Most brand managers picture brand-bidding fraud as one person, in a basement, running one ad on your name. That mental model is why so many programs lose so much money — because the model is wrong by three orders of magnitude.
Here is the documented reality. In March 2025, the threat-intelligence firm QuoIntelligence published an autopsy of a single coordinated operation that was, among other things, promoting NordVPN. The numbers: over 1,000 subdomains across seven primary domains, 500+ fake social-media accounts, AI-generated content in eight languages, parasite-hosted across LinkedIn, Medium, Tumblr, WordPress and Facebook — all tied together by one affiliate ID. In QuoIntelligence's own words, "NordVPN promotions consistently use affiliate ID 103411 in redirection links and final URLs, indicating a structured tracking system." One ID. A thousand front doors.
That is what you are actually up against when brand bidding gets serious, and almost nobody on the defender's side has ever laid out how one of these operations is built. So here it is — from the catching side. Every layer, the fingerprint each one leaves in your evidence, and how you see through it. The point isn't to admire the machine. It's to stop fighting individual ads and start recognizing the operation behind them.
I run AdCrime; dismantling these is the job. This is intelligence for defenders — how the machine is assembled and where it shows itself. It is deliberately not a how-to, and it doesn't touch how we catch them; it's about what you can recognize.
The case in front of us
Before the anatomy, sit with the QuoIntelligence operation a moment longer, because every layer below is visible in it.
It ran AI-generated, keyword-stuffed content in English, Spanish, Italian, Greek, German, Portuguese, Polish and Lithuanian, seeded across hundreds of fake LinkedIn company pages and Medium/Tumblr/WordPress posts — parasite hosting on high-authority platforms to manufacture search visibility. The subdomains (names like bestvpnprice.com and five other primary domains, fanning into 1,000+ subdomains) acted as redirection hubs: a user landed on one, got bounced through the affiliate link, and arrived at the NordVPN checkout with 103411 embedded. The operation was event-driven — it spun up around affiliate competitions and major sporting events, and pivoted between iGaming and VPN promotions by season to chase the best payouts. Attribution stayed inconclusive (the infrastructure points to a single coordinated entity, possibly involving a Polish SEO operator, but shared tooling means others could ride the same rails) — and that inconclusiveness is itself a feature of how these are built.
The lesson in one sentence: the unit of this fraud is not an ad or a domain. It is an operation, and the only thread that ties the whole thing together is the affiliate ID. Hold that thought; it's the key to everything below.
The six layers — and the tell each one leaves
Layer 1 — One identity, a thousand faces
What it is. A serious operation does not run one ad from one account. It spreads across many disposable domains, subdomains, and ad accounts, so that when any single ad, page, or account gets reported and killed, the operation continues uninterrupted under the next one. The 1,000+ subdomains in the QuoIntelligence case are this layer made literal.
The fingerprint. For all that surface-level multiplicity, the operation has to get paid, and getting paid requires a consistent affiliate account. So the same publisher ID resurfaces — across different domains, different ads, different days. The faces change; the payee can't.
How you catch it. You stop chasing domains and start resolving the publisher ID behind each detection (the awinaffid, the CJ PID, the Impact partner ID — see how to read a redirect chain and the per-network guides). When the same ID shows up behind twelve "different" coupon sites, you haven't found twelve problems — you've found one operation, and one account to terminate. Block the domain and 999 remain; block the ID and the whole thing loses its paycheck.
Layer 2 — The keyword spread
What it is. The operation doesn't bid only your exact brand name (too easy to catch). It blankets the modifier space — [brand] coupon, [brand] promo code, [brand] review, [brand] login, [brand] vs [competitor], and common misspellings — to catch buyers at every late-funnel moment, while keeping each individual term low-profile.
The fingerprint. Two tells separate a deliberate operator from an "accidental broad-match" bystander: your brand term sitting in the affiliate's {keyword} tracking parameter (only the brand appearing, not the full query, signals targeting), and a high impression share on your branded terms. And the decisive one: strip your brand out of the query and a deliberate bidder vanishes — they were never targeting the category, only you.
How you catch it. Scan the full modifier set, not just your bare brand name — the spread is the surface area, and a check that only looks at [brand] misses most of it. (More on intent vs. accident in how affiliates hide brand bidding.)
Layer 3 — The fronts
What it is. Between the ad and your checkout sits a front: a coupon page, a thin "review" page, a typosquat lookalike, or one of those thousand subdomains. Its only job is to receive the click, drop the affiliate cookie, and pass the user through to you. The coupon front is the most common because it's the most disarming — the user expects a coupon site, so nothing looks wrong (the full mechanics are in the coupon affiliate playbook).
The fingerprint. The redirect chain. A legitimate result goes where it says it goes. A front bounces the user through an affiliate network hop — awin1.com, a CJ alphabet-soup domain, an Impact sjv.io short link — on the way to your site. That hop is the proof the "review" or "deal" was a tollbooth. For typosquat fronts, the domain's WHOIS (registered last month, privacy-protected, offshore) is the second tell.
How you catch it. Follow every chain to the end and read the hop. The front is designed to look like content; the redirect is where it confesses.
