Search your own VPN brand name plus "coupon" right now, from a clean browser. Look at what sits above your own listing: the deal aggregators, the "verified 2026 promo code" pages, the YouTube discount-code channels uploading three videos a week. Most of them are not doing you a favor.
A large share of them are intercepting customers who already typed your brand name into Google, dropping an affiliate cookie on the way through, and billing your program a commission on a sale you had already won. The discount they show is usually real — that's not the fraud. The fraud is who gets paid for a decision the customer already made.
VPN affiliate fraud is when an affiliate bids on a VPN brand's own name in Google Ads, intercepts a customer who had already chosen that brand, and collects a commission — typically 40–100% of the first payment — on a sale the brand had already won.
The short version
- Every major VPN program bans brand bidding in writing. The gap between the ban and the enforcement is where the fraud lives.
- One intercepted "nordvpn coupon" click on the 2-year plan is worth $37.69 to the affiliate — 40% of the $94.23 the customer pays.
- The brand pays twice: once to Google, to keep its own listing above the affiliate's ad on its own name; once to the affiliate, in commission.
- One documented operation ran more than 1,000 subdomains behind a single affiliate ID. The takedown unit is the affiliate ID, not the domain.
- The links are cloaked and geo-targeted, so a single-region, business-hours SERP check is structurally blind to this.
Across the programs I've looked at, this is the single most expensive, most under-policed leak in the VPN growth stack. I run AdCrime — a scanner network that searches brand keywords across regions, catches the unauthorized ads, and pulls the affiliate publisher ID out of the redirect chain. I have watched this pattern run against every major VPN brand I've scanned, in multiple countries, for a long time. This is the playbook for understanding it and shutting it down.
One thing up front, because I sell a product in this space: every detection method below can be run by hand with a browser and patience. If you'd rather not, you know where to find me. Either way, the goal is the same.
Why VPN is the highest-value target in affiliate fraud
Fraud follows margin. VPN has the best margins in consumer software, and it pays them straight back out to affiliates. Look at what a single conversion is worth to the person who intercepts it. Rates below come from the brands' own affiliate pages where published, supplemented by network listings, July 2026:
| Program | New-sale commission | Recurring | Networks |
|---|---|---|---|
| NordVPN | 100% (1-month) / 40% (1–2 year) | 30% | In-house program on TUNE (go.nordvpn.net) + Impact (nordvpn.sjv.io) + CJ |
| ExpressVPN | Flat CPA from $13 / $22 / $36 (1-month / 6-month / 12-month and longer) | none — CPA only | Impact |
| Surfshark | from 40% of new sales | not paid by default | TUNE (primary) + Impact + CJ + Awin |
| CyberGhost | up to 100% (1-month) | not published | Kape / HasOffers |
| Proton VPN | up to 100% | paid on renewals, rate not published | In-house program + CJ + Webgains |
Three caveats, because published rates flatter themselves. They are floors, not ceilings — ExpressVPN says outright that the rate rises with volume, and most programs set the real number per affiliate in an insertion order. "Up to 100%" is a first-payment hook that applies only to the cheapest monthly plan, the lowest-lifetime-value product in the catalogue, so it overstates typical earnings when it sits in a column beside annual rates. And "not published" means the brand doesn't state it, not that the answer is zero — with one documented exception: Surfshark's affiliate terms say it will not pay for recurring sales unless specifically agreed otherwise.
Now the math on one stolen click. A user searches "nordvpn coupon," clicks a coupon site instead of NordVPN's own result, and buys the 2-year Basic plan — $94.23 billed upfront ($3.49/month × 27 months, as listed on nordvpn.com for US customers in July 2026, before tax). At NordVPN's published 40% new-sale rate on the 1–2 year plans, the affiliate earns $37.69 for that single interception. The customer was already at the door with their wallet out. The affiliate just stepped in front of the till.
Date-stamp any number like that before you quote it internally. VPN pricing is promotional and geo-dependent, and a figure with no date on it will be wrong within a quarter.
For a cross-industry baseline: BforeAI's March 2025 study of branded-query advertising found that 6.9% of ads served on brand terms were affiliate brand bidding, and that 31% of the 605 brands studied were targeted at least once. That is the average across all verticals. Nothing in the commission table above suggests VPN sits below the average.
