TutorialsSecurity

Affiliate Payout Scams: Account Takeover and Payment Diversion

propellerads-diverted-payments-scam

On January 5, 2026, several Twitch creators reported the same alarming discovery: someone had replaced their payout details with unfamiliar bank or PayPal information.

One of them, VTuber Mysti, said she had enabled two-factor authentication, mobile verification, and email alerts for account changes. Yet her payment details were still altered. Other creators described similarly frustrating attempts to get help. 

DJTICKLE wrote, “Support was no help and just logged it.” 

Twitch acknowledged the reports and said it was investigating the issue. At the time, however, neither the cause of the incident nor the method used to bypass the creators’ safeguards had been publicly established.

The incident had nothing to do with traffic quality, creatives, or tracking software. The target was the payout itself. In fraud terminology, this is payment diversion: legitimate money is redirected to an account controlled by the attacker. The UK’s National Crime Agency defines payment diversion as a broader category that includes invoice fraud, salary diversion, and certain forms of business email compromise.

Affiliate accounts can be attractive targets for the same reason. Payout schedules are often predictable, balances may be large enough to justify a targeted attack, and many affiliates manage their account, email, tax information, and payment details themselves.

Once an attacker gains control of that chain, or finds another way to change the payout destination, the legitimate earnings may still be paid on time, just not to the person who earned them.

No reliable public dataset measures affiliate payout diversion on its own. The closest large-scale comparison is business email compromise, although it covers a much broader range of attacks. In 2025, the FBI’s Internet Crime Complaint Center recorded 24,768 BEC complaints with reported losses of $3.05 billion. IC3 received complaints of all types from more than 200 countries; that figure does not refer specifically to BEC cases. The report also cautions that its statistics reflect complaints submitted to the FBI, not every fraud incident that occurred.

Affiliate losses are likely to be smaller than the corporate transfers that dominate BEC statistics. That does not make them minor to the people affected. A diverted payout of a few thousand dollars can erase weeks or months of work, and it may be difficult to recover once the payment has cleared.


Key Takeaways

  • Payout scams target the payment stage. Because the campaigns themselves remain untouched, your tracker, anti-fraud tools, and campaign checks will not usually detect the attack.
  • The attack may begin with a compromised inbox, a cloned login page, a generic phishing email, or malware on your device. Some clipboard-stealing malware can replace a copied wallet address with the attacker’s address just before you paste it.
  • Payout-change controls vary by platform. Some rely on email confirmation, while others require multi-factor authentication or manual verification. Email confirmation offers little protection if the attacker already controls your inbox.
  • Recovering your login does not necessarily restore your payout details. Treat account access and payment settings as two separate recovery tasks, and ask the platform to pause any pending payouts until you’ve secured both.
  • If the money has already been sent, act immediately. Start with The First Hour After a Diverted Payout.

Three Very Different Problems Called “Affiliate Payout Scams”

The same label covers three unrelated problems. When money goes missing, confusing them can waste the first, and most important, hour.

payout-scams-three-problems
Three unrelated problems share the name affiliate payout scam: a program that never intended to pay, fraud committed against a program, and payout diversion, where a genuine payment is released to a destination the affiliate did not authorize. This article is about the third.
Problem 1Nobody intended to payUpfront fees, “quality” bars nobody can clear, a hold period that keeps extending.Check the network first
Problem 2The program is defraudedFabricated leads, conversion fraud, cookie stuffing. Most affiliate-fraud guides cover this one.Written for merchants
Problem 3The payout is divertedReal program, real earnings, payment released. It just went to a destination you did not authorize.This article
The tell: nobody refused to pay you. The dashboard says completed and the money is somewhere else.
  • The first is a program that never intended to pay. It may charge upfront fees, impose vague “quality” requirements that are almost impossible to satisfy, or keep extending the hold period whenever a payout comes due. Researching the network, its payment history, and its terms before sending traffic can reduce this risk, though it cannot eliminate it completely.
  • The second is fraud against the program. In this scenario, commissions are manufactured through tactics such as fabricated leads, conversion fraud, or cookie stuffing. Most affiliate-fraud guides focus on this category and are written for merchants, networks, and advertisers.
  • This article is about the third problem: payout diversion. The program is genuine, the earnings are real, and the payment was released, but it was sent to a destination you did not authorize. Nobody refused to pay you; the money simply went somewhere else.

