Intelligence · Legal / Newsjack

The PayPal Honey Lawsuit, Explained for Affiliate Managers: Last-Click Hijacking and What It Means for Your Program

By Mario Vaher·July 16, 2026·13 min read·Field report
Update — August 24, 2026. No new ruling since June 22, 2026, when Judge Freeman denied PayPal's motion to dismiss the Second Amended Complaint in full and sent all seven claims into discovery (Wendover Productions, LLC v. PayPal, Inc., No. 5:24-cv-09470, N.D. Cal., ECF 277). Two things have moved since. The separate consumer case — Campbell v. Honey Science, dismissed with prejudice by Judge Pitts in June — is now on appeal to the Ninth Circuit, with the plaintiffs' opening brief due October 5; it concerns privacy and coupon quality, not diverted commissions, so wins counted there don't touch the creator claims. The commercial side has also kept moving independently of the courtroom: third-party trackers put Honey's merchant roster down from roughly 35,000 to about 28,000 and its coupon database down from about 90,000 codes to roughly 50,000, while Rakuten reinstated the extension in May 2026 after Honey adopted Rakuten's open-source stand-down SDK. None of this is a finding of liability — the allegations remain allegations until a court says otherwise.

If you run an affiliate program, the PayPal Honey lawsuit is not a tech-celebrity story about YouTubers and a coupon plugin. It's a stress test of the one assumption your entire program runs on — that the affiliate who gets the commission is the one who actually drove the sale. Honey allegedly broke that assumption at scale, and in June 2026 a federal judge refused to throw the case out, clearing the creators who lost their commissions to take PayPal into discovery.

Here's the short version, and then the whole thing properly. A shopper clicks a creator's affiliate link, lands on the merchant, and the creator's tracking cookie is set — they're owed the commission. At checkout, the Honey browser extension allegedly fires a hidden redirect through PayPal's own affiliate ID, overwrites the creator's cookie, and claims the commission for itself — even when it found no coupon and handed the shopper nothing. The creator never sees it happen; their dashboard just shows an attribution that quietly vanished. In one documented test, the commission Honey captured was $35; the "reward" the shopper got back was $0.89.

I run AdCrime, which catches a different face of this same problem — affiliates hijacking brand searches in Google's paid results. Honey is the checkout-layer version; brand bidding is the paid-search version. I'll be clear about that line throughout, because the lesson generalizes even where the tooling doesn't. This is the case explained for the person whose job it is to pay the right partner.

I am a founder, not a lawyer. Everything below about the litigation is sourced to court reporting and primary filings, and every allegation is exactly that — an allegation in a case PayPal disputes and that has not been decided.

What Honey allegedly did

To see the alleged harm you have to understand one industry rule most people outside affiliate marketing have never heard of: the stand-down rule.

Affiliate commissions run on last-click attribution — whoever's affiliate link was clicked most recently before purchase gets paid. A browser extension has a structural superpower here: it can always make itself "last," because it activates at checkout, after every other referral has already happened. So since roughly 2002, networks have required software/extension affiliates to stand down — to suppress their own link when a prior publisher (a YouTuber, a blogger, a newsletter) already referred the customer. Without that rule, extensions would vacuum up commissions from the people who actually created the demand.

The complaint alleges Honey didn't stand down. Instead, when a shopper reached checkout, Honey would allegedly open a concealed browser tab — the filings call it a "Secret Tab" — and run the browser through a URL carrying PayPal's affiliate credential. The merchant logged that as a fresh, more-recent referral and overwrote the creator's cookie. Honey got credited. Crucially, the complaint alleges this happened even when Honey found no working coupon, offered no meaningful reward, or the user simply clicked "Got it" to dismiss the popup. The technical term for manufacturing a referral that didn't really happen is cookie stuffing.

Here's what that does to a creator, concretely. You publish an honest review with a NordVPN link paying ~$35 a sale. A viewer clicks it, lands on NordVPN, your cookie is set. They check out. Honey pops up. They dismiss it. Your cookie is gone, PayPal's is in its place, and when the sale completes you earn nothing — for a customer you sent. And you can't even see it: your affiliate dashboard doesn't show a theft, it just shows a referral that didn't convert. That invisibility is the whole reason it allegedly ran for years.