Here is the part that makes it worse than it first looks. When a fraudster bids on your brand term, you don't pay once — you pay twice:
- Once to Google, because to keep your own listing above an affiliate's ad on your own brand name, you raise your branded-search bids and your CPC climbs.
- Once to the affiliate, in commission, on the conversion they intercepted.
So the brand pays to defend its own name, and then pays again to the person it was defending against. That is the structural reason this fraud is so profitable and so persistent. It is not proportional to your affiliate budget — it is proportional to how much of your organic and branded demand a fraudster can wedge themselves into.
The cheapest customer in the world to "acquire" is the one who already searched your name. That is exactly the customer a brand-bidding affiliate sells back to you.
Legitimate VPN affiliate vs. brand-bidding fraud: what's the difference?
Here's the honest version, because the difference is the whole game and most coverage blurs it.
| Legitimate affiliate | Brand-bidding affiliate | |
|---|---|---|
| What the user searched | best vpn, vpn for streaming — category intent | nordvpn, surfshark coupon — your brand, already chosen |
| What the affiliate did | Created the demand, or genuinely informed the decision | Inserted a redirect into a decision already made |
| Is the sale incremental? | Yes — it would not have happened otherwise | No — it was going to close at your own checkout, for free |
| What the commission buys | A customer you didn't have | A customer you already had |
| Program status | Encouraged | Prohibited |
A reviewer who writes an honest "best VPN for streaming" piece, gets found by someone searching "best vpn", and sends them through has earned the commission. Pay them gladly.
A brand-bidding affiliate creates nothing. The user searched "nordvpn" — they had already chosen. The affiliate bid on that branded intent, inserted a redirect, and captured the credit. This is also the answer to the skeptical question consumers keep asking: why is Surfshark so cheap, and what's the catch? The discount is real. The catch is that the site showing it to you is often billing the brand a full commission for a decision you had already made, which is part of why the brand can't make the discounts any deeper.
That distinction — incremental vs. non-incremental — is the line between a partner and a parasite. Everything below is about finding the parasites without punishing the partners.
The five VPN affiliate fraud patterns
The general fraud patterns show up with a specifically VPN flavor:
Pattern 1 — Coupon-term brand bidding. The bread and butter. The affiliate bids on [brand] coupon, [brand] discount, [brand] deal, [brand] promo code. The user is in late-funnel, code-hunting mode — the highest-converting moment there is — and the affiliate owns the ad slot above your listing. VPN is the perfect host for this because "search for a code before checkout" is near-universal behavior for a subscription purchase.
Pattern 2 — The creator-code echo. VPN is the most influencer-saturated category in software; every podcast has a code. Fraud sites scrape those creator codes (or the auto-applied ones) and rank pages like "NordVPN code — [creator] 2026," intercepting the searcher who half-remembers a code from a video. The credit that should go to the creator who actually drove the awareness gets siphoned by a page that did nothing. This is last-click hijacking wearing a VPN costume — the same mechanism at the centre of the PayPal Honey lawsuit.
Pattern 3 — Typosquatting and lookalike domains. Adjacent to affiliate fraud rather than identical to it, but the same brand-abuse ecosystem. A February 2026 TechRadar investigation (written by Chiara Castro, research by Mike Williams) identified over 980 registered lookalike domains across five VPN brands and screened them through NordVPN's Threat Protection Pro, which flagged roughly 14% as containing active threats — 24% for Surfshark, 29.1% for Proton VPN. Many of the rest were parked or inactive. Read those per-brand figures with the caveat they deserve: the scoring tool is NordVPN's own product, and NordVPN itself ranked second-lowest at 8.2%. ExpressVPN, for its part, had already defensively registered at least 22 misspelled domains. Most lookalikes distribute malware or harvest data; some bounce through an affiliate tag on the way to the real checkout. Either way, your brand is the bait.
Pattern 4 — Subdomain farms at industrial scale. This is where it stops being a nuisance and becomes an operation. See the case below.
Pattern 5 — Cloaking. The one that makes everything above nearly invisible to a normal compliance check. Also below, because it's the most important and the least understood.
The anchor case: how one affiliate ID ran 1,000+ NordVPN front doors
In March 2025, the threat-intelligence firm QuoIntelligence published the most detailed public autopsy of a VPN affiliate-fraud operation we have. It is worth knowing in detail, because it shows the shape of the thing.