A dashboard marked “completed” and an empty bank account are warning signs, but they do not prove diversion on their own. A payment may still be processing, rejected, or sent using outdated details. 

Diversion is confirmed when the platform’s payout record shows an unfamiliar bank account, PayPal address, wallet, or other payment destination.

PropellerAds-protect-ad-campaigns-from-malware

Why Attackers Target the Payment Leg

Stealing someone else’s campaign revenue takes work: the attacker has to keep campaigns running, pass moderation, and monetize the traffic. Payout diversion is simpler. 

The victim has already earned the money; the attacker only has to change where it goes.

To redirect a payout, the attacker first needs a way in. They may steal your password, take over your email, or pretend to be someone you trust. Abnormal AI found that about one in four scam emails asking to change payment details came from a real vendor account that had been hacked. For ordinary invoice questions, it was fewer than one in 100. A request to redirect money needs to look convincing, so attackers often send it from an account the victim already trusts.

That is not a success rate. It means attackers were roughly 28 times more likely to use a real compromised account when requesting new payment details, presumably because such requests attract more scrutiny. 

The findings come from the security vendor’s customer base, but the pattern is useful: redirecting an existing payment often requires extra credibility.

Affiliates are attractive targets for a simpler reason: many are their own accounts-payable department. Support messages, account-manager updates, and payout notifications arrive in one inbox, and the same person approves every change. 

Larger organizations can separate these roles and verify new payment details through a second channel; solo media buyers must build those safeguards into their own routines.

The danger is that everything else keeps working. Clicks arrive, conversions post, and the balance grows as expected. Every campaign dashboard stays green while the payout destination quietly changes.

propellerads-ransomware-economy

Where the Attack Starts

Most payout-diversion attacks begin in one of four places. Some require weeks of preparation; others rely on volume or malware already running on the victim’s device.

A payout-diversion attack starts in a trusted email thread, on a copied login page, in a mass phishing campaign, or in the clipboard on the affiliate’s own machine. All four routes end at the same step: the payout destination is changed before the next payment run.
Weeks of preparationA conversation you trustA reply from a compromised mailbox, or a domain one character off from the real one.
Kit from $120 / 10 daysA copy of a login pageRelays the login to the real service and keeps the session cookie, so MFA is not in the way.
No research neededA mass campaignThe same payment warning to a large scraped list, sent from free webmail.
Already on the deviceYour own clipboardSwaps a copied wallet address for a lookalike, keeping the characters people glance at.
Every route ends hereThe payout destination is changed before the next payment run, and nothing about the campaigns looks different.
  • A conversation you already trust. The attacker may reply from a compromised mailbox, complete with the real message history, or use a lookalike domain that differs by a single character. The FBI lists small variations in legitimate email addresses as a common BEC tactic. When you are expecting the message, your brain tends to read the address you recognize.
  • A convincing copy of a login page. Modern phishing sites can reproduce an affiliate or advertising dashboard closely enough to survive a quick glance. Some also work around MFA by relaying the login to the real service and stealing the resulting session cookie. Proofpoint found that access to one such phishing kit, Tycoon 2FA, started at $120 for ten days.
  • A mass phishing campaign. This version needs no detailed research: send the same plausible account or payment warning to a large list and wait. APWG recorded 971,181 phishing attacks in the first quarter of 2026, up 13.8% from the previous quarter. Fortra’s data in the same report found that 72% of observed BEC attacks used free webmail accounts.
  • Your own clipboard. For affiliates paid on-chain, this may be the hardest attack to notice. Microsoft analyzed malware that checked the clipboard about every 500 milliseconds and replaced copied wallet addresses with attacker-controlled alternatives. Some replacements are built to survive a glance: for one address format, the substitute matches the first two characters of the original, for another only the final character changes. If the altered address is pasted directly into a payout form, there may be no warning before it is saved.