This wasn't a niche extension. Per the MegaLag investigation, Honey had sponsored roughly 5,000 YouTube videos across 1,000 channels, accumulating billions of views, to build a user base of around 20 million — including promotions from Linus Tech Tips, MrBeast, and MKBHD. Linus Media Group says it asked Honey to change the behavior, was refused, and terminated the partnership after some 160 sponsored segments.


The detail that turned it from "misunderstanding" into "Dieselgate"

PayPal's core defense is that Honey simply participated in last-click attribution like everyone else — that the creators misunderstand how affiliate tracking works. That defense ran into Ben Edelman.

Edelman — a Harvard-trained economist who has investigated affiliate fraud for twenty years and is independent of the litigation — reverse-engineered Honey's extension, sniffed its configuration files, and ran controlled experiments. In a December 2025 analysis titled "Honey's Dieselgate," he documented that Honey allegedly didn't just override cookies — it detected when it was being watched and behaved differently. From Honey's own config, he reported four tester-detection signals that would make Honey stand down properly:

  1. Account age under 30 days (testers use fresh accounts).
  2. Honey Gold points below a threshold — raised to ~65,000 points (≈$650) after the MegaLag video, high enough that an ordinary tester would never reach it.
  3. A server-side killswitch that could flag specific IPs, cookies, and account IDs — e.g. known complainers.
  4. A check for whether the user's browser carried login cookies for CJ, Rakuten, Awin, or Swagbucks — i.e., whether the user was an affiliate-industry professional.

On that last one, Edelman's verdict is the line worth quoting:

"It is inconceivable why a shopping plugin should care whether a user previously logged into an affiliate dashboard. There's only one reason to check: to hide from testers. But that reveals Honey's intent and Honey's knowledge that its conduct is prohibited."

And the framing that named the scandal:

"Designing its software to perform differently when under test, Honey follows in Volkswagen's 'Dieselgate' footsteps. Like Volkswagen, the cover-up is arguably worse than the underlying conduct."

If those findings hold up, they reframe the whole dispute. They also explain why so many networks didn't catch it for years — as Edelman put it, the best read isn't that the networks approved, it's that "Honey's concealment prevented them from figuring out what Honey was doing." (PayPal disputes the allegations; none of this has been adjudicated.)


Where the case stands (June 2026) — and why the dismissal matters

This is a live case, and the procedural history is genuinely instructive for anyone who manages affiliate attribution, so it's worth getting right.

  • Dec 2024 — After MegaLag's video (~18 million views by Edelman's later count), creators filed suit; 25-plus actions were consolidated into In re PayPal Honey Browser Extension Litigation, No. 5:24-cv-09470 (N.D. Cal.), before Judge Beth Labson Freeman.
  • Nov 7, 2025 — The court denied PayPal's bid to force arbitration, ruling its consumer user-agreement didn't cover affiliate marketers' business disputes. The case stays in federal court.
  • Nov 21, 2025 — Freeman dismissed the first amended complaint — but without prejudice. The reasoning is the part affiliate managers should sit with: she found the creators hadn't shown a concrete injury clearly traceable to PayPal, because the complaint didn't establish they "were in fact entitled to those commissions pursuant to their contracts with the merchants," and that lost commissions under last-click rules are "just as traceable to merchants." In plain terms: the law has not yet said a creator is entitled to a commission a last-click system reassigned. That ambiguity is the soft spot in every affiliate program's attribution model.
  • Jan 5, 2026 — Plaintiffs answered with a 101-page Second Amended Complaint: 11 named plaintiffs (down from 26), seven causes of action (CFAA, California's CDAFA, UCL, Washington's CPA, unjust enrichment, and two tortious-interference counts), and — critically — specific merchant affiliate agreements showing the exact commission terms Honey allegedly violated, plus the Edelman tester-detection findings.
  • June 4, 2026 — At the hearing on PayPal's motion to dismiss the new complaint, Freeman signaled it is likely to survive into discovery: "I don't think further amendment is going to be needed. I think these claims are either in or out at this point." She said she'd likely need "the summer to decide."
  • June 22, 2026 — motion to dismiss DENIED. Judge Freeman refused to dismiss the Second Amended Complaint, holding that the creators now plausibly allege Article III standing — the amended complaint "remedies both of the defects in the FAC previously identified by the Court" — and let all seven claims proceed (CFAA, California's CDAFA, the UCL, Washington's CPA, unjust enrichment, and two tortious-interference counts). She rejected PayPal's core defense that the lost commissions were just a feature of last-click attribution, crediting the specific merchant contract terms and the plaintiffs' test-purchase evidence. The case now heads into discovery — where Honey's internal communications and code become evidence.

