Measurement 4 min read

Could Bill Gates daughter face prison time for cookie stuffing?

Phoebe Gates, daughter of Bill and Melinda Gates, is in the press lately for an alleged "Cookie stuffing" operation. If charged and convicted, penalties could include actual jail time. Do you know how it works?

Could Bill Gates daughter face prison time for cookie stuffing?
(Disclosure: Generative AI assisted in the creation of this image.)

How Cookie Stuffing Actually Works

More specifically, a tactic as old as digital marketing called "cookie stuffing."

Just a quick fact check before continuing. No charges have been filed. Phia and its founders face allegations, an affiliate network suspension, and some very unflattering Slack logs. Legal experts noted that cookie stuffing is typically prosecuted as federal wire fraud, which technically carries a maximum of 20 years. <-- That is where the scary number comes from.

But let us just pause for a moment and take in the fact that 7 years before Phoebe Gates was born, Microsoft deployed the cookie spec into Internet Explorer. Her father founded and lead the company while her mother was also a senior member of management at the time. Even though cookies were invented by the team at Netscape, IE was the browser that drove explosive growth.

Then, 31 years later, the market alleges that their daughter's tech startup was involved in a large-scale media attribution scandal. This is the type of drama nerds dream of.

The honest handshake that never was

So what is the actual alleged crime? It is one of the oldest hacks in ad tech

Affiliate marketing operates on a pretty simple agreement that if you drive sales, you get paid a commission. The ways we prove who drove what sale is the tricky bit.

In overly simplified terms:

  1. A publisher writes about a product.
  2. You click their link.
  3. Your browser stores a tracking cookie.
  4. You buy the product.
  5. The merchant sees the cookie and pays the publisher a commission.

The entire system rests on one assumption: the cookie "proves" influence.

Cookie stuffing breaks that assumption. Someone plants an affiliate cookie in your browser without you ever clicking anything. You later buy something on your own. Direct visit, Google search, whatever. The merchant's billing attribution vendor looks up the planted cookie and pays a commission to someone who did nothing.

It is attribution theft. I call it last-click larceny.

The plumbing

Your browser is trusting by design. When a page tells it to fetch a resource, it fetches. If the responding server sends back a cookie, the browser stores it. Few questions asked.

Fraudsters exploit that trust a few ways:

Read next