Affiliate fraud sounds like something that happens to big networks with bot farms and stolen cards. For a Shopify brand it is almost never that. It is a customer who signed up as an affiliate to get 15% back on their own orders. It is a code that ended up on a coupon site and now gets applied to every sale, including the ones your ads paid for. It is a creator who bid on your brand name in Google and collected commission on people who were already looking for you.
None of it is clever, and all of it is cheap to stop once you know what to look for. This checklist covers the five patterns that account for most of the leakage in Shopify affiliate programs, how each one looks in your data, and the rule or setting that closes it.
Run your affiliate program on Shopify
Install Reveshare from the Shopify App Store and start turning customers into ambassadors.
Get the app →The five patterns
Where commission actually leaks
- Self-referral: an affiliate using their own code or link on their own orders
- Coupon-site leakage: a code posted publicly and applied by shoppers who never saw the affiliate
- Brand bidding: paid search ads on your own brand terms, intercepting customers who were already coming
- Code sharing and stacking: codes passed around in groups or combined with other offers
- Refund and return gaming: orders placed for the commission, then returned after the payout
1. Self-referral
What it is. An affiliate places an order with their own code or through their own link. In a customer ambassador program this is the most common leak by a wide margin, because the affiliate is, by design, also a customer. Some do it without realising it is a problem. Some sign up purely for the discount-plus-commission arithmetic.
How it looks in the data. The order's customer email matches the affiliate's email, or the shipping address matches the affiliate's profile, or a single affiliate has a "conversion rate" close to 100% with a handful of orders and no clicks from anyone else.
What it costs. The commission plus the customer discount, on an order that would have happened anyway. On a 15% commission and a 15% customer discount, you are giving away 30% of an order you already had.
The fix. Two layers. First, a written rule in your terms that self-purchases are not commissionable, so there is no argument later. Second, automatic detection. On plans with self-serve auto cleaning, Reveshare flags orders where the buyer matches the affiliate and keeps them out of commission, so you are not reviewing orders by hand. For plans without it, a weekly export filtered on customer email equals affiliate email catches most of it.
2. Coupon-site leakage
What it is. An affiliate's static code gets posted on a deal site, a browser extension picks it up, and from then on it is applied automatically to a share of your checkouts by people who never saw the affiliate's content. You pay commission on your own organic and paid traffic.
How it looks in the data. A single code's orders jump sharply with no corresponding content from the affiliate. The buyers are geographically spread in a way that does not match the affiliate's audience. Conversion on the code is high because the shoppers were already at checkout when the extension applied it.
What it costs. This is usually the biggest single leak. A leaked code that gets applied to 5% of your checkouts at 15% commission is 0.75% of revenue paid to someone who did nothing for it, forever, until you notice.
The fix. Stop relying on static codes as the only attribution. With Sneakylinks, the affiliate shares a link, and each click mints a short-lived code for that shopper. The code expires after the program's code lifetime, 24 hours by default, so there is nothing durable to post on a deal site. The click and the order are tied to the affiliate through the link, not through a code that anyone can copy.
Where you must use static codes, make them unattractive to scrapers: usage limits, once-per-customer, and a product scope. And watch for the jump.
Static code only
- One durable code per affiliate, valid indefinitely
- Scrapable by extensions and deal sites within days of first use
- Applied at checkout by shoppers who never met the affiliate
- Attribution is 'whoever's code got typed'
Sneakylink attribution
- One link per affiliate, a fresh code per click
- Codes expire in hours, so there is nothing worth posting
- Order ties back to the click, not to a string of text
- Attribution is 'whose link brought this shopper'
Product tour
See how attribution actually works
Sneakylinks track the sale even when the code is never typed. Post-checkout referrals turn the thank-you page into your recruiter.
3. Brand bidding
What it is. An affiliate runs paid search ads on your brand name, or misspellings of it, and drops their code on the landing page. Customers who searched for you by name, because your own marketing worked, arrive through the affiliate's ad and you pay commission on the sale, plus your own brand-term ad costs go up because someone is bidding against you.
How it looks in the data. An affiliate with high volume, very high conversion, and no visible audience. Their traffic converts at the rate of branded search because it is branded search. Your own branded CPC creeps up.
What it costs. Commission on customers you already owned, plus inflated ad spend on your own name.
