Statement SR-289022 · posted September 30, 2026

Affiliate Programs & NetworksFull statement

Honey Investigation Deepens: New Browser Extension Risks for Affiliates

The Honey probe now frames checkout-time extension cookie hijacking as a category risk for CPL, CPA, rev-share and hybrid deals — not a one-off allegation.

By Nathan Brooks3 min read622 words

Statement notes

  1. The Honey investigation has expanded from allegations against a single extension to broader extension-based attribution risks for affiliate programs.
  2. Coupon extensions can capture last-click attribution at checkout, redirecting CPA and rev-share commissions away from referring publishers.
  3. FTC disclosure rules and program-terms conflicts with network agreements form the two live compliance fronts in the case.
Honey Investigation Deepens: Revealing New Browser Extension Risks for Affiliate Programs - Affiverse
Exhibit AHoney Investigation Deepens: Revealing New Browser Extension Risks for Affiliate Programs - Affiverse — AI-generated

The Honey investigation has widened, and the new filings name a risk every affiliate program running last-click attribution should price in: browser extensions that sit between the publisher and the merchant at the moment of conversion.

At the center of the case is PayPal's Honey extension, whose default coupon-search behavior has been accused of overwriting affiliate cookies at checkout. The deepened investigation now points to broader extension-based risks for programs — not a single bad actor, but a structural weakness in how last-click CPA and rev-share deals attribute sales.

The mechanics matter more than the branding. A shopper clicks a publisher's link — a deal site, a cashback portal, a YouTube creator — and the tracking cookie is set. At checkout, the shopper opens a coupon extension to hunt for a discount. If that extension submits any code, even an invalid or empty one, it can capture the last-click position on the merchant's affiliate network. The commission flows to the extension operator. The publisher who sourced the traffic gets zero.

For CPL and CPA campaigns, the exposure is immediate: a converted lead or sale is credited to the wrong partner. For rev-share and hybrid deals, the damage compounds, because every recurring payment tied to that customer follows the hijacked click. Publishers with long cookie windows — 30, 60, 90 days — lose the most, since the extension interception typically occurs at the end of the funnel, right where the cookie is about to pay out.

The deepened investigation also raises a question program managers have avoided: what did merchants and networks know, and what did their terms of service permit? Several major networks prohibit adware and toolbar override behavior on paper. Enforcement, historically, has depended on complaints and manual audits. Extensions that present as legitimate shopping tools — coupon finders, price comparators, cashback reminders — occupy a gray zone those policies were not written to cover.

The compliance angle is now live on two fronts. In the US, the FTC's endorsement and disclosure framework applies to creators promoting Honey and similar tools; undisclosed paid placements of extensions to audiences of deal-seekers carry disclosure obligations regardless of the attribution question. Separately, merchants face a potential conflict between their affiliate program terms — which promise publishers attribution for referred traffic — and network agreements that let extensions claim the same clicks. The investigation is testing whether that conflict amounts to a breach of publisher agreements.

For programs, the practical exposure is measurable. Any merchant with a meaningful share of coupon-hunting traffic should assume some percentage of affiliate-attributed conversions is being captured by extensions at checkout. The fix set is known but unevenly applied: network-level enforcement of override bans, de-duplication logic that prioritizes the referring click over the last-injected one, and audit testing using clean browser profiles that run publisher links alongside popular coupon extensions.

For publishers, the lesson from the deepened investigation is to segment. Traffic that converts at checkout with a coupon query is the traffic most at risk. Creators and deal sites negotiating rev-share or hybrid terms should ask networks directly what de-duplication rules apply to extension-injected clicks, and get the answer in the program terms rather than in a support ticket.

What separates this phase of the investigation from the original allegations is scope. The earlier claims targeted one extension's behavior. The new material frames extension-based attribution capture as a category risk — one that affects every performance deal type and every network that settles commissions on last click. Whether that framing holds up will depend on what the investigation produces next, and whether networks move from policy language to technical enforcement before regulators or courts force the issue.

source Google News: Affiliate programs & networks (Source)

Filed under

Share this article:

More from Nathan Brooks

Nathan Brooks

Show full bio

News editor covering media and advertising at RevShare Report.

37 articles

Carried forward

« Previous articleNext article »

SR-289022

End of statementThank you