The investigators traced a single coordinated campaign promoting NordVPN (and the iGaming brand Casinia) through AI-generated content seeded across fake LinkedIn, Medium, Tumblr, WordPress, and Facebook accounts. The numbers:
- At least seven primary domains and over 1,000 subdomains funnelling traffic to affiliate offers.
- 500+ fake social accounts, posting in multiple languages including English, Spanish, Italian, Greek, German, Portuguese, Polish and Lithuanian.
- A posting schedule timed to NordVPN's own seasonal marketing calendar — Black Friday, Cyber Monday, Christmas, Easter, student deals — so the fraud spiked exactly when the brand's real campaigns did.
And the detail that ties it in a bow — the affiliate IDs. In QuoIntelligence's own words:
"All Casinia redirection links embed affiliate ID 82813, while NordVPN promotions consistently use affiliate ID 103411 in redirection links and final URLs, indicating a structured tracking system."
One affiliate ID — 103411 — operating a thousand-plus front doors. That is the number that matters, and it's the number that gets a publisher terminated. (If you want the mechanics of how an ID like that is pulled out of a redirect chain, that's its own piece: how to read an affiliate redirect chain.)
Block one subdomain and 999 are still live. The takedown unit isn't the domain. It's the affiliate ID behind all of them.
QuoIntelligence was careful — and so am I — to say attribution stayed inconclusive. The report describes a possible link to an allegedly Polish SEO specialist; the infrastructure points to a single coordinated entity, but shared tooling means others could ride the same rails. The lesson isn't the name of the operator. The lesson is the scale: a lone operation can put a thousand entry points on your brand, and no affiliate manager refreshing a SERP by hand is going to find them all.
The forensic anatomy: what a VPN brand-bidding chain actually looks like
Here is where the VPN vertical gets its own technical signature, and where most monitoring quietly fails.
VPN affiliate links overwhelmingly run through Impact, whose tracking domain is sjv.io — so a resolved chain will usually pass through a brand-shaped host like nordvpn.sjv.io. Treat that as orientation, not evidence. sjv.io answers on a wildcard: any string in front of it resolves, including brands that don't exist. The hostname proves nothing. What proves something is the publisher ID inside the hop.
A real resolved chain looks like this:
1. bestvpndealsexample.com/nordvpn coupon page ranking for "nordvpn coupon"
2. surfshark.sjv.io/GbgrDr Impact short link — drops the publisher's cookie
3. surfshark.com/?utm_source=impact&utm_medium=<publisher-id>&...
the real site, now tagged to the affiliate
Read that chain twice, because it isn't a typo. The page ranks for NordVPN's coupon term and sells the searcher a Surfshark subscription. That cross-sell is a pattern in its own right: a coupon page monetizes your branded query with whichever program it happens to hold, not necessarily yours. If you only audit links belonging to your own program, this one is invisible to you — it surfaces as a competitor's affiliate revenue and your lost sale.
The publisher's identity is in that middle hop. But here's the catch, and it's the reason this fraud stays invisible: those Impact short links are cloaked. They're built to show one thing to a real shopper and something else — or nothing at all — to anything that looks like an automated check. Point a casual script or a one-off SERP tool at the link and it dead-ends; the affiliate stays anonymous. On Awin the equivalent hop runs through awin1.com, and the same logic applies — the publisher ID is the thing you're reading for.
If your "monitoring" is someone running a SERP check from the office Wi-Fi at 2pm on a Tuesday, you are seeing the clean version on purpose. The fraud is built to show you nothing.
That is the heart of why VPN affiliate fraud goes uncaught: it is cloaked and geo-targeted. The ad that fires for a real consumer in Bangkok on a Friday night does not fire for a compliance officer in the brand's home market during business hours. A single-region, single-IP, business-hours check is structurally blind to it. You don't catch this by looking harder from where you're sitting. You catch it by checking from the markets and at the hours the ad is actually served in — and that's the part that doesn't scale by hand. That's the problem AdCrime exists to solve.
Every major VPN bans this. It happens anyway.
Do VPN affiliate programs allow brand bidding?
