Intelligence · Data & Research

The State of Affiliate Brand-Bidding 2026: September Edition

71,858 paid ads on brand-name searches in 16 markets, February to September 2026, followed to where they landed. 42.8% were an affiliate intercepting a customer who had already chosen the brand.

By Mario Vaher·September 5, 2026·16 min read·Field report
Correction, 30 September 2026. The first version of this report said one Awin publisher account was caught on 314 brands across 723 captures over 159 days. That count included the account's links to other advertisers on the same coupon pages. Counting only captures where the click runs through the account's own Awin link and lands on the advertiser whose brand was searched, it is 93 advertiser programs (95 brands) in 246 captures between 25 July and 31 August, and the account was seen again on 27 September. We also removed an Impact figure (107 brands in 26 days) that rested on a value that is not a real publisher account, and withdrew two figures that counted IDs found anywhere in a capture (the account-level recurrence counts, and the share of confirmed cases carrying a static publisher ID) until they are re-derived on the same basis. The Awin confirmed-grade figure now comes from the recorded click path (90.5%, previously 92.5%), the network table now says what it counts, and screenshot coverage is now stated exactly. The classification, domain-level and market figures are unchanged.

Executive summary

Between 19 February and 4 September 2026 we captured 71,858 paid Google ads that appeared on the search terms of 4,917 brands across 16 markets, and followed every one of them from the click to the page it landed on. 30,757 of them, 42.8%, were affiliate brand-bidding: an affiliate ran an ad on a brand's own name, caught a customer who had already decided where to buy, and routed the click through affiliate tracking so that the sale would be commissioned to them. 19,132 met the hardest evidence standard, meaning the captured chain carried the attribution itself: a static publisher account ID, an offer ID, the brand's own affiliate link, or the brand's coupon codes.

The majority of examined ads, 57.2%, were not called fraud. Competitor ads were cleared as competitor ads, Shopping listings as Shopping listings, thin cases as unknown. The 42.8% is what survives a process built to say no.

Five findings:

  1. It is an industry of repeat operators. 91.7% of interceptions came from offender domains caught on two or more brands, 79.4% from domains caught on five or more. One Awin publisher account, running four coupon sites, was traced through its own Awin link to 93 different advertiser programs in five weeks.
  2. It is concentrated. 2,106 offender domains produced the 30,757 interceptions. The top 1% of them, 22 domains, produced 29.6% of the volume; the top 10% produced 71.7%. All ten of the largest were still running in the last two weeks of the window.
  3. Awin and Impact are where the identifiable action is. Of the interceptions whose evidence named a network, 41% named Awin and 29% Impact. Where the recorded click path ran through Awin's own tracking, 90.5% of cases reached confirmed grade, because Awin's URL carries the publisher account in plain sight. A third of offenders with a recognised network were caught on two or more networks.
  4. More than a third of the interceptions had no named network behind them. 37.6% ran through in-house programs, SaaS-native referral platforms, or tracking we could not attribute. For most of those brands there is no compliance desk to file with; the brand is the entire enforcement apparatus.
  5. Coupon sites are the shape of it. A third of offender domains carry coupon, code, deal, promo or voucher in their name, and that third produced 60% of the interceptions. More than half of confirmed interceptions had the brand's own coupon codes on the page the click landed on.

Methodology and honest caveats

Credibility is the point of a report like this, so the limits come first.

What the corpus is. Every figure here comes from AdCrime's own detection database: 71,858 paid ads observed on the branded search terms of 4,917 brand domains between 2026-02-19 and 2026-09-04, across the 16 markets we cover (a few dozen rows come from three markets we retired in July). Each record contains the ad as served, the redirect chain we recorded behind it, the tracking parameters carried in that chain, a screenshot of the landing page (90% of interceptions) and, for about a quarter of interceptions, a screenshot of the search results page.

What a "detection" is. One ad, on one branded query, in one market, at one point in time, that intercepted the click and routed it through affiliate monetization. The same operator on ten days, or in three markets, counts ten or three times. Ad-level counting is the honest unit for exposure, because each occurrence is a separate set of intercepted clicks, but detection counts are not counts of unique offenders. Unique-offender figures are reported separately.

What "confirmed" and "likely" mean. A detection is confirmed only when the captured evidence contains hard attribution: a static publisher account ID read off a network's tracking domain, an offer or campaign ID, the brand's own affiliate link inside the chain, or the brand's coupon codes on the landing page. Likely means the monetization signals are there (multi-hop tracking redirects, affiliate-network infrastructure, coupon-site behaviour) but the chain did not yield hard attribution. Everything else is classified against the fraud hypothesis.

