Cookie stuffing: the affiliate fraud tactic behind Phoebe Gates’ Phia scandal


Cookie stuffing, the affiliate fraud tactic at the center of Phoebe Gates’ Phia scandal, is a deceptive practice where tracking cookies are placed on a user’s browser without their knowledge to falsely claim credit for online sales. When someone shops using a service like Phia, the software drops a “cookie” to track that the service helped drive the sale and earn a commission—but cookie stuffing bypasses this legitimate process by inserting cookies into checkout flows even when customers never engaged with the service.

According to the Wikipedia entry on cookie stuffing, affiliates engaging in the practice use invasive techniques like pop-up ads to falsely claim credit for sales they did not facilitate. The SEON resource dictionary defines it as a method fraudulent affiliates use to trick websites into thinking they have sent them traffic when they have not done so.

Computer screen showing browser cookie tracking data, affiliate marketing dashboard with transaction logs, and a highlighted warning notification about fraudulent cookie insertion

Phia, the AI-powered shopping startup co-founded by Phoebe Gates and Sophia Kianni, became the public face of this fraud in 2026. According to TechCrunch, the company was accused of taking credit and commission for affiliate purchases it did not help to generate through cookie stuffing. When Bloomberg first published its investigation in July, Phia claimed the company had only learned of the issue when Bloomberg reached out—but new reporting told a different story.

In August 2026, Bloomberg revealed that Gates and Kianni knew their startup was cookie stuffing as far back as December 2025, based on leaked Slack messages and sources familiar with the matter. According to the New York Post, internal communications showed Gates messaging developers in December to confirm that Phia was dropping a cookie each time its browser extension popped up, even if the shopper did not click a coupon. In another instance, Kianni suggested a feature that would drop a cookie when a user tried to close out a Phia pop-up, though a colleague noted this violated Google Chrome’s policies.

The scale of the fraud was substantial. According to the New York Post, cookie stuffing accounted for approximately 51 percent of the merchandise value that Phia claimed credit for in June 2026. When Phia disabled the cookie stuffing features in July, the financial impact was dramatic: average daily revenue plummeted from around $80,000 to between $10,000 and $28,000, according to Bloomberg’s analysis cited by the Post.

What Phia initially characterized as a software bug was actually a deliberately built feature. According to the New York Post, an internal dashboard reviewed by Bloomberg showed the feature was called “enable coupon auto drop” and could be switched on and off. The company later issued a statement saying any features causing misattributions were removed on July 7 and that it was “reviewing every transaction” and issuing transaction reversals to brand partners.

Phia app interface on smartphone screen showing shopping features, with a highlighted section showing affiliate commission settings and toggle switches

The legal consequences of cookie stuffing are severe. According to Givner Law, cookie stuffing is typically treated as federal wire fraud in U.S. courts, carrying a maximum penalty of up to 20 years in prison plus fines and restitution. Chargebacks911 confirmed that cookie stuffing can be prosecuted as wire fraud under 18 U.S.C. § 1343, which can result in a sentence of up to 20 years.

The Phia scandal is not the first time cookie stuffing has drawn scrutiny. Phoebe Gates’ Phia reportedly knew of cookie stuffing for months, and the practice has broader implications for the affiliate marketing industry. In 2025, PayPal’s Honey browser extension faced similar allegations of cookie stuffing and affiliate fraud, with class action lawsuits claiming the extension was stealing commissions from content creators by swapping in its own affiliate cookies. According to The Verge, Honey faced accusations of stealing affiliate revenue and exploiting small businesses, leading to major merchants dropping the extension from their networks.

Affiliate platforms typically prohibit cookie stuffing in their contracts precisely because it diverts revenue from legitimate affiliate marketers. According to TechCrunch, when affiliate platforms sign on to work in a marketplace, they sign a contract stating that cookie stuffing is banned because it is unfair to other affiliates. The practice has become common enough that fraud detection firms now track it as a major threat to affiliate marketing networks.

Sources

  • TechCrunch — reported that Phoebe Gates and Sophia Kianni knew Phia was cookie stuffing for months, including details of the practice and Phia’s response
  • The New York Post — provided details of leaked Slack messages, the revenue decline after disabling cookie stuffing, and the feature mechanics
  • Bloomberg — conducted the original investigation and follow-up reporting on the founders’ knowledge and internal dashboard details
  • Wikipedia — defined cookie stuffing and described how affiliates use invasive techniques to falsely claim credit
  • SEON — explained cookie stuffing as a method fraudulent affiliates use to trick websites into thinking they sent traffic
  • Givner Law — warned that cookie stuffing is typically treated as federal wire fraud with maximum penalties of 20 years
  • Chargebacks911 — confirmed that cookie stuffing can be prosecuted as wire fraud under federal statute with up to 20 years imprisonment
  • The Verge — reported on Honey browser extension’s similar cookie stuffing allegations and merchant departures

Give your feedback

Be the first to rate this post
or leave a detailed review



ECIKS.org is an independent media. Support us by adding us to your Google News favorites:

Post a comment

Publish a comment