No — but you have to go looking for where each one says so, and several don't say it in public at all.
| Program | Brand bidding | Where it's stated | What it says |
|---|---|---|---|
| Proton VPN | Prohibited | Public partner page | "[W]e do not allow bidding on Proton's brand names, including the product names and variations of them. If you use PPC advertising, you should send the traffic to your website first and not directly to us." |
| NordVPN | Prohibited | Public Nord Marks trademark policy | Forbids using the Nord Marks "in the context of unrelated goods or services to increase their visibility on search engines or e-commerce platforms." |
| ExpressVPN | Prohibited | Not public — the affiliate terms sit behind the signup portal; the ban is stated by networks distributing the offer | Cuelinks lists "Brand Bidding" under traffic not allowed and Involve Asia states it plainly. Cuelinks also bars generic SEM, so the restriction runs wider than brand terms alone. |
| Surfshark, CyberGhost | Terms not public | Behind the affiliate signup | — |
"Not published" is not the same as "allowed." It does mean that if you run one of those programs, the prohibition your whole compliance case rests on is a document your fraudster has read and your lawyer hasn't.
So why is your brand still infested? Because a written prohibition is not enforcement. The gap between the two is exactly where the fraud lives, and it has three parts:
- Detection latency. Brand bidding happens in real time and rotates constantly. A monthly manual check catches a fraction of it, weeks late.
- Scale. One operator, a thousand subdomains (see above). You cannot keep up by hand.
- The cloak. Even when you look, you're shown the clean version.
A policy you cannot enforce is a wish. Enforcement starts with detection that survives cloaking and geography — and then with turning a detection into a filing the network will act on.
How do you stop affiliates bidding on your VPN brand?
Finding the fraud is most of the work. Acting on it is procedural, and it is four steps.
1. Capture evidence that survives a dispute. A timestamped SERP screenshot showing the ad above your own listing, from the region it actually ran in, plus the full redirect chain with the publisher ID resolved out of the sjv.io (Impact) or awin1.com (Awin) hop. A screenshot alone is not enough: it proves an ad existed, not who ran it, and only one of those is actionable. Keep the raw chain rather than a summary — the hop order and the parameters are what a network's compliance team will re-check.
2. File with the right network, the right way. For Impact, use Report Partner on the partner's profile slideout and select the "Ad Hijacking / Trademark (TM) Bidding" issue type — though for brand bidding the more direct route is Impact's automated Paid Search Monitoring, where you raise the violation yourself and set the partner's response deadline. For Awin, reports go to the Partner Compliance Team through your account contact. Neither network publishes a response-time commitment, and that is worth internalising: the clock you are racing is your own validation window, not their queue. Give them the static publisher ID, not a per-click hash — nobody can act on a hash.
3. Decline inside the validation window, because after it closes the money is gone. This is where the real cost sits, and Awin is the clearest documented case. Its Advertiser Agreement bars an advertiser from recovering commission on a transaction once that transaction has been approved — and approval happens automatically if you let the validation window lapse without acting. There is no fraud carve-out at that stage; the fraud exception operates only before approval. So the publisher ID you found has a shelf life. Decline inside the window and the money stays yours. Miss it, and you are doing unpaid forensics on someone who has already been paid.
One asymmetry worth knowing: the network isn't barred from clawing back from the publisher for breach of its terms. That's the network's remedy against its own partner, though — not a route for you to recover an approved commission. Don't plan around it.
4. Escalate beyond the program only with counsel. I'm a founder, not a lawyer, so treat trademark complaints, termination, and the broader recovery ladder as things to walk through with someone qualified — there's a fuller version in the Playbook. What I can tell you is the operational core: the affiliate ID is the unit of enforcement, and speed is the whole ballgame.
A note on the shape of that work. Steps 2 through 4 take an afternoon each and are essentially clerical. Step 1 is where programs actually fail, because it has to happen continuously, across every brand term, from every market you sell in, before the validation window closes. That is a monitoring problem rather than a compliance problem, and it is the reason so many VPN programs have a written policy and no enforcement record.
None of this requires our software. A browser, a few vantage points, and the patience to read every hop will surface the publisher ID yourself. But VPN brand bidding is cloaked, geo-targeted, and spread across a thousand rotating subdomains — so doing it by hand, on every brand term, from every market, every week, is the part that breaks. That's the part I built AdCrime to handle, and VPN is the vertical we know best. Either way, the goal is the same: fewer fraudsters getting away with it.
Mario Vaher is the founder of AdCrime, which scans Google Ads across multiple regions for affiliates bidding on brands they aren't authorized to touch, captures the redirect chain and publisher ID behind each one, and packages it as evidence affiliate managers can file. If you run a VPN program and want to see what's bidding on your brand right now, the first scan is free — or read the full, ungated Affiliate Brand-Bidding Fraud Playbook.