The full classification of all 71,858 ads:

ClassificationCountShare
Confirmed affiliate interception19,13226.6%
Likely affiliate interception11,62516.2%
Competitor ad (cleared)32,38045.1%
Unknown (insufficient evidence)6,7339.4%
Google Shopping / CSS (cleared)9601.3%
Evidence capture failed or legacy9701.3%
No fraud found580.1%
Total71,858100%

This is not a census. Three selection effects shape every number:

  • The brands were chosen, not sampled. We scan programs where interception is economically attractive, and since July a large share of the corpus came from brands we picked because a coupon site was already listing them. The finding that 71.9% of scanned brands had at least one interception describes what targeted examination finds. It is not a market base rate. For a neutral base rate, BforeAI's 2025 study of roughly 33,000 ads across 605 brands on Google US found 6.9% of branded-query ads were unauthorised affiliate brand-bidding and 31% of brands were affected.
  • The keywords are purchase-intent modifiers by design. The scanned queries are the terms customers type at the moment of buying: "brand coupon", "brand promo code", "brand discount". More than 99% of the corpus is one of those three families. The brand name alone was barely scanned, so this report says nothing about navigational queries.
  • Markets are weighted by where we scanned, not by size. The United Kingdom, the United States and Germany carry 84% of the corpus. Treat every geographic figure as coverage-weighted.

One more caveat, on concentration. Offender rankings here count domains. We know from reading Google's own advertiser disclosures that one advertiser account can front twenty differently named coupon domains. Every concentration figure in this report is therefore an understatement; the real number of operators is smaller than the number of domains.

Where this report cites third-party research, it is marked and linked. Everything else is AdCrime primary data.


The scale of interception

Of 4,917 brands scanned, 3,535 (71.9%) had at least one interception on their terms, and 2,278 (46.3%) had at least one confirmed case. The median brand with an interception had two distinct offenders on it, across two markets. 705 brands had five or more offenders; 126 had ten or more.

What 71,858 ads on brand-name searches turned out to be
What 71,858 ads on brand-name searches turned out to be

The interception rate sat between 40% and 44% in the three months that carry 95% of the corpus (March 42.2%, July 40.3%, August 43.3%), which is the most useful thing the monthly series says: as the corpus grew from a hundred hand-picked brands to over four thousand, the share of purchase-intent ads that turned out to be affiliates did not move. April's 60.1% is twenty brands chosen because they were already known to be hit.

MonthAds examinedInterceptionsRateBrands
March3,5531,49842.2%95
April1,46588160.1%20
July13,0275,25140.3%514
August51,76022,40743.3%4,382

(February 204 ads / 43 interceptions, May 161 / 86 and June 695 / 570 are too small to read a rate from and are omitted.)


Which networks the interceptions named

About 13,000 of the 30,757 interceptions named a recognised affiliate network in their evidence. The rest ran through in-house programs, SaaS-native referral platforms, or tracking hosts we could not attribute to a network; 37.6% named no network at all.

Which networks the interceptions named
Which networks the interceptions named
NetworkInterceptionsConfirmed rateDistinct offendersBrands affected
Awin5,37284.0%3491,134
Impact3,76081.4%409835
Rakuten78593.2%121233
PartnerStack58993.9%4143
CJ48853.3%75208
ShareASale25494.9%3080
Webgains24776.9%7282
TradeDoubler23375.5%6668
PaidOnResults20475.5%1941
Partnerize13942.4%4444
Admitad6377.8%1019
Adtraction4395.3%37

How to read this table. The network is the one named in each interception's evidence: the tracking in the recorded click path where the click was followed through, otherwise the tracking links on the page the ad landed on. On coupon pages that list many advertisers, a link on the page can belong to another advertiser, so treat these counts as upper bounds. Counting only interceptions whose recorded click path passes through Awin's own tracking gives 1,265 for Awin, a lower bound. The account-level figures in this report use that stricter click-path rule.

Three things in that table matter for anyone who has to file a complaint.

Awin's share fell from 72% to 41% since July, and that is a coverage story, not an Awin story. The July corpus was European retail and VPN; since then the scanning broadened into North American ecommerce and SaaS, where Impact and PartnerStack carry the programs. Impact's share of named-network interceptions is now 29%.

The confirmed rate is a property of the network's link format. Awin (84%), Rakuten (93%), PartnerStack (94%) and ShareASale (95%) put the publisher account in the URL, so a captured chain names the account. CJ (53%) and Partnerize (42%) sit lower because their chains more often hand back a per-click token rather than the static ID, and a per-click token is not something a network can act on. Where the recorded click path passed through Awin's own tracking domain (1,265 interceptions), 90.5% reached confirmed grade.