Layer 4 — The disappearing act
What it is. The operation is engineered to be invisible to exactly the check a brand runs. It geo-targets away from your headquarters, schedules ads for overnight and weekends, targets the device you don't check, and cloaks — serving a clean, compliant page to anything that looks like a monitoring tool while serving the real redirect to actual shoppers. The most sophisticated versions go further and try to detect compliance testers specifically — the kind of tester-evasion Ben Edelman documented in the Honey teardown, where the software behaved one way when it suspected it was being watched and another for ordinary users (see the Honey piece).
The fingerprint. A program that is "clean" every time you check from the office but is bleeding commission is showing you the disappearing act, not a clean program. The tell is structural: the absence of evidence from one vantage point, against rising affiliate commissions or branded CPC.
How you catch it. You can't beat systematic evasion from one desk, one IP, one time of day. The only counter is to look from where the fraud actually runs — many markets, many hours and devices, arriving like a real shopper rather than an obvious checker, continuously. That's a coverage problem, not a cleverness problem, and it's the whole argument of how affiliates hide brand bidding.
Layer 5 — The attribution capture (and the identity it hides)
What it is. The actual theft is mundane: the front's affiliate tracking link sets a last-click cookie, and when the user completes the purchase they were always going to make, your network pays the operation a commission. The sophistication is in hiding who got paid.
The fingerprint. Here's where operations try to fog the trail. The value that's most visible on your landing-page URL is usually a per-click token — an Awin awc, an Impact irclickid, a CJ cjevent — a hash that resets every click and identifies no one. The static publisher ID that actually names the account (the awinaffid, the PID, the partner ID) is upstream in the chain, or behind the cloak. Grab the visible token and your complaint dies; find the static ID and you have the operation's payee.
How you catch it. Pull the static publisher ID out of the chain, never the click hash — the difference between the two is the difference between a filed complaint and a closed ticket (Awin, CJ, Impact).
Layer 6 — Industrial scale
What it is. What turns a nuisance into the QuoIntelligence case is automation. AI generates thousands of pages of multilingual content for near-zero cost. Bot-managed fake social accounts seed them. Parasite hosting borrows the authority of LinkedIn and Medium. And the whole thing is timed to your calendar — spinning up around your Black Friday, your student-discount push, your affiliate competition — because that's when the interceptable, already-decided traffic peaks.
The fingerprint. The coordination is the signature: a cluster of subdomains sharing hosting and naming patterns, a wave of new "publishers" appearing in lockstep with your promotion, the same affiliate ID under all of it. No single ad looks like much. The pattern across them is unmistakable — if you're looking at the pattern.
How you catch it. This is where individual detection isn't enough and you need the aggregate view: which IDs recur, which fronts share infrastructure, which timing tracks your campaigns. It's the difference between catching an ad and mapping an operation — and it's why the data layer matters (see The State of Affiliate Brand-Bidding 2026).
Why they bother: the economics of an operation
Lay the layers over the math and the business case is obvious. The commission on a VPN or SaaS sale can be 30–100% of the first payment; the branded CPC to intercept that sale is often a few dollars; and the marginal cost of the thousand-and-first subdomain, with AI writing the content, is essentially zero. That's an arbitrage that scales — which is exactly why it gets industrialized.
It's also why the new and the unwatched get hit first. Affiliate-management veterans have described for years a standing population of PPC affiliates who monitor the new-program listings at every network and "crank up campaigns on them all" the moment a program launches and before its terms and monitoring are in place. A brand that hasn't audited assumes silence means safety; to an operation, silence means an open door. And the scale a single operator can reach is not theoretical — one monitoring vendor reported a single partner running 89,000 brand infringements against one program over a year (vendor-reported, so weight it as directional, but the order of magnitude is the point).
What this changes about how you defend
If you take one thing from the anatomy, take this: you are not fighting an ad. You are fighting an operation, and you have to fight it at the layer where it's actually singular — the affiliate ID.
Everything an operation does at the surface is built to be plural and disposable: the domains, the subdomains, the ad accounts, the fake profiles, the languages. All of it regenerates. The one thing that can't multiply freely, because it's how the money comes home, is the publisher account. So the entire defensive strategy collapses to three moves you've now seen in every layer:
- See the whole surface — scan the modifier spread, from many markets and times, like a real user, because the operation is engineered to hide from the one check you'd run by default.
- Resolve to the identity — pull the static publisher ID from every chain, so twelve fronts collapse into one account.
- Act on the operation, not the instance — file on the ID, watch for it resurfacing, and treat a wave of coordinated fronts as the single thing it is.
Block a domain and you've inconvenienced an operation for an afternoon. Terminate the publisher ID, inside the validation window, with the evidence the network needs, and you've taken its paycheck. That's the difference between playing whack-a-mole and dismantling the machine.
Mario Vaher is the founder of AdCrime, which scans Google Ads across multiple regions for affiliates bidding on brands they aren't authorized to touch, resolves the redirect chain and publisher ID behind each one, and packages it as the evidence you'd file with the network — built to surface the operation, not just the ad. If you want to see what's bidding on your brand right now, the first scan is free, or read the full, ungated Affiliate Brand-Bidding Fraud Playbook.