The fix. A clear line in your terms: no paid search on brand terms or misspellings, no ad copy that could be mistaken for the brand's own. Then check occasionally by searching your brand name in a private window and clicking anything that is not you. When you find it, one warning, then removal.
4. Code sharing and stacking
What it is. Two related behaviours. Sharing is when a code is passed around in a group chat, a forum or a family, so one affiliate is effectively running a discount club. Stacking is when a shopper combines the affiliate discount with another offer that was not meant to be combined.
How it looks in the data. Sharing looks like a single code with many orders from a tight geographic cluster, or from repeat customers who never use anyone else's code. Stacking looks like orders with a lower net value than the offer should produce.
What it costs. Sharing is a milder version of coupon leakage. Stacking eats margin on every affected order.
The fix. Sharing is partly a design question: if your customer discount is large enough that people organise around it, the discount is too large. Bring it down and put the value into the commission instead. Stacking is a Shopify configuration question: set discount combinations so affiliate codes do not combine with sitewide sales, and use once-per-customer on campaign codes.
5. Refund and return gaming
What it is. Orders placed through an affiliate's code, commission paid, then the order refunded or returned. Sometimes the affiliate and the buyer are the same person. Sometimes it is simply the normal return rate landing after you paid.
How it looks in the data. A refund rate on one affiliate's orders that is well above your store average. Or, more subtly, a program-wide gap between commissions paid and net revenue after refunds.
What it costs. Commission on revenue you never kept.
The fix. Do not pay on orders that can still be returned. Reveshare tracks refunds against the orders that earned commission, so commission on a refunded order is reversed rather than paid out. Set your payout timing to sit outside your return window, so an order has to survive the return period before its commission is released. If your window is 30 days, monthly payouts on the prior month's orders line up naturally.
A commission that is only released once the order can no longer be returned removes the incentive to place and refund. Most brands run payouts monthly on the previous month's orders, which handles it automatically.
Putting it together: the monthly audit
You do not need a fraud team. You need twenty minutes a month and four sorted lists.
Sort affiliates by conversion rate, descending
Anyone near 100% with more than a few orders needs a look. Self-referral and brand bidding both produce this signature.
Sort codes by order count, and look at the month-over-month change
A code whose orders doubled without the affiliate posting anything is probably leaked. Search the code in a private window to confirm.
Filter orders where buyer email matches affiliate email
On plans with auto cleaning, this is done for you and the orders are already excluded. Otherwise, export and filter. Reverse any commission that got through.
Compare refund rate per affiliate to the store average
An affiliate at three times the store's return rate is either sending the wrong customers or gaming. Either way, a conversation.
Search your brand name and misspellings in a private window
Click every ad that is not yours. If it lands on an affiliate code, you have found a brand bidder.
Have a question about your program?
Payouts, removals, tier setup, migrations. Write to the team and a real person replies, usually the same day.
Email the team →Conclusion
Affiliate fraud in a Shopify program is rarely dramatic. It is a customer buying with their own code, a code on a coupon site, an ad on your brand name, a code shared in a group chat, and an order returned after payout. Each one has a clear signature in your data and a specific fix: written rules, automatic self-referral cleaning, link-based attribution with short-lived codes, Shopify discount combination settings, and payouts timed after the return window. Twenty minutes a month keeps all five in check.
See pricing that scales with you
Compare plans and find the right fit for your brand and creator volume.
View pricing →Frequently Asked Questions
Read more
BFCM 2026 for Affiliate Programs: A Six-Week Countdown From Recruiting to Payout
Black Friday is 27 November 2026 and the affiliate program that performs is the one that was ready in October. Here is a week-by-week plan: recruiting, briefs, scheduled campaign codes, fraud settings, a tracking test, Meta whitelisting, the go-live checklist, and what to do in the week after.
Affiliate Payouts Without the Spreadsheet: Timing, Methods, Tax Forms and What to Do When One Fails
Paying affiliates is where good programs quietly lose trust. Learn when to run payouts so refunds cannot bite, how balances become pending payouts, which payment details and tax forms to collect and when, how reversals work, and what to do on the day a payment bounces.
Your Meta Pixel Is Lying About Affiliate Sales: Fixing Attribution in Both Directions
The browser pixel misses affiliate orders it should see and Meta claims affiliate orders it did not earn, so the two dashboards never agree. Learn why each one is wrong, how server-side conversion tracking from Reveshare fixes the undercount, and a monthly routine for reading both reports without paying twice.