Clipboard malware is not the only form of address substitution. In address poisoning, attackers place lookalike addresses in a wallet’s transaction history and wait for the user to copy the wrong one later. 

A study presented at USENIX Security 2025 identified 270 million attempts targeting 17 million victims. The researchers attributed at least $83.8 million in losses to 6,633 successful incidents. Most attempts failed, but successful blockchain transfers could not simply be reversed.


Two Tickets, Two Queues

Regaining access to an account does not always restore control of its payment profile. On some platforms, these become separate support problems, handled at different speeds and with different evidence requirements.

One AdSense publisher reported that Google restored his account in September 2024 but left the attacker’s email attached to the payment profile. “Except that they forgot one thing, it is to delete the email of the payment profile that was hacked,” he wrote. The attacker could still change bank details and repeatedly block the publisher’s verification attempts. A month later, the issue remained unresolved.

Similar reports go back years. In 2011, a ClickBank affiliate wrote: “Someone has logged into my clickbank, changed the emails and everything now I can’t access my account. There are still recurring payments going in every day.

In May 2025, a Shopify merchant described the same timing problem after two days of support tickets: “I continue to have my sales revenue deposited in a fraudulent checking account.

That is the real danger: another payout may leave before support finishes reviewing the case. The first line of your ticket should request an immediate hold on all outgoing payments. Recovering the login comes next; securing the payout profile is a separate step, and you must confirm both.

Do not rely on alerts alone. One Payoneer user reported: “I never received any SMS or email alert about the account having unusual activity on it.” Check the saved payout destination and pending transactions directly, even if no warning has arrived.

propellerads-hikacked-ad-accounts

Why Payout Week Is a Risk Window

Reconnaissance runs from roughly fifteen to three days before payout. The change request lands two days before, the details are changed one day before, and the payment executes on payout day, inside the same days the affiliate is already waiting for a payment email. The affiliate spends the following two weeks asking where the payment is.
WhenWhat the attacker is doingWhat you are doing
Days 15 to 3 beforeQuiet reconnaissance. The mailbox is already accessible and the payout cycle is being learned from the inside.Nothing looks different. Campaigns run, conversions post.
Day 2 beforeA change request or a cloned-login link arrives.Waiting for an email about money, so this one gets opened faster and read less carefully.
Day 1 beforePayout details changed.No alert, or an alert into a mailbox the attacker also reads.
Payout dayPayment executes to the new destination.Expecting the payment to land.
Days 2 to 14 afterGone. The receiving account is emptied and closed.Asking support where the payment is, while the recovery window closes.
The attacker’s window sits inside the days you are already waiting for the money.
Schematic. The 10 to 15 day reconnaissance window is from Microsoft’s analysis of a device-code phishing campaign; the rest of the calendar is illustrative.

Attackers do not need to guess when money will move. Networks publish their hold periods and Net payment terms, while affiliates discuss payout schedules publicly. A payment message arriving when you already expect one feels routine and may receive less scrutiny.

Targeted attacks can also begin well before payday. 

In one Microsoft-documented phishing campaign, reconnaissance started 10 to 15 days before the phishing attempt. That is enough time to study a compromised inbox, identify financial contacts, and learn when payments are expected.

Attackers also favor moments when victims are less likely to respond. 

Shannon Mattern discovered suspicious activity in her Stripe account on the Monday after Easter 2023. During the three-day holiday, someone had created fraudulent connected accounts and routed instant payouts to a prepaid debit card. This was not affiliate payout diversion: the money came from fraudulent card charges. But it shows the value of a quiet weekend.

The pattern appeared again in the January 2024 attacks on Payoneer users in Argentina. Victims reported receiving password-reset codes while they were asleep and waking to empty balances. The exact attack method remained disputed, but the timing gave the attackers hours before anyone could react.


What Platforms Actually Do to Protect Payouts

In December 2022, an Ezoic employee changed the bank details on the company’s Google payment profile and redirected roughly $9 million to his personal account. Before making the transfer, according to reporting on the case, he had “tested a couple of times changing their bank account information and then immediately unchanging that, to see if any triggers would go off.