Operators are network-agnostic. Of the 788 offender domains caught on a recognised network, 242 (30.7%) were caught on two or more networks. Suspending an account on one network moves the traffic, it does not stop it.


Offender concentration and recurrence

A small number of operators do most of the intercepting
A small number of operators do most of the intercepting

2,106 distinct offender domains produced the 30,757 interceptions. The distribution is steep: the top 1% of domains (22 of them) produced 29.6% of interceptions, the top 10% produced 71.7%, and 701 domains (33%) were caught exactly once. The 25 largest offenders were caught on a median of 84 brands each, and 13 of them in every one of the 16 markets.

All ten of the largest offenders were still running ads in the final two weeks of the window. Their median active span in the corpus is 159 days. Among the 482 domains with ten or more detections, the median span between first and last capture is 35 days, which is what a coupon site looks like when it moves between programs as accounts get suspended.

Nine in ten interceptions come from repeat offenders
Nine in ten interceptions come from repeat offenders

Seen from the other side, 952 offender domains (45%) were caught on two or more brands, 219 on ten or more, and those repeat domains produced 91.7% of all interceptions. At the publisher-account level, the clearest case is one Awin publisher account running four coupon sites. Counting only captures where the click from the ad's landing page runs through that account's own Awin link and lands on the advertiser whose brand was searched, it reached 93 advertiser programs (95 brands) in 246 captures between 25 July and 31 August, and it was seen again on 27 September. Whether each advertiser's terms allow it is for that advertiser and the network to judge. Account-level counts across all publisher IDs are being re-derived on the same basis.

For an affiliate manager the practical consequence is this: when a publisher appears on your terms, the probability that it is a one-off is small, and the probability that a network has already seen the same account on other advertisers is high. A complaint that says "this account, on our program, and on dozens of others" is a different instrument from a complaint that says "this account, on our program".


What the offenders look like

Coupon sites, by name and by behaviour. 686 of the 2,106 offender domains (32.6%) carry coupon, code, deal, promo, voucher, discount, save or cashback in the domain name, and those domains produced 60.1% of the interceptions. 53.5% of confirmed interceptions landed on a page that carried the brand's own coupon codes: the affiliate had the brand's discount and was buying the brand's customer with it.

Geo split is real but rare. 69 of the 1,100 confirmed offender domains (6.3%) served the affiliate route to some markets and a clean page to others. Rare, but it is exactly the pattern that makes a brand's own check from its home market come back clean.

Every offender with a network label also tells you which link format it prefers. Chains on Awin, Rakuten, PartnerStack and ShareASale gave up the account nine times in ten. That is why the case files for those networks are the easiest to file and the fastest to get reversed.


The geographic picture

Interception rate by market
Interception rate by market
MarketAds examinedInterceptionsRateBrands scanned
United Kingdom23,0499,13639.6%3,702
United States21,91510,36947.3%3,994
Germany14,9195,47436.7%3,048
13 other markets pooled10,9965,77152.5%

Read the pooled row carefully. The smaller markets were scanned mostly for brands where we already had a confirmed case in a big market and went looking for the same offender elsewhere, so their rate is inflated by selection, not by geography. The defensible claim is narrower and more useful: in every market with more than a thousand examined ads, between 37% and 52% of purchase-intent brand ads were affiliates, and 96% of the interceptions in the smaller markets came from domains also caught in the United Kingdom, the United States or Germany. Offenders geo-target; a brand that checks only from its home market sees a fraction of what runs on its name.


The keyword picture

The corpus is built on the three modifier families customers type when they are ready to buy, and the interception rate is nearly flat across them: coupon and voucher terms 45.9% (23,992 ads), promo terms 43.5% (23,902), discount and deal terms 40.9% (22,732). There is no safe modifier. The brand name alone was scanned too rarely to report (53 ads), which is a deliberate limit of this corpus rather than a finding.


What this means for brands

Assume recurrence, not accident. Nine in ten interceptions come from operators who do it across many brands. Treat the first case on your terms as the first sighting of a professional, not a misunderstanding by a partner.

Get the account, not the click. Networks act on the static publisher ID (awinaffid on Awin, the PID on CJ, the u value on ShareASale, the first number in an Impact pxf.io or sjv.io path). Per-click tokens like awc, cjevent and irclickid change on every click and identify nothing after the fact.

File inside the window. The recovery window is the whole game. CJ's standard lock is the 10th of the month following the transaction, with a 72-hour published SLA on correction files. Awin Access validates automatically after up to 67 days, after which paid commissions cannot be reversed under any circumstances. PartnerStack reviews invoices from the 1st to the 7th and offsets rather than refunds after payment. Impact locks per contract. Rakuten, Admitad, Partnerize, TradeDoubler and Webgains do not publish a window, so the only safe assumption is the shortest one.

