Full Breakdown
Phia’s Cookie-Stuffing Scheme: Internal Slack Messages Reveal Months-Long Misattribution
8/13/2026, 11:33:22 AM
Core Event – Misattributed Commissions via Cookie Stuffing
Phia, a browser-extension “personal shopping assistant,” automatically dropped affiliate cookies during checkout even when shoppers did not click its links or use its coupons. The practice, known as “cookie stuffing,” let Phia claim commissions on sales it did not actually drive. Internal Slack messages show co-founders Phoebe Gates and Sophia Kianni discussed and approved the feature as early as December 18, and a dashboard flag named “enable coupon auto drop” was active until it was turned off in early July. After Bloomberg’s July 9 report, Phia said the issue was a software bug discovered the previous day and that the offending code was removed shortly thereafter.
Background & Context – Affiliate Marketing Rules and Phia’s Model
In affiliate marketing, a publisher earns a commission only when a shopper clicks a referral link or uses a coupon that places a tracking cookie on the browser. Contracts with retailers such as Nike, Gap, and Nordstrom expressly prohibit “automatic” cookie placement. Phia’s extension was designed to pop up discount offers at checkout; tests showed it opened a background tab and injected its own cookie, overriding legitimate referrals from other publishers.
Timeline
- Feature “enable coupon auto drop” enabled in code.
- Company claims it became aware of the issue “within the last 24 hours.”
- Bloomberg publishes initial findings of cookie stuffing.
- Revenue chart shows daily earnings fall sharply after the feature was disabled.
- Impact.com begins reallocating commissions attributed to Phia.
Data & Statistics – Revenue Impact and Scope of the Practice
- An internal revenue chart reviewed by Bloomberg shows average daily revenue dropped from about $80,000 to between $10,000 and $28,000 after the features were disabled.
- A Phia data-scientist’s estimate placed “cookie stuffing” at roughly 51 % of the merchandise value Phia claimed credit for in June.
- The “passive trigger” feature, active from October to July, dropped a cookie every two hours on any “top 1000 website” where a user had previously interacted with Phia.
Official Statements & Responses
Impact.com suspended Phia from its marketplace and began reallocating pending commissions. The company also announced new features such as a “digital closet” while pledging to continue connecting shoppers with discount offers.
Conflicting Reports & Gaps
Phia’s spokesperson argued that the revenue decline was also due to the company disabling “most of its monetization efforts,” contending that Bloomberg’s methodology “overstated the potential impact.” Bloomberg, however, cited internal dashboards and Slack messages that label the behavior a deliberately switchable feature, not a bug. Kianni later claimed a proposed “dismiss-event” cookie-drop feature “never got implemented or launched,” while internal messages show the idea was actively discussed.
Verbatim Quotes
- “Whatever we can do to keep these cookies dropping will be amazing thank you,” — Sophia Kianni, messages between co-founder
- “These additional findings reveal a multipart effort designed to inflate Phia revenue despite lack of benefit to merchants,” — Ben Edelman, affiliate marketing expert
- “It’s typically treated as federal wire fraud in US courts. There’s a possibility of a max penalty of up to 20 years prison + fines/restitution,” — Ariel Givner, corporate attorney
- “AI is reshaping nearly every industry, but shopping is stuck in the past,” — Phoebe
