August 19, 2026:


Phia co-founders Phoebe Gates and Sophia Kianni knew their AI shopping browser extension was automatically claiming affiliate commissions on purchases it did not drive for at least seven months before they told Bloomberg they had only learned of the problem “within the last 24 hours,” according to an August 11, 2026 Bloomberg investigation that reviewed internal Slack messages and interviewed people familiar with the matter. The scheme — a practice known as cookie stuffing — had by June accounted for an estimated 51% of the merchandise value Phia claimed credit for each month, and daily revenue collapsed from roughly $80,000 to between $10,000 and $28,000 once the features were disabled. The company has denied some of Bloomberg’s claims, says it is reversing fraudulent transactions, and has announced the hire of a compliance head — but its statement did not acknowledge that its founders had prior knowledge of the scheme.
Legal experts have been direct about the stakes. Ariel Givner, founder of Givner Law PC, wrote on X on August 11, 2026 that cookie stuffing “is typically treated as federal wire fraud in US courts” and warned of “a max penalty of up to 20 years prison + fines/restitution.” No criminal charges have been filed against Gates or Kianni as of publication.
Phia operates as a browser extension for Chrome and Safari that helps online shoppers find discount codes and compare prices across tens of thousands of retail and resale sites during checkout. When a user employed Phia’s offers to complete a purchase, the extension legitimately dropped a tracking cookie signaling to the retailer that Phia had referred the sale — and collected a commission. The problem, according to Bloomberg’s July 2026 and August 2026 investigations, was that three separately engineered features caused the extension to drop those cookies whether or not the user had actually engaged with Phia.
The first and most consequential feature was named “enable coupon auto drop” in Phia’s internal dashboard. A screenshot of that dashboard seen by Bloomberg shows the feature had been switched on remotely beginning December 10, 2025, and remained active until July 7, 2026 — the same day Bloomberg first contacted Phia for comment. While active, the extension would open a hidden background tab during checkout and inject Phia’s own affiliate referral code, overriding any prior referral link from another publisher — meaning Phia collected commissions on sales it did not send to the retailer.
The second mechanism, called “passive trigger,” was designed to fire Phia’s affiliate cookie at two-hour intervals on any site where it was active — not just at the moment of checkout. A third feature triggered a cookie whenever a user simply closed a Phia pop-up, regardless of whether they had used any Phia offer. The combined effect was a system that claimed credit for retailer transactions across Nike, Nordstrom, Gap, and thousands of other brand partners — transactions that users reached independently or through competing affiliates.
All three mechanisms are specific engineering choices, not emergent side effects of legitimate code. Ben Edelman, an independent researcher and former Harvard Business School faculty member widely regarded as the leading expert in affiliate marketing fraud, assisted Bloomberg in testing Phia’s extension across more than 50 websites alongside Capital One Shopping. His decades of cookie-stuffing research have documented the same hidden-tab injection technique in prior fraud cases, including the Hogan and Dunning wire fraud convictions — eBay’s top two affiliates — who received prison sentences of five months and 15 months respectively after defrauding eBay of tens of millions of dollars through substantially similar methods.
The timeline is the most legally consequential element of the Bloomberg reporting. On December 18, 2025, Gates wrote in an internal Slack channel that she was “worried this is an issue across the board” regarding Phia’s automatic cookie behavior, asking whether the auto pop feature was live across all retail sites to confirm Phia was monetizing on all gross merchandise value. That message, reviewed by Bloomberg and confirmed by people familiar with the matter, reads as verification that a feature was working as intended — not as discovery of an unexpected bug.
In a separate exchange, Kianni reportedly pushed to keep cookie features running even after an engineer raised the practice as a compliance concern. Bloomberg also reported that approximately 40 days before Phia publicly announced its $35 million Series A funding round — which cited eleven-fold revenue growth — Gates was asking employees to confirm the auto cookie drop was operating across all retail partners.
On July 8, 2026, the day after Bloomberg first contacted the company, a Phia spokesperson issued a statement saying they had become aware of the “misattributions” “within the last 24 hours” and that the team had “worked overnight to identify, mitigate, and has since resolved the issue.” The company called it a coding error. Bloomberg’s August 11 follow-up contradicted that framing entirely, reporting that the core mechanism was a named, remotely togglable product feature active for 209 days, and that the founders had been actively monitoring it.
