Key takeaways
- Self-referral is a partner converting through their own link or code to earn on their own purchase.
- Coupon abuse is a code earning commission on traffic the partner never genuinely drove, often via leaked codes.
- Detect self-referral by correlating the partner's identity, device, and IP with the converting customer.
- Detect coupon abuse by comparing redemptions against the partner's real click volume and audience size.
- Flag and hold suspicious conversions through a clearing window so clawbacks can reverse anything confirmed.
Self-referral and coupon abuse are the frauds that hide in plain sight, because the conversions are real purchases. Someone genuinely bought something — the fraud is in who claims credit and whether they earned it. That makes these harder to spot than obvious bot traffic, but they leave correlation signatures you can detect systematically instead of relying on a finance manager's gut feeling.
What is self-referral fraud?
Self-referral fraud is when an affiliate buys through their own tracking link or code to pocket commission on their own purchase. It can be small and opportunistic — a partner saving on a personal order — or systematic, with rings of accounts buying and refunding to farm commissions.
How do you detect self-referrals?
You detect self-referrals by correlating the converting customer with the partner across the identifiers a person can't easily separate. One overlap is suspicious; several together is close to conclusive.
- Email match: the customer's email matches or shares a domain with the partner account.
- Device match: the conversion comes from a device the partner has used to log in.
- IP match: the converting IP overlaps with the partner's known IPs.
- Payment fingerprint: the same card or billing details recur across the partner's own conversions.
- Behavior: the click-to-conversion gap is implausibly short, as if the same person did both.