One thing not to misread: in mid-June 2026, PayPal's lawyers publicized a "fourth victory" in the Honey litigation. That was a separate case — Campbell v. Honey Science, a consumer false-advertising suit by UK shoppers about whether Honey found the "best" deals — dismissed with prejudice on June 15. It is not the creator-commission case, which is not only alive but, as of June 22, 2026, headed into discovery after surviving PayPal's motion to dismiss. Don't let the headline tell you the influencer suit is over; it isn't.

PayPal's defense, for the record: it attributes the conduct to "legacy code" predating its 2019 acquisition of Honey, says it affected "less than 0.1% of Honey's traffic," and states it has deactivated it. Its communications VP framed it simply: "Honey follows industry rules and practices, including last-click attribution, which is widely used across major brands."


The industry reached its verdict faster than the court

Here's the part that should reset your sense of how fast enforcement can move when the evidence is undeniable — and how inconsistent it is. Long before the court ruled, the affiliate networks acted in a single month:

  • Rakuten Advertising — Jan 12, 2026: terminated Honey, cutting it off from ~2,000 merchants including Walmart. Internal Rakuten–PayPal emails reportedly flagged stand-down violations from 2020 to 2025.
  • Impact.com — Jan 16, 2026: suspended Honey from its marketplace after an investigation into its attribution practices and tester-concealment.
  • Awin — Jan 21, 2026: confirmed Honey breached its policies and suspended Honey's payments and access to new programs. CEO Adam Ross: "Transparency and trust matter, especially when our industry is under scrutiny." Honey agreed to a remediation plan — including giving networks access to relevant source code for verification.

Not everyone was satisfied that suspension equals justice. Consultant Benjamin Völk, replying to Awin's statement:

"What's being discussed here is not a grey area or a 'difference in interpretation', it is a credible allegation of fraud. Partners have been removed from platforms for far less in the past."

— with the unavoidable impression, he argued, "that compliance stops being uncompromising once enough money is involved." And the sequel proves his point: by May 2026, Rakuten reinstated Honey after it implemented Rakuten's new open-source, client-side stand-down SDK. Edelman's public response was that he'd expect Honey to "pay a substantial monetary penalty for the trouble they caused" before being treated as if nothing happened. The same month, Edelman and TopCashback's James Little published a draft industry Code of Conduct for extension affiliates — requiring stand-down logic to run entirely client-side and forbidding software from concealing itself from testers.

The takeaway for you isn't the gossip. It's that the network is a faster and more reliable enforcement venue than the courthouse — the same lesson that runs through brand-bidding enforcement, where a clean evidence package filed with the network beats a lawsuit you'll never file.


Google's "anti-Honey" rule, one year on

The platform layer moved too. On March 11, 2025, Google published a Chrome Web Store affiliate-ads policy — widely read as aimed squarely at Honey — with enforcement beginning June 10, 2025. It requires that any extension applying an affiliate link, code, or cookie must: disclose the affiliate program before install, act only on explicit user action, and deliver a direct benefit to the user at that moment. It explicitly bans appending or replacing an affiliate code in a URL, or updating a shopping cookie, "without the user's explicit knowledge or related user action" — a near-verbatim description of the conduct alleged against Honey.

One year on, the honest read is mixed. There's no public record of Google yanking a major named extension under the rule — Google rarely announces removals. But the norms clearly shifted: Honey altered its practices, Rakuten shipped a compliant client-side SDK, and the industry wrote the behavior into a Code of Conduct. The rule reshaped the floor even without a splashy execution. (And security researchers still find new extensions doing hidden affiliate hijacking — the policy raised the bar; it didn't end the game.)


The lesson for your program

Strip away the celebrity and the litigation and Honey is a clean illustration of the single structural weakness in affiliate marketing: last-click attribution rewards whoever is closest to the conversion, not whoever created it. A browser extension exploits that by sitting at checkout. A brand-bidding affiliate exploits the same weakness one layer up, by sitting on your brand name in Google's paid results and intercepting a customer who'd already decided to buy. Different surface, identical exploit — a party with no role in generating intent captures the credit by standing nearest the finish line. The plaintiffs' own complaint says it plainly: Honey "inserts itself as the last touchpoint during checkout, effectively erasing previous affiliate referrals."