None did. The money was later recovered, and Ezoic’s publishers were paid. The important number, however, is not $9 million. It is zero: the number of alerts reportedly triggered while the attacker rehearsed the change.

Platforms that treat payout-detail changes as security events generally use one or more of the following controls.


Delays and Reviews

Fiverr creates a cooling-off period: adding or changing a withdrawal method blocks withdrawals for 24 hours, while updating a verified phone number triggers its own 48-hour wait. This can stop an immediate cash-out, but not an attacker who retains access and waits.

Digistore24 sends the account back into review when key bank details change. Payouts remain blocked until the account is approved again. The value of that control depends on what the review verifies, and the platform does not publish its criteria.

PayPal checks the withdrawal rather than the change itself. Its “system automatically reviews every withdrawal before it’s released,” and some withdrawals may be held for up to 72 hours. Signals include unusually large payments, unfamiliar devices or networks, account limitations, and discrepancies in the linked bank or card details. The weakness of any risk-based system is that an attacker who looks sufficiently normal may not trigger it.

PropellerAds - infostealer marketing tools threatening browser sessions and advertising accounts

Email Confirmation

ClickBank requires users to confirm a new payment method through an emailed link. This prevents accidental changes and some unauthorized requests. It offers far less protection when the mailbox is already compromised: the attacker can approve the change and hide the follow-up message with an inbox rule.

That is the basic problem with using the same inbox for login recovery, payout confirmation, and security alerts. Once the attacker controls it, several supposedly separate checks collapse into one.

Identity Verification and Its Exception

Stripe normally requires connected-account users changing a bank account or debit card to “provide details about the existing external account or verify their identity.”

There is an exception. A platform responsible for a connected account’s negative balance can generate a seven-day update code that bypasses the normal identity check. 

Stripe says the platform then “accepts sole legal and financial liability for any errors that result from incorrect external account changes.” It also instructs the platform to verify the requester’s identity and document the request before issuing the code.

Sometimes the normal check is impossible, for example, when the existing payout account belongs to a previous account owner. The platform can then issue an override code, but must verify the requester’s identity itself and accept liability if the change is wrong.

KYC - Why it matters for affiliates

Controls on the Payment Rail

At the bank-transfer level, the EU’s Verification of Payee rules add a limited safeguard. Since 9 October 2025, euro-area banks have had to compare the beneficiary name with the IBAN before standard and instant euro transfers. A mismatch triggers a warning, not an automatic block, and business customers can opt out for bulk payment files. The check helps when an attacker changes only the IBAN, but not when both fields match the attacker’s account. It does not cover card, wallet, or on-chain payouts.

On digital-asset exchanges, one of the strongest published controls is Kraken’s Global Settings Lock. Once enabled, it prevents account changes “including by Kraken Support.” 

The user chooses an unlock delay of between 24 hours and 30 days, creating time to detect and stop an unauthorized request. Its main limitation is simple: users must enable it before the account is compromised, and a previously configured Master Key can override the delay.

Every control below is running somewhere today, on a platform that pays affiliates. A few are settings in your own account and take a couple of minutes. The rest are the network’s to build, so ask what it has before you start sending traffic.

ControlWhat it can stopWhere it fails
Withdrawal delayImmediate cash-out after takeoverAn attacker who keeps access and waits
Account reviewAutomatic or instant diversionA weak review, or one that does not verify the requester
Risk review before withdrawalUnusual devices, networks, amounts, or payment detailsAn attacker whose activity appears normal
Email confirmationAccidental and some unauthorized changesA compromised mailbox
Identity verificationAttackers without the old account details or identity evidenceIncorrect verification or misuse of a platform-issued override
Name-to-IBAN checkTypos and mismatched beneficiary detailsMatching fraudulent details; non-bank payout rails
Settings lock with a delayAccount changes after login compromise, including support-assisted changesUsers who never enable it; a compromised Master Key

Why 2FA and DMARC Are Not Enough

Two-factor authentication remains essential, but its strength depends on the method. Platforms such as impact.com support verification by SMS, email, or an authenticator app. 