If you run an in-house or SaaS-native program, you are the network. For most of the 37.6% of interceptions that resolved to no named network, there is no compliance desk to file with. That is not a worse position; it is a faster one. Reverse the commission, remove the affiliate, and put the brand-term clause in the terms you control.

Check the markets you pay out in, not the one you sit in. Thirteen of the 25 largest offenders were caught in every one of the 16 markets we cover.


A forward look

The August corpus is 51,760 ads on 4,382 brands, and the interception rate in it (43.3%) is within a point of the March rate (42.2%) on a corpus one fourteenth the size. If the share of affiliate interception on purchase-intent brand terms is stable across a widening set of brands, the arithmetic for any program is simple: the exposure is proportional to how many purchase-intent searches your brand gets, and the remedy is proportional to how fast you can name the account and file. The next edition of this report will add the one number nobody in the category publishes: commissions actually reversed per case filed, and median days from capture to filing against days to window close.


How we know

Source. Every primary figure comes from AdCrime's production detection database: 71,858 paid ads observed on the branded search terms of 4,917 brand domains across 16 markets between 2026-02-19 and 2026-09-04. Each detection record contains the ad as served, the redirect chain we recorded behind it, the tracking parameters carried in that chain, the resolved network and account identifiers where present, captured coupon codes, a screenshot of the landing page for most records, and a screenshot of the search results page for about a quarter of interceptions.

Standard. Detections are classified against the fraud hypothesis. Confirmed requires hard attribution captured in the chain or on the landing page; likely means monetization signals without hard attribution; competitor ads and Shopping listings are affirmatively cleared; insufficient evidence is labelled unknown. 57.2% of the corpus was not classified as fraud.

Limits. The corpus is AdCrime's own scanning footprint, not a random sample. Brands were selected for exposure, markets are unevenly covered, keywords are purchase-intent modifiers. Detection counts are ad-level, not unique-offender counts. Offender rankings count domains, and one operator can run many, so concentration is understated. Third-party statistics are attributed and linked where used and are the only figures not drawn from AdCrime's corpus.

Withheld. Publisher account IDs, offender domain identities, and the identities of affected brands are deliberately not published. They exist in the evidence records and are provided privately to the brands whose programs they concern.

All AdCrime figures in this report are as of 2026-09-04, except those the appendix marks as recomputed on 2026-09-30 for the correction at the top. The July edition (8,599 ads, 108 brands, 14 markets) remains available for comparison.


Appendix: every figure and the query behind it

All queries run against fraud_reports (one row per captured ad) on 2026-09-04, except rows marked recomputed 2026-09-30, which were re-run for the correction at the top of this report. "Interception" means classification in ('CONFIRMED_AFFILIATE_FRAUD','LIKELY_AFFILIATE_FRAUD').

