Intelligence · Detection & Forensics

How Affiliates Hide Brand Bidding: Geo-Targeting, Dayparting, and Cloaking (and Why Your SERP Check Comes Back Clean)

By Mario Vaher·August 27, 2026·9 min read·Field report

You searched your own brand name in Google from your desk, saw nothing but your own ad, and concluded your program is clean. I want to take that conclusion away from you, because it's the single most expensive mistake in brand protection.

A clean SERP from your office doesn't mean no affiliate is bidding on your brand. Very often it means the opposite: that the affiliate is good enough to hide from exactly the check you just ran. Sophisticated brand-bidding affiliates don't run their ads everywhere, all the time, to everyone. They run them where you aren't looking, when you aren't looking, on devices you didn't check, and behind a page that shows your compliance team something different from what it shows a real shopper. The result is a fraud that is, by design, invisible to a manual spot check.

I run AdCrime, so I look at this from the catching side. This is the hiding side — the four ways brand-bidding affiliates disappear, how to tell a deliberate bidder from an accidental one, and why "I checked and it looked fine" is the emptiest sentence in affiliate compliance.

The honest version of the thesis: absence of evidence is not evidence of absence. A single check that comes back clean tells you almost nothing, because the whole game is built around making that one check come back clean.

The case that taught the whole industry this

The clearest illustration in the public record comes from Jamie Birch of the agency JEBCommerce, who was managing paid search for the retailer Coldwater Creek. An affiliate was bidding on the brand's terms — but Birch's manual checks always came back clean, so for a long time he had no idea. In his words: "I only found out when I traveled to a state I usually didn't travel to… I had no idea what geo targeting was at the time and he ended up swindling away tens of thousands in commissions from us that we weren't able to get back."

The affiliate had simply excluded the state Birch worked in from the ad campaign. Every check Birch ran from his own location returned nothing, because the ad was configured to never show there. He only saw it by accident, from a different state, far too late to recover the money. That's evasion tactic number one, and it's the simplest of the four.


The four ways affiliates stay invisible

1. Geo-targeting — they exclude your home region

Google Ads lets an advertiser include or exclude locations down to a city or radius. A brand-bidding affiliate excludes the brand's headquarters city, state, or the region where its compliance team sits. The ad then runs in every market that matters — where your customers are — but never where your checkers are. You search from the office; the affiliate's ad was specifically told not to appear there. This is why a brand with customers across many countries cannot validate anything from one location: the fraud may be live in nine markets and dark in the tenth, and the tenth is the one you checked.

2. Dayparting — they only run when no one's watching

"Dayparting" is scheduling ads to specific hours and days. Affiliates run brand-bid campaigns overnight, on weekends, and during holidays — the windows when brand managers are asleep, off, or not monitoring. A 2pm-Tuesday check from the office is the one time the ads are reliably not running. Combine this with geo-targeting and the surface you'd have to monitor to catch it expands fast.

3. Device-targeting — they pick a screen you didn't check

Bidding strategies and ad delivery differ by device, and an affiliate can target mobile-only (or desktop-only). If you check from your desktop and the campaign runs on mobile, you see nothing. Most manual checks are run on whatever screen is in front of the person checking — usually a desktop — and that's a coin-flip the affiliate gets to call.

4. Cloaking — they show your compliance team a different page

The most sophisticated of the four. Cloaking means serving one version of a page to monitoring tools, crawlers, and compliance checks, and a different version to real users. The affiliate's landing page detects whether the visitor looks like a checker (by IP range, by how the request is made, by behavior) and, if so, shows a clean, compliant, boring page with no affiliate redirect — while a real consumer from a real market gets the version that drops the cookie and harvests the sale. A compliance officer fetching the page from the corporate network sees Version A and signs off. The fraud is happening in Version B, which that officer will never be served.

mFilterIt's analysis (reported via Search Engine Land) found cloaking in 25% of affiliate fraud cases in 2022, rising to roughly 45% by 2024 — vendor data, so treat the exact figure as directional, but the trend direction matches what everyone in this space sees: cloaking is now common and getting more so. It's also the reason a brand can run a "URL check" tool, get a green light, and still be hemorrhaging commission — the tool checked the URL once, from one place, and got shown the clean version on purpose.

A fifth, layered on top: affiliates rotate accounts and disposable domains so that even when one ad or one publisher ID is caught and shut down, the operation continues under another — which is why a single takedown rarely ends it. (Catching the account behind the ad, not just the ad, is the whole point of pulling the publisher ID from the redirect chain.)


The math of why a manual check finds nothing

Put the four together and look at what you'd actually have to monitor to be sure. One affiliate, bidding across — say — 5 markets, 3 dayparts (business hours, evenings, overnight), and 2 device types, behind a cloak, is 30 distinct conditions under which the ad might or might not appear, before you even account for which exact keyword variant triggered it. A manual check covers one of those 30, from one IP, at one moment.

So the brutal arithmetic: if your detection is a marketing-ops person running a SERP check from the office once a week, your detection rate against a competent affiliate is, for practical purposes, zero. You will never see the ad that only shows to consumers in Bangkok on a Friday night. You will never see the one that only runs between 8pm and midnight on payday weekends. The affiliates know this — it's not a secret on their side — and they design around it. The check coming back clean is the expected outcome of a fraud that's working, not evidence that there's no fraud.

This is not an argument that you need a fancier tool. It's a structural point about where you look. One vantage point will always, eventually, be the vantage point the affiliate excluded. The only thing that beats systematic evasion is systematic looking: from the regions your customers are actually in (not your HQ), across the hours and devices the affiliate might target, arriving the way a real shopper does rather than as an obvious checker, and continuously rather than once a quarter. That's the entire reason AdCrime runs as a distributed scanner network across regions instead of a single script — and it's why the Playbook keeps insisting that geographic coverage, not cleverness, is what surfaces this fraud.


"It was just broad match" — telling deliberate from accidental

There's an honest complication, and a good affiliate will hide behind it: not every appearance of an affiliate on your brand term is intentional. Google's automation — Performance Max, broad match, close variants, auto-applied recommendations — can drag an affiliate's ad onto your brand query without them explicitly targeting it. So when you do catch one, you need to distinguish the deliberate bidder from the accidental one, because they get handled differently (and because "it was just broad match" is the first thing every caught affiliate says).

The signals that separate intent from accident (per The Search Monitor's detection guidance):

  • The keyword in the URL parameter. Affiliates often pass the triggering search into a {keyword} dynamic parameter in their tracking URL. If the entire searched phrase shows up, it may be an accidental broad-match catch. If only your brand name appears in the parameter, that's a strong sign they targeted it deliberately.
  • Bolded brand text in the ad. Google bolds ad text that matches the search query. If your brand name appears bolded in the affiliate's ad copy, the brand term was in their keyword list. Non-bolded brand mentions point more toward an incidental broad-match trigger.
  • Impression share. An affiliate showing on your brand term with a high impression share (the Search Monitor flags roughly 30%+) is almost certainly targeting it on purpose; a low, sporadic share is more consistent with automation spillover.
  • Remove the brand and watch them vanish. If you strip your brand name out of the query and the same affiliate stops appearing, your brand was the target — not the category.

None of this excuses the harm — even an "accidental" broad-match bidder is costing you CPC and commission until they fix their negatives. But it tells you whether you're sending a one-line "please add brand negatives" note or building an evidence package for termination. (The enforcement workflow covers what to do with each.)


Mario Vaher is the founder of AdCrime, which scans Google Ads across multiple regions for affiliates bidding on brands they aren't authorized to touch, resolves the redirect chain and publisher ID behind each one, and packages it as the evidence you'd file with the network. If you want to see what's bidding on your brand right now — from where it's actually running, not just from your desk — the first scan is free, or read the full, ungated Affiliate Brand-Bidding Fraud Playbook.

FAQ

Why can't I find affiliates bidding on my brand even though I suspect they are?

Because sophisticated affiliates configure their ads to hide from exactly the check you're running. They geo-target away from your office location, schedule ads for overnight/weekend hours (dayparting), target devices you don't check, and cloak their landing pages to show compliance checkers a clean version. A single manual SERP check from one place at one time is the one condition under which the ad reliably doesn't appear.

What is dayparting in affiliate fraud?

Dayparting is scheduling ads to run only at specific times — typically overnight, on weekends, or during holidays — when brand managers are least likely to be monitoring. It lets an affiliate bid on your brand terms while keeping the ads dark during normal business hours when you'd catch them.

What is affiliate cloaking?

Cloaking is showing different content to different visitors: a clean, compliant page to monitoring tools, crawlers, and compliance checks, and a different page (the one that drops the affiliate cookie and harvests the sale) to real users. It's why a brand can run a URL-checking tool, get a green light, and still be losing commission — the tool was served the clean version on purpose. Industry estimates put cloaking behind a large and rising share of affiliate fraud.

How do affiliates avoid getting caught bidding on a brand?

A combination: geo-targeting (excluding your region), dayparting (off-hours), device-targeting, cloaking (a clean page for checkers), targeting brand misspellings, and rotating accounts/domains so a single takedown doesn't end the operation. Each tactic defeats a different assumption a manual check relies on.

Was the affiliate bidding on my brand on purpose, or just broad match?

Check four signals: whether only your brand (vs. the full search phrase) appears in their tracking URL's keyword parameter; whether your brand name is bolded in their ad copy; whether their impression share on your brand term is high (~30%+); and whether they vanish when you remove the brand from the query. Deliberate bidders show the first three and disappear on the fourth.

Does a clean SERP check mean my program is safe?

No. Given geo-targeting, dayparting, device-targeting, and cloaking, a single clean check from one location is close to meaningless — it's the expected result of a fraud that's working as designed. Reliable detection requires looking from multiple regions, across times and devices, like a real user, continuously.

Next step

See what's bidding on your brand right now

Run a free scan, or read the ungated Playbook.