CISA classifies app-generated one-time codes as vulnerable to phishing, with SMS and email codes offering still weaker protection. Security keys and other FIDO/WebAuthn methods are the stronger, phishing-resistant option.

Adversary-in-the-middle phishing can bypass ordinary codes by stealing an authenticated session. The victim signs in through a malicious proxy, completes 2FA on the real service, and the attacker captures the resulting session cookie. As Microsoft explains, that cookie can authenticate the attacker “regardless of the sign-in method the latter uses.”

DMARC protects a different part of the chain. When correctly configured and enforced, it can stop unauthorized mail from using a company’s actual domain. But RFC 7489 explicitly says that DMARC “does not address the use of visually similar domain names (‘cousin domains’)” or abuse of the visible display name. It also cannot stop messages sent from a genuine mailbox that has already been compromised.

Keep both controls: 2FA protects the login, while DMARC protects the domain. Yet, none of them independently confirms that a payout change is legitimate or that the new destination belongs to the account owner.

The most useful additional control is a cooling-off period after any payout-detail change, paired with a notification sent through a separate channel, not only to the account email.

Ideally, pending payouts should remain on hold until the change is confirmed. In the Ezoic case, that combination could have made the repeated test changes visible before the real transfer took place.

PropellerAds - postback security protecting S2S tracking endpoints from forged conversions

Who Bears the Loss When a Payout Is Diverted

In practice, the affiliate often ends up carrying the loss. But this is not a universal rule. Responsibility depends on the platform’s terms, how the payout details were changed, the payment method, and local law.

If a platform sent the money to the account listed in its system, it may argue that it followed the instructions on file. That argument is weaker if the change happened because the platform’s own security checks failed or were bypassed.

Stripe describes one narrow exception. If a platform uses an override code to change a connected account’s bank details without the usual checks, it “accepts sole legal and financial liability” for errors caused by the change. This rule applies only to that specific Stripe process. It does not tell us who is responsible on other platforms.

Consumer fraud protections may not help either. In the UK, mandatory reimbursement rules for authorized push payment fraud protect individuals, microenterprises, and charities tricked into sending money through Faster Payments or CHAPS. With a diverted affiliate payout, however, the platform is usually the sender, while the affiliate is the person who was supposed to receive the money. So these rules are unlikely to protect the affiliate directly.

The answer ultimately depends on the contract, the payment method, and the country involved. The practical answer is simpler: once a platform marks the payout as completed, it may consider its job done. Unless the payment can be recalled or the platform accepts responsibility for a security failure, the affiliate may be left to absorb the loss.


The First Hour After a Diverted Payout

Speed matters. The best chance of freezing the money is before it has been withdrawn, split, or moved through several accounts.

In 2025, the FBI’s Recovery Asset Team handled 3,900 incidents involving almost $1.16 billion in attempted theft. It helped freeze $679 million, 58% of the total, down from 66% in 2024. A freeze is not the same as a refund, but it can stop the money from disappearing while the case is investigated.

You are the intended payee, not the sender. The money left the network’s account, so the network and its bank must start the recall.

  • Contact the platform first. Ask it to freeze all upcoming payouts, secure the account, and tell its bank to recall the payment that has already left. Also request the transfer reference, time, amount, and destination details. The platform is also the only party that can prevent another payout from being sent.
  • Report the fraud through an official channel. Contact your country’s fraud-reporting service, cybercrime unit, or police and provide all the transaction details you have. Add the report or case number to your support ticket.

Next, work out how the attacker got access. Possible routes include your email account, a stolen or reused password, a hijacked login session, or malware on your device. Until you know which one it was, assume the attacker may still have access.

From a device you trust, secure your email first, change the affected passwords, sign out of every active session, and check the payout details on every platform you use. Do not use the suspected device for payments until you have properly checked and cleaned it.

On-chain transfers cannot be recalled through the blockchain. An exchange or other custodial service may sometimes freeze the funds if contacted quickly, but there is no guarantee. For on-chain payouts, checks made before the transfer remain the strongest protection.


The Routine Before Payout Day

General login security is covered in the companion piece on hijacked ad accounts. It is also worth understanding how cracked marketing tools can steal session cookies, allowing attackers to bypass an ordinary login. The checks below focus specifically on payouts.