FigureQuery (abbreviated)
71,858 ads; 4,917 brands; windowselect count(*), count(distinct official_domain), min(detected_at), max(detected_at) from fraud_reports
Classification tableselect classification, count(*) from fraud_reports group by 1
3,535 brands with an interception; 2,278 with a confirmedcount(distinct official_domain) filter (where <interception>) and filter (where classification='CONFIRMED_AFFILIATE_FRAUD')
Median 2 offenders and 2 markets per hit brand; 705 with 5+; 126 with 10+per official_domain: count(distinct lower(fraud_domain)), count(distinct region) over interceptions
Monthly tableto_char(detected_at,'YYYY-MM'), rows with classification not in ('EVIDENCE_CAPTURE_FAILED','LEGACY_UNCLASSIFIED')
Network tableinterceptions grouped by affiliate_network, the network named in the capture's evidence (upper bound, see the note under the table); confirmed rate = confirmed / interceptions; offenders = count(distinct lower(fraud_domain)); brands = count(distinct official_domain)
~13,000 named-network interceptions; 37.6% unnamedsum of interceptions whose affiliate_network is a recognised network label (excluding Self-hosted, Unattributed, Generic, blank); unnamed = 11,552 / 30,757
90.5% confirmed where the recorded click path ran through Awin (recomputed 2026-09-30)interceptions whose redirect_chain has a hop on an Awin click host (awin1.com click URLs, zenaps.com, tidd.ly and Awin's other click hosts) or an Awin click reference (awc=): 1,145 confirmed of 1,265
242 of 788 offenders on 2+ networksper lower(fraud_domain): count(distinct affiliate_network) over the twelve recognised networks
2,106 offender domains; top 1% = 29.6%; top 10% = 71.7%; top 25 = 31.7%; 701 single-hitinterceptions per lower(fraud_domain), ranked; cumulative share
Top 10 all active in last 14 days; median span 159 days; top 25 median 84 brands, 16 marketsper domain min/max(detected_at), count(distinct official_domain), count(distinct region)
952 domains on 2+ brands; 219 on 10+; 91.7% and 79.4% of interceptionsper domain count(distinct official_domain); share of interceptions from domains with brands >= 2 and >= 5
482 domains with 10+ hits, median span 35 daysper domain, n >= 10, percentile_cont(0.5) of (max - min) detected_at
Account-level recurrence counts (withdrawn 2026-09-30)were read from publisher_threat_intel, which counts an ID wherever it appears in a capture, including other advertisers' links on the same page; being re-derived on the click-path basis
One Awin account: 93 advertiser programs, 95 brands, 246 captures, 25 Jul to 31 Aug, four coupon sites (recomputed 2026-09-30)captures whose redirect_chain contains that account's Awin click (an awin1.com click URL carrying its publisher ID) followed by a hop on the searched brand's own site; programs = distinct Awin advertiser IDs (mid) in that click; identity withheld
686 coupon-named domains (32.6%) producing 60.1%domain name ~* '(coupon|kupon|cupon|code|deal|promo|voucher|discount|rabatt|gutschein|sconto|save|offer|sale|cashback)'
53.5% of confirmed with coupon codesjsonb_array_length(coupon_codes) > 0 over confirmed rows: 10,235 / 19,132
Share of confirmed with a static publisher ID (withdrawn 2026-09-30)the published 65.7% counted an ID read from any link in the capture, including other advertisers' links; being re-derived on the click-path basis
69 of 1,100 confirmed offender domains geo split (6.3%)count(distinct lower(fraud_domain)) filter (where geo_split) over confirmed rows
Market tableinterceptions and ads per region, capture-failed and legacy rows excluded; pooled row = the 13 markets outside uk, us, de
Modifier rateskeyword matched against coupon/voucher, promo, discount/deal families; brand-alone = 53 rows
Recovery windowsnetwork-published policy as collected in AdCrime's enforcement research, August 2026 (CJ, Awin, PartnerStack, Impact); others not published

FAQ

What share of branded-search ads are affiliate brand-bidding?

In AdCrime's corpus of 71,858 paid ads captured on the search terms of 4,917 brands across 16 markets between February and September 2026, 42.8% were affiliate brand-bidding: an affiliate running an ad on a brand's own name and routing the intercepted click through affiliate tracking. The corpus is skewed toward brands that suspected a problem and toward purchase-intent terms like "brand coupon", so treat the figure as a ceiling. BforeAI's neutral 2025 sample of Google US found 6.9% of branded-query ads were unauthorised affiliate brand-bidding and 31% of brands were affected.

Are these one-off partners or repeat operators?

Repeat operators. 91.7% of the interceptions came from offender domains caught on two or more brands, and 79.4% from domains caught on five or more. The largest single publisher account we traced, on Awin, reached 93 advertiser programs between late July and the end of August, counting only clicks through its own Awin link to the advertiser whose brand was searched. All ten of the largest offender domains were still running ads in the last two weeks of the window.

How concentrated are the offenders?

2,106 distinct offender domains produced the 30,757 interceptions. The top 1% of them, 22 domains, produced 29.6% of the volume, and the top 10% produced 71.7%. Because one operator often runs several coupon domains, every concentration figure in the report is an understatement.

Which affiliate networks show the most brand-bidding?

Of the interceptions whose evidence named a network, 41% named Awin and 29% Impact; these are upper bounds, because on coupon pages that list many advertisers a link can belong to another advertiser. Whether a case can be acted on depends on the network's link format: where the recorded click path passed through Awin's tracking, 90.5% of cases reached confirmed grade because the URL carries the publisher account; captures naming Rakuten, PartnerStack or ShareASale confirmed at 93% to 95%, CJ at 53%. 37.6% of interceptions named no network at all, which usually means an in-house or SaaS-native program where the brand is its own compliance desk.

Is affiliate brand-bidding mainly a US problem?

No. In every market with more than a thousand examined ads the interception rate sat between 37% and 52%, and 96% of the interceptions in the smaller markets came from domains also caught in the United Kingdom, the United States or Germany. Offenders geo-target, so a brand checking Google only from its home market sees a fraction of what runs on its name.

Next step

See what's bidding on your brand right now

Run a free scan, or read the ungated Playbook.