So what should an affiliate manager actually do? The post-Honey industry guidance converges on a handful of moves:

  • Audit last-click anomalies at the coupon/extension tier. If a coupon or extension partner posts conversion rates dramatically higher than your content partners, that's the fingerprint of a partner capturing traffic that would have converted anyway. Investigate it.
  • Write stand-down and cookie-replacement into the contract — with explicit, mandatory termination clauses for cookie stuffing or attribution hijacking. (This is the same "Step 0" that makes brand-bidding enforcement possible: you can't act on what your terms don't prohibit.)
  • Move toward server-side / first-party attribution so a client-side extension can't quietly rewrite the record.
  • Diversify away from bottom-funnel-only partners. Over-reliance on coupon and extension players is a concentration risk the moment one of them faces a policy change — or a lawsuit.
  • Apply the same scrutiny to paid search. The extension face made headlines; the paid-search face is quieter and, in my experience, more common. Watch your brand terms.

That last point is the one I work on. AdCrime doesn't police browser extensions — that's a different detection problem that shows up in your attribution data, not on the search page. What we catch is the paid-search version: affiliates bidding on your brand, intercepting the click, and claiming a commission on a customer who was already yours. Same root, same fix — knowing who actually drove the sale versus who just stood closest to it.


Mario Vaher is the founder of AdCrime, which scans Google Ads across multiple regions for affiliates bidding on brands they aren't authorized to touch, resolves the redirect chain and publisher ID behind each one, and packages it as filable evidence — for the paid-search face of attribution theft. If you want to see what's bidding on your brand right now, the first scan is free — or read the full, ungated Affiliate Brand-Bidding Fraud Playbook.

FAQ

What is the PayPal Honey lawsuit about?

Content creators allege that the Honey browser extension (owned by PayPal) overwrote their affiliate tracking cookies at checkout — firing PayPal's own affiliate ID through a hidden redirect — to claim commissions on sales the creators had referred, even when Honey provided no coupon or reward. The consolidated case is *In re PayPal Honey Browser Extension Litigation*, No. 5:24-cv-09470 (N.D. Cal.). PayPal disputes the allegations.

Did Honey actually steal affiliate commissions?

That's what the lawsuit alleges and what investigations by MegaLag and researcher Ben Edelman documented — including, per Edelman, that Honey detected compliance testers and behaved differently when watched. PayPal denies wrongdoing, attributing the conduct to "legacy code" affecting "less than 0.1%" of traffic. The case has not been decided; these remain allegations.

Is the Honey lawsuit still going in 2026?

Yes — and it just cleared a major hurdle. On June 22, 2026, Judge Beth Labson Freeman denied PayPal's motion to dismiss the Second Amended Complaint, finding the creators plausibly alleged standing and letting all seven claims proceed into discovery. (A separate consumer false-advertising case, Campbell v. Honey Science, was dismissed with prejudice on June 15, 2026 — that one is not the creator case.)

What is last-click hijacking?

Affiliate commissions go to whoever's link was clicked most recently before purchase ("last-click attribution"). Last-click hijacking is when a party — a browser extension at checkout, or a brand-bidding affiliate in paid search — inserts itself as that final touchpoint to claim the commission, despite playing no role in the customer's decision to buy.

Did affiliate networks drop Honey?

Yes — quickly. Rakuten Advertising terminated Honey on Jan 12, 2026; Impact.com suspended it on Jan 16; Awin confirmed policy breaches and suspended payments on Jan 21. Rakuten later reinstated Honey (May 2026) after it adopted a new client-side stand-down SDK.

How does the Honey case affect my affiliate program?

It's a warning about last-click attribution generally. Audit coupon/extension partners for anomalous conversion rates, write explicit stand-down and anti-cookie-stuffing terms into your contracts, consider server-side attribution, diversify your partner mix, and apply the same scrutiny to paid-search brand bidding — the quieter version of the same exploit.

Next step

See what's bidding on your brand right now

Run a free scan, or read the ungated Playbook.