Episode 4
Clipping, Affiliates, and the Industrialization of Online Deception
with Craig Silverman of Indicator
Show Notes
Craig Silverman is an award-winning journalist who has spent more than 15 years researching and reporting on the manipulation of our information environment. He is currently the co-founder of Indicator, a media outlet dedicated to exposing digital deception and teaching digital investigative and OSINT (open-source intelligence) techniques.
Prior to launching Indicator, Craig was a national reporter at ProPublica, where he focused on investigating digital platforms and online manipulation. Before that, he served as the media editor for BuzzFeed News, where he pioneered innovative approaches to exposing digital disinformation and media manipulation.
Key Episode Takeaways
- The Industrialization of Deception: Digital manipulation has shifted from lone actors into a massive, industry backed by venture capital and brutal supply chains, including Southeast Asian "scam compounds" that merge human trafficking with high-tech fraud.
- The "Manufactured Organic" Loophole: Brands are now using "clipping" and industrial-scale UGC campaigns to generate billions of views through paid creator networks that mimic authentic posts.
- An Incentive to Cheat: The current digital economy creates a "race to the bottom" where deceptive or violative content often sees higher engagement and lower costs than honest ads.
- Ad Revenue Cannibalization: By failing to police undisclosed marketing, social platforms are letting a shadow ad economy thrive that actively drains budgets away from their own official, trackable ad businesses.
- Deterrence Through Public Examples: Instead of trying to automate everything, platforms could flip the script by making high-profile, public examples of agencies that openly brag about their deceptive tactics on social media.
Episode Highlights
- 00:00Introduction and Background of Craig Silverman
- 01:21Early Collaboration and Scam Evolution
- 04:27Indicator Media's Mission and Approach
- 08:29Undisclosed Marketing and UGC Campaigns
- 13:21Scale and Enforcement Challenges
- 20:51Platform Cannibalization and Business Impact
- 28:29AI Labeling Audit Results
- 34:15Community-Based Detection and User Skills
- 39:17Affiliate Marketing Case Study
- 46:48Systemic Incentive Problems
- 49:13Conclusion and Resources
Transcript
There may be transcription errors: we apologize for those in advance.
Rob: Hey, everyone. Welcome back to Won't Fix. Today I'm talking to Craig Silverman. Craig is an award-winning journalist who has spent more than 15 years researching and reporting on the manipulation of our information environment. He's currently the co-founder of Indicator, a media outlet that exposes digital deception and teaches digital investigative and OSINT techniques.
Before Indicator, Craig was a national reporter at ProPublica, where he focused on investigating digital platforms and online manipulation. Before that, he was the media editor at BuzzFeed News, where he pioneered new approaches to exposing digital deception, disinformation, and media manipulation.
I'm really glad Craig could join us today. I've interacted with him on several occasions over the years — when I was at Facebook, he wrote a number of articles we commented on. He's a great journalist and also a great teacher, helping people understand what's behind the content they're seeing online. I'm excited for you to hear this conversation, and as always, please send us your feedback.
---
Rob: Hey, Craig, how are you?
Craig: I'm good. How are you doing?
Rob: Good. It's been a while — actually, it hasn't been that long. We've been chatting every now and then for what seems like ages. When was the first time? Was it when I was at Facebook, or before that?
Craig: It was when you were at Facebook. I did a lot of reporting on scams and fraud on Facebook, particularly people running scammy ads or nasty affiliate offers. I think one of the first times we actually got on a call was in 2018, when I did a story about a San Diego marketing agency that looked from the outside like a normal digital marketing agency but was actually running tens of millions of dollars' worth of celebrity scam affiliate ads — people would click, and then they'd be enrolled in an auto-billing scheme.
Rob: The number of weird, crazy scams out there continues to amaze me. But I talked to Asaf Kipnis recently, and he was saying a lot of it is just the same playbook with different optimizations and different tools. So I also wonder how much of this is actually new, and how much is re-rolling old scam tactics.