In its post-August 11 response, a Phia spokesperson told multiple outlets: “Any features causing misattributions were immediately removed over a month ago on July 7. We are reviewing every transaction, we are fully committed to and have already begun issuing all transaction reversals to brand partners as a result of any misattribution, and we are hiring a head of compliance to make sure something like this never happens again.” The Phia post-investigation spokesperson statement did not address the Slack messages or the timeline.
Cookie stuffing is an affiliate marketing fraud technique in which tracking cookies are secretly placed on a user’s browser without their knowledge, using hidden browser elements — iframes, background tabs, JavaScript redirects — to falsely credit a purchase to an affiliate who played no role in driving the sale. In the standard affiliate marketing model, retailers like Nike or Nordstrom pay commissions only when an affiliate demonstrably sent them a buyer. Cookie stuffing bypasses that verification by having the affiliate’s tracking code present in the browser at purchase time — regardless of how the shopper actually got there.
Federal courts have found that intentional cookie stuffing can constitute wire fraud under 18 U.S.C. § 1343. Wire fraud requires four elements: voluntary and intentional participation in a scheme to defraud, intent to defraud, reasonable foreseeability that interstate wire communications would be used, and actual use of those communications. Cookie stuffing through a browser extension satisfies the “interstate wire communications” element because affiliate tracking involves cross-state data transmission between the extension, the retailer’s servers, and the affiliate network’s commission ledger. The 2025 Supreme Court ruling in Kousisis v. United States also reinforced wire fraud prosecution for “fraudulent inducement” — meaning prosecutors need not prove that defendants intended to cause economic loss, only that they induced a transaction under materially false pretenses.
The FTC has advertising disclosure guidelines that explicitly require transparency in affiliate relationships — guidelines cookie stuffing by design circumvents. Additionally, affiliate networks, including Impact.com, contractually prohibit cookie stuffing; Impact.com suspended Phia from its marketplace after Bloomberg’s first investigation.
Phia is not the only browser extension shopping tool to face these allegations. PayPal’s Honey extension — a shopping discount finder with tens of millions of users — has been the subject of an ongoing federal class action in the Northern District of California that alleges it engaged in substantially the same conduct: opening hidden browser tabs during checkout to replace legitimate affiliate cookies with Honey’s own tracking code, collecting commissions the extension had not earned. On June 22, 2026, the court denied PayPal’s dismissal motion in that case, formally titled In re PayPal Honey Browser Extension Litigation, before Judge Beth Labson Freeman. Rakuten Advertising terminated Honey from its affiliate network in January 2026 over the allegations, cutting the extension’s access to approximately 2,000 merchant partners.
The architectural reason both cases share the same mechanics is not coincidental. Any browser extension that legitimately intercepts the checkout process to find discount codes must, by technical necessity, run JavaScript at the point of purchase and have the ability to communicate with affiliate tracking networks. That same access enables fraudulent cookie injection. Neither Chrome nor Safari extensions have a technical enforcement layer that distinguishes legitimate cookie placement from hidden-tab stuffing. Google updated its Chrome Web Store affiliate policies in 2025 to address affiliate link-swapping behavior, but enforcement remains complaint-driven rather than automated. The Phia and Honey cases together represent a category-level vulnerability, not isolated corporate misconduct.
When Phia disabled the features on July 7, 2026, Phia’s internal revenue chart seen by Bloomberg showed average daily revenue falling from roughly $80,000 to between $10,000 and $28,000. At the lower end of that range, the disabled features had been generating as much as $70,000 per day — roughly 87% of daily affiliate revenue. A July 7 Slack message from a Phia data scientist, reviewed by Bloomberg, put the share of merchandise value the company improperly claimed at approximately 51% for June, though Phia disputed that figure, arguing the methodology was flawed and overstated the effect.
That revenue figure has implications beyond operational impact. Phia raised a $35 million Series A in December 2025, announced publicly in January 2026, at a $185 million valuation. The fundraising announcement cited eleven-fold revenue growth. If a substantial portion of that revenue was generated by the “enable coupon auto drop” feature — switched on December 10, six days before the Series A closed — the question of what was disclosed to investors about the source of revenue becomes material.
Yes. In 2014, Shawn Hogan, who ran eBay’s largest affiliate marketing program, pleaded guilty to wire fraud for cookie stuffing and received a five-month federal prison sentence along with a $25,000 fine. Brian Dunning, eBay’s second-largest affiliate, received a 15-month sentence for substantially similar conduct. Both cases involved browser-based cookie stuffing targeting a single affiliate network. The mechanism Phia allegedly used — targeting 6,200+ brand partners through a browser extension — represents a considerably larger scope. In the Hogan and Dunning cases, the FBI collaborated with eBay to gather evidence; the Phia case involves internal company communications already reviewed by journalists and multiple named individuals familiar with the matter.
The cookie-stuffing scandal lands at a moment when Gates had publicly staked her brand identity on building without parental assistance. “My primary motivation is I have a chip on my shoulder to build something generational that has no ties to, you know, me, my privilege, or my last name,” she told Yahoo Finance’s Opening Bid Unfiltered podcast in February 2026. She has stated she did not take money from her parents for Phia and raised outside capital to build independently.
Kianni’s parallel narrative was built on sustainable and ethical technology. The youngest United Nations advisor in US history, she founded Climate Cardinals, the world’s largest youth-led climate nonprofit with more than 10,000 volunteers in over 80 countries, and served on the EPA’s Youth Advisory Council. Her co-founder role in a company now facing allegations that it deliberately routed fraudulent cookie injections past compliance warnings sits in stark contrast to that public profile.
The story’s immediate business damage is concrete: suspension from a major affiliate network, a revenue collapse of 65–87%, an obligation to reverse disputed transactions with more than 6,200 brand partners, and the cost of standing up compliance infrastructure. No criminal charges have been filed, and Phia continues to operate. Whether federal prosecutors examine the Slack evidence — and whether investors press for answers about the revenue figures that underpinned the company’s $185 million valuation — remains to be seen.
Cookie stuffing is an affiliate marketing fraud technique in which a software tool plants tracking cookies on a user’s browser without their knowledge during an online checkout — falsely signaling to a retailer that the tool drove the sale and is owed a commission. In Phia’s case, Bloomberg found that the browser extension used three specific mechanisms: an “enable coupon auto drop” feature that opened hidden background tabs during checkout and injected Phia’s referral code over other affiliates’ links; a “passive trigger” that fired cookies every two hours on active sites regardless of user action; and a user-dismissal trigger that dropped a cookie whenever someone closed a Phia pop-up, again regardless of whether any Phia offer was used. All three mechanisms are described in Bloomberg’s August 2026 Phia reporting.
No. PayPal’s Honey browser extension faces a federal class action in the Northern District of California — In re PayPal Honey Browser Extension Litigation — alleging substantially the same conduct: secretly replacing other affiliates’ tracking cookies with Honey’s own during checkout. On June 22, 2026, the dismissal motion was denied, keeping the case active. Both cases point to the same structural problem: browser extensions that legitimately run at checkout have the technical access needed to fraudulently stuff cookies, and no automated enforcement mechanism currently prevents this.
Federal wire fraud (18 U.S.C. § 1343) carries a maximum penalty of 20 years imprisonment and substantial fines. Prior cookie-stuffing prosecutions — most notably the 2014 eBay wire fraud convictions of Shawn Hogan (five months) and Brian Dunning (15 months) — established wire fraud as the applicable charge. The Supreme Court’s 2025 ruling in Kousisis v. United States expanded the “fraudulent inducement” theory of wire fraud, meaning prosecutors would not need to prove intent to cause economic harm — only that the founders knowingly induced commission payments under false pretenses, per the federal wire fraud statute. As of publication, no charges have been filed.
Users who installed the Phia browser extension should remove it from Chrome or Safari if they have concerns, and monitor whether any browser permissions it held gave it access to their checkout data beyond commission tracking. Retailers who were Phia brand partners — particularly those on Nike, Nordstrom, and Gap’s scale — should audit their affiliate commission records from December 10, 2025 through July 7, 2026, and contact Impact.com or Phia directly regarding the announced transaction reversal process. Phia has stated it has begun reversing misattributed transactions to brand partners as a result of the investigation.