  • Keep a separate record of every payout destination. Store the bank account, wallet address, payment provider, and currency or network somewhere secure outside your email and affiliate dashboard. This gives you a trusted reference for every later check.
  • Confirm every change through a channel you chose yourself. Do not reply to the same email thread or call a number included in the request. If the mailbox or message is compromised, those routes lead back to the attacker. Open a new ticket from inside the platform or use contact details you already know are genuine. The FBI gives the same advice for payment fraud: verify any change to account details or payment procedures independently.
  • Open dashboards from your own bookmarks. If your password manager does not recognize a login page, stop and check the address carefully. It is not proof that the site is fake, but it is a warning. Where available, use a passkey or hardware security key for both the payout account and the email account that can reset it.
  • For wallet payouts, check the full address after pasting. Do not compare only the first and last few characters: address-swapping malware can generate replacements with similar-looking fragments. Use a saved or allowlisted address where possible. If you control the transfer, send a small test amount first, and check the address again before sending the rest.
  • Check the payout details before every payment cycle. Open the dashboard directly and compare the destination with your own record. This catches changes made without an email, alert, or support request.

These steps do not depend on spotting a fake email. Follow the same routine whether the message looks suspicious or completely genuine. A phishing page can look exactly like the real one and steal your one-time code as soon as you enter it. Fixed checks are safer than trusting appearances, especially when you are already expecting a payout.

propellerads-ads-safety-report-2025

FAQ: What Affiliates Ask After a Diverted Payout

Is two-factor authentication enough to stop a payout scam?

Not always. Two-factor authentication will usually stop an attacker who has only your password. It may not stop a phishing page that captures an authenticated session, or malware that steals the session from your browser. As Microsoft explains, a stolen session cookie can let an attacker skip the login process even when MFA is enabled.

A hardware security key or passkey is much harder to phish because it checks that you are signing in to the correct website. CISA recommends FIDO/WebAuthn as the widely available phishing-resistant option. Codes sent by email provide much less protection if the attacker already controls your mailbox.

Are on-chain payouts riskier than bank transfers?

They are not necessarily easier to divert, but they are harder to recover. The same stolen login, fake support message, or changed payout field can redirect either type of payment.

The difference comes after the money is sent. A bank may sometimes recall a transfer or freeze the receiving account. 

A confirmed blockchain transaction cannot be reversed through the network itself, although an exchange or other custodial service may be able to freeze the funds if alerted quickly. The address-poisoning study discussed above found 6,633 successful incidents causing at least $83.8 million in losses, a measure of the consequences, not proof that on-chain users are targeted more often.

Can the platform see that my payout was diverted?

Sometimes, but do not rely on it. A platform may flag an unusual login or payout change, but a payment sent to the destination saved in your profile can still look normal to its systems.

Once you report the incident, ask the platform to lock the account, stop future payouts, preserve the access and change logs, confirm where the money was sent, and contact its bank about a recall. The earlier Shopify case shows why the payment hold must come first: support tickets can remain open while scheduled payouts continue.

What should I check before relying on a network for payouts?

Look in its help center or ask your account manager:

  • Does changing payout details delay the next payment? For how long?
  • Will the platform send an alert through a separate channel, not only to the account email?
  • Can support stop a scheduled payout, and how quickly?
  • What information will the platform never ask you to send by email?

These answers tell you more about the platform’s real payout protection than a general security page.


Treat Payout Changes as Security Events

Most people think of payout details as routine account information, like a phone number or billing address. Attackers rely on that. A request to “update bank details” feels like paperwork, even though it changes where the money goes.

The Ezoic case showed how dangerous this can be: the employee changed and restored the company’s bank details several times without triggering an alert.

Treat every change to a payout destination like a password reset. Verify it through a trusted channel, add it to your own record, and expect the platform to delay the next payment.

Then make one final check before every payout cycle: open the dashboard and compare the destination with your record. It takes two minutes and, if something has changed, gives you time to stop the payment before it leaves.

Join our Telegram for more insights and share your ideas with fellow affiliates!

Trends

View more posts