Craig: There are fundamental playbooks that still work. What's different is that the internet made it possible to reach victims in many different places, a lot more easily than direct mail ever could. And then over the last couple of years, AI made it possible for small teams to really scale up the volume of messages, marketing, and ads.
But there was also an awful human innovation, which is the scam compounds in Cambodia and elsewhere in the region. They realized: if we run a job scam and recruit hundreds or thousands of people and put them into forced labor, they become the human machine sending out all of these messages and putting people into our funnel. It's a brutal marriage of technological innovation — they built systems, they ran these things like tech companies in a lot of ways — with human trafficking and slavery to get the mass human element. That's the most astonishing, awful thing we've seen. But it also means you can be a small group of people and potentially steal a lot, a lot, a lot of money. And it's never-ending now.
Rob: It's really unfortunate, and the scale is immense. The transnational nature of it is very challenging too.
Rob: Let me back up. I've been following what you're doing with Indicator, and I'd love for you to share more about it. To my mind, one of the coolest parts is how you're giving people the tools to find some of what's going on online and pick apart the scams and other things trying to deceive people. Maybe set some context on the kinds of things you're doing and how you're going about it — and how you decided to do it.
Craig: For sure. My background is journalism, but I've also been part of startups. One of my first jobs was at a technology company called Zero Knowledge Systems that was building a private overlay for the internet. One of the crazy things about that: one of the senior engineers there was Adam Back, who was recently the subject of a New York Times article claiming he's Satoshi, the creator of Bitcoin. I didn't know Adam well.
I've just sort of found a niche around digital investigative work, particularly looking at the different ways our digital environment is being abused and used for deception. I did a lot of early reporting on disinformation and on the manipulation of platforms like Facebook to spread false and misleading content at scale. Over the previous ten years, I started BuzzFeed Canada, then I was media editor, where I did much of that disinformation reporting. Then I joined ProPublica, the nonprofit investigative newsroom, in 2021 and worked there for four years.
Almost exactly a year ago, I quit ProPublica because I felt like there was something else I should be doing. That became Indicator, a publication I run with my partner, Alexios Mantzarlis.
We do investigations into what we call digital deception, which is a broad umbrella term we chose deliberately. We don't just do disinformation. We don't just do scams. We're interested in fake engagement — in any way the digital environment is being manipulated to deceive people.
One part of it is reporting and investigations. The other part is training. I've spent a long time training people in newsrooms and NGOs in what's often called OSINT, or digital investigative work: gathering available material online, digging into it, and producing investigative work from it. I felt like we have a real challenge in journalism, where the skills still aren't where they need to be. And there's a growing number of people around the world who are really into OSINT and trying to learn it.
I'd been writing a free newsletter for a while, focused on tools, tips, and techniques, because I couldn't do anything else — I had a full-time job. I felt there was an opportunity to build something where we did investigations, but then explained how we did them and taught people to do them, and kept investigators' skills sharp by tracking the enormous volume of new tools and techniques, because it's a burgeoning, exploding area. We built a paid membership business around that.
So when we publish an investigation, at the end of it we publish what we call the info box, which is a bulleted list of everything I did to put the investigation together and the tools I used. I also publish deep-dive guides and give a monthly workshop.
We're in this moment where deception is not only widespread, it's become industrialized — scam compounds, large-scale transnational organizations intersecting with organized crime. But the other part, really just over the last couple of years, is that it's becoming legitimized. You have VCs in Silicon Valley — Andreessen Horowitz invested in a TikTok bot farm, a company called Doublespeed. Nobody had ever put a million dollars into a bot farm before at a major VC.
I also do a lot of reporting on undisclosed marketing, which is one of the playbooks a lot of tech startups and other companies are using: hiring tons of very young people to create new TikTok and Instagram accounts and post hooks and relatable content, without ever disclosing they're being paid by the company.
So for me there's a sense of urgency and mission that we need to spread these skills as far as possible, and that I need to be digging into this stuff and publishing as much as possible. We're doing journalism, and then we're teaching people — whether they're journalists or not — how to do these investigