The Phia extension for Safari iOS is suspected of stealing over $10 million from online retailers through forced clicks in affiliate programs. Research by Capital One Shopping and expert Benjamin Edelman revealed that the extension opened background tabs and automatically triggered affiliate tracking links without user action — brands ended up paying commissions for sales that would have happened regardless of the affiliate partner's involvement.
How the forced click scheme worked
When a user with the Phia extension installed visited a website participating in an affiliate program, the extension would create an affiliate transaction in the background. Edelman calls this intentional fraud, not a software glitch: "Forced clicks cannot be unintentional by the nature of the violation itself."
The distinction from the Honey scandal is fundamental. Honey intercepted commissions for a referral that had already occurred through another blogger or media outlet — the advertiser still paid one commission per sale, only the recipient changed. Phia created commissions where there was no affiliate referral at all. Brands incurred additional expenses for each such transaction.
Why affiliate fraud has scaled up
Forced clicks encompass a larger volume of transactions than traditional affiliate marketing. Partner programs typically account for only a portion of a brand's online sales — specifically those where a customer arrived via a blogger's or publisher's referral link. The Phia scheme could convert any visit to a retailer's site into an affiliate transaction, including direct traffic and organic search results.
Edelman notes anomalously high metrics: "With forced clicks, both CTR and revenue per user will be implausibly high." These economic signals should have raised red flags for both Phia and affiliate networks — but the extension operated in mobile Safari, where oversight is traditionally weaker than in desktop browsers.
"Merchants are victims of forced clicks. If affiliate clicks are generated without legitimate referral, advertisers pay commissions for sales that would have happened anyway"
Precedent: prison time for forced clicks in eBay
Nearly 20 years ago, Edelman discovered a similar scheme among eBay's partners — Sean Hogan and Bryan Dunning. Both used forced clicks to obtain unearned commissions. eBay passed the materials to the FBI, both were charged with wire fraud, both pleaded guilty and served prison time. Dunning's charges alleged $5.3 million in illegal compensation, Hogan's — $15.5 million.
Phia has not yet faced criminal charges, and the facts of the cases differ, but the precedent shows that forced click schemes can be prosecuted as criminal fraud if used to appropriate commissions.
Takeaways for brands: how to protect your media plan from affiliate fraud
For advertisers, the Phia story is a wake-up call to review the transparency of affiliate programs. Abnormally high CTR or conversion per user, atypical traffic sources in mobile channels — these are markers requiring audit. Brands working through influencer marketing and media buying with bloggers get a more controllable payment model: CPM or fixed integration cost instead of commissions per order. A transparent media plan with reach forecasts and KPIs shows exactly what the brand is paying for — the ETC team helps build such campaigns with blogger selection, audience verification, and publication monitoring.
Frequently asked questions
What are forced clicks in affiliate marketing
Forced clicks are automatic generation of affiliate tracking links without user action. A browser extension or app opens hidden tabs and simulates a referral link click, even though the user didn't consciously click it — the advertiser pays the partner a commission for a sale that would have happened anyway.
How does Phia differ from Honey
Honey intercepted commissions for an existing affiliate referral, redirecting it from one publisher to itself — the brand paid one commission per deal. Phia created a new affiliate transaction where no partner existed at all: it turned direct site visits into partner sales, increasing the brand's commission expenses without any real contribution to acquiring the customer.
How can brands protect themselves from affiliate fraud
Audit anomalous metrics in your affiliate programs: implausibly high CTR, suspiciously high revenue per user, traffic concentration from mobile extensions. Use transparent payment models — fixed integration cost with bloggers or CPM instead of CPA commissions, where the traffic source is harder to verify.
In brief
- The Phia extension is suspected of stealing over $10 million from brands through forced clicks in Safari iOS — it opened background tabs and created affiliate transactions without user action.
- Unlike Honey, which redistributed commissions between partners, Phia created new commissions where no affiliate referral existed — the brand bore additional expenses for each such sale.
- Similar schemes at eBay resulted in criminal cases and prison time for two affiliate partners who stole $5.3 million and $15.5 million.
- For brands, the lesson is to audit affiliate programs for anomalous metrics and choose transparent payment models, including working with bloggers through media buying at fixed rates.
Want to see where the market is heading before your competitors do? The ETC team builds a media strategy and media plan for your niche — with reach forecasts and KPIs fixed in the contract.