to know how that song goes. As to proving the breach, I think the proof is pretty well on my website. I don't think it's going to be that hard to prove the breach. Merchants who want to pursue their legal remedies should consult their attorneys, figure out how much is at issue. Obviously, suing about $100 is dumb. Suing about $100,000 is kind of annoying. Suing about a million or 10 million. I doubt there's any single merchant that lost $10 million. Unlike the huge ebay incidents of a while ago, this problem is spread across a large number of merchants. You almost need like a merchant class action which has its own problems.
B
Yeah, that's. That feels like a possible. It's a very fascinating point and I think you make a great one on that. Yeah.
A
You know, the. The network should advocate on behalf of their merchants. A network is there fundamentally to provide economies of scale to merchants. Merchants that wouldn't want to be in the business of designing the IT platform that the network provides, that wouldn't want to have to write all the rules. So the network provides template rules. Wouldn't want to have to figure this all out. Great. Now if the network determines that one of its affiliates has been cheating and a thousand different merchants need a refund of $1,000 to $10,000 each, the network could compel that. The network could bring suit on behalf of all of the merchants that it advises. Think about the legal particulars of that. Is it a proper case? But ultimately that's the kind of efficiency that a complicated economy demands. If we ask a thousand companies to each bring their own lawsuit, about $1,000, obviously it's never going to happen. The way to get this problem solved and to put the money back where it belongs is to do it efficiently and centrally. And the networks have just an awfully important role in doing that. I hope they will.
B
Yeah, I agree. How much does this do you think is browser extension related? Just trying to make sense of it all and not necessarily say, hey, all browser extensions are bad because there's example of those that function well, test well, have high integrity. And there's a lot of issues with them as well, especially with recent this isn't the first controversy we've reported on in the last 12 months, which is not ideal. What's your take on them as partner type and trying to piece together what's been done well and what's not working in the browser extension world.
A
You know, I think people who know me who have read my writings for a while know that I'm not a fan of shopping extensions. Not even really a fan of browser extensions. Where's the last really good browser extension you came across? I don't know. A password manager, something like that. It's good. There can be competing password managers and you don't have to use the password manager made by the same company that made your browser. But these shopping extensions have such a clear temptation to bend or break the rules, to twist the rules beyond recognition, to ignore other companies economic interest because they figure the other guys aren't going to notice and aren't paying attention. I have very little patience for that. When advising merchants and networks, my usual advice is can we just kick this stuff out and do the easy part of the business? Then you don't even need me, right? You don't need to pay me. I could go do something else. I got kids to spend time with. I don't get it fundamentally, but the temptation is real. There's affiliate managers who want to see number go up. Certainly networks want to see the numbers go up and as a result you get a bunch of industry participants who want these shopping plugins in their program. Whether the shopping plugins genuinely drive incremental value for the merchant shareholders, I have a lot more doubt. I can imagine ways to prove that. To test it to the title of the podcast, it would require some kind of randomization, right? We're going to give These users, the shopping plugin and these users, we don't give the shopping plugin and that can't be endogenous. We can't let the users decide whether they're in this group or that group. We can give this percent to these users and that percent to those users. A lot of shopping plugins are not set up to give any kind of personalized offer. They have one offer, you know, the cash back at Dell on laptops is 2% or, or what have you. And once you have one offer to every user, how are you ever going to test anything and measure the impact of this on that? So a lot would have to be done to really test it. I haven't seen a lot of people willing to do the work of engaging in tests like that. Without the tests. I fall back on economic theory. I fall back on intuition and hypothesis and supposition, which are all less reliable than the tests. But they all tell me to be skeptical of this stuff. Yeah.
B
And I would say agree. They're partners, affiliates generally, and also in the very small minority in terms of my opinion on browser extensions that are willing able to test, think about holdout testing, think about incrementality, think about the needs of the brand that's paying the bills, think about the needs of the user that's trying to navigate, know their shopping experience and, and even thinking about to some extent other affiliates in the space that are doing the lifting to educate and make a brand, make a something aware to a consumer to get credit at some point across the ecosystem. So I do think there are some good players out there. I think there are some very quality players out there. And fortunately this isn't, you know, widespread. Depends how we define that. It's getting to be a problem. And I think that that's why we're having this conversation. That's why you and I have done our second podcast about it, to raise awareness on it. I'm seeing, you know, such a flurry of, you know, piling on and digital environment that we, we are in which is good and bad. And so part of this is to make sense of what it is and what it isn't. I've seen a lot of falsehoods being talked about online of like, oh, this and it's that. And I think today you've done a good job of laying out the facts of the case candidly of like, what it is and what the, what the breach and the, and the violation was. And so I think that gives people an opportunity to know, you know, what are we Talking about here, I think there's still, as you said, the, the. We're in the middle of this, maybe even in the early part of this current fiasco or controversy, what you want to call it. And I think we're going to see some interesting things come out around response, around the size of the issue and around the subsequent likely legal or consequences part of this process.
A
Well, I certainly agree with all of that, Ty. The online reaction had so many people saying this seems the same as Honey, which is both true and not true and a little bit frustrating for me as a person involved in both episodes. Obviously Honey was just stand down. This is stand down and force clicks. That's kind of a big difference. Maybe it's a difference that is too subtle for some people. They're both breaches of affiliate network contracts. So in that sense, you know, a breach is a breach is a breach, but some breaches are worse than others. It will be interesting to see what comes next.
B
Yeah, it all, I mean, the force clicks one is a big violation in my view and I think, in your view and I think even if maybe the population of those affected was smaller, again, I don't, I don't have an exact take on it, but that's, that could be a concerning element to it in my view. You know, the iOS, you know, only showing up on the iOS is a big one as just as there's some similarities there that you alluded to where Honey was doing some very specific things to evade detection. This case, there was that, but in a more broader method, I think.
A
Absolutely. Thanks for your interest in this dye. Thanks for explaining it to people.
B
Yeah, no, I'm grateful. And for your continued communication, collaboration, trying to work through this with our team at Round Barn Labs, with the industry, with publishers that are looking to do the right thing and to be transparent, follow the rules and do the good work that is promoting products for people that they care about in a way that is legitimate. And so we're hoping that this emergency pod gives people some, some context, some information. It's not just hand waving stuff that we see online. Unfortunately, it explodes after these things happen, especially when it's involving celebrities or its daughter. That's not really what it's about. It's about just laying it out for everybody. Hopefully it's helpful and ideally we move to a role, we get better at mitigating these risks and we are highlighting what's good about our industry, which there's plenty of that. So hopefully it's helpful. Ben, thanks for joining me on a Saturday and have a great rest of your weekend, everybody. Hopefully we'll get this out soon so you can hear it, learn from it, and take action.
A
Thanks, D.
Host: Tye DeGrange
Guest: Ben Edelman (Affiliate Fraud Expert/“Lead Detective” on FIA investigation)
Date: July 15, 2026
This emergency episode tackles the unfolding controversy around FIA (also referred to as "Via") and serious allegations of affiliate fraud within B2B SaaS and e-commerce affiliate marketing. Host Tye DeGrange brings on fraud expert Ben Edelman to break down the facts, strip away the online hysteria, and explain the wider ramifications for the affiliate and performance marketing ecosystem.
Nature of the Allegations (01:34)
Forced Clicks: FIA’s iOS Safari browser extension was automatically firing affiliate links (without user action), allowing FIA to get credit for sales where the user never clicked an affiliate offer. Ben refers to this as “forced clicks,” a form of cookie stuffing.
“The Safari extension forces clicks. Some people call it cookie stuffing… There’s no need for a user to click or tap on an affiliate link for the affiliate link to get invoked. Kind of nuts. That hasn’t been allowed under affiliate network rules for quite a while.” – Ben Edelman [01:55]
Timeline: Evidence shows the misconduct dates back to at least December 2025, covering the crucial holiday season.
Industry Comparison: Ben recalls similar fraud cases from 2004, emphasizing the recurring nature of this problem.
Who is FIA? (03:41, 04:39)
Affiliate Marketing Basics (04:39)
The user must click/tap an affiliate offer and make a purchase for a commission to be valid.
“You can’t skip any of those steps. If the user didn’t click or didn’t tap, the rules say that’s not a commissionable event.” – Ben Edelman [04:45]
The FIA extension bypassed the required user action, a direct contract violation.
Taking Credit for Non-Generated Traffic (06:29)
In multi-touch affiliate journeys, browser extensions are required to “stand down” (not claim commission) if another partner drove the last click leading to a purchase.
FIA repeatedly failed (seemingly by design) to stand down, even when evidence of a prior affiliate click was present.
“It correctly classified that as a prior affiliate link… and then it set a variable called should stand down equal to false… What kind of barrel am I shooting into where I caught fish the first two times?” – Ben Edelman [09:21]
FIA’s failure to stand down disproportionately hurts other (“normal”) publishers who produce incremental value (actual reviews, endorsements, etc.).
Ben compares FIA’s errors to those seen in Honey and Microsoft Edge plugins but highlights FIA is less subtle and less sophisticated in their concealment.
Evidence points to intent:
“Even testing in my first minute after installation… they still don’t stand down even for me.” – Ben Edelman [13:07]
FIA disguised the worst misconduct (forced clicks) in an obscure iOS Safari extension—a place few would notice or check.
Merchant & Network Blind Spots (17:04, 18:36)
“Whatever testing and compliance the networks are doing is not meeting expectations… We need a better test suite…” – Ben Edelman [17:12]
Risks for Brands and the Industry (18:36, 19:05)
Many merchants may not know FIA is operating in their programs due to sub-affiliate relationships—FIA can appear both directly and via third parties.
“Oh, how I hate sub affiliates… Anyone good should just apply directly.” – Ben Edelman [21:52]
Ben advocates for giving each sub-affiliate its own ID for full traceability (cites eBay’s long-standing approach).
What constitutes strong legal evidence (video, packet logs, chain of custody).
Primary claim: breach of contract.
“Lawyers don’t have to wake up too early in the morning to know how that song goes. As to proving the breach, I think the proof is pretty well on my website.” – Ben Edelman [27:14]
Suggests class action or network-led action is more efficient than expecting every merchant to pursue their own separate case.
Ben’s stance: skeptical of shopping/browser extensions due to repeated rule violations and limited incremental value for merchants.
“Where’s the last really good browser extension you came across? … Shopping extensions have such a clear temptation to bend or break the rules…” – Ben Edelman [30:10]
Calls for rigorous testing and “holdout” experiments to validate real partner value—rarely done in the industry.
On FIA’s Misconduct:
“They were hiding in a different way. The worst misconduct, the forced clicks, they hid it by only doing it in the iOS Safari extension, which hardly anyone tests.” – Ben Edelman [13:51]
On Merchant Protection:
“We need to help [smaller publishers] because their traffic is highly incremental and we need to help them because they’re vulnerable because a shopping plugin… has this weird opportunity to claim commission on everything…” – Ben Edelman [11:31]
On Network Responsibility:
“The network should advocate on behalf of their merchants… the network provides template rules… if the network determines that one of its affiliates has been cheating… the network could compel that.” – Ben Edelman [28:25]
Industry Call to Action:
“I hope some networks can think about that solution today… I’m not necessarily looking for some fancy solution. I’m looking for something that gets to the bottom of this and helps merchants understand who they’re paying and why. Without the world being so complicated.” – Ben Edelman [25:36]
This episode offers a clear and urgent exploration of the FIA affiliate fraud case, the technical and ethical breaches involved, and the broader implications for B2B SaaS and e-commerce partnership programs. Ben Edelman provides deep, candid expert perspective and draws actionable lessons for brands, networks, and practitioners, calling for increased vigilance, transparency, and compliance to keep the affiliate marketing space clean, high-performing, and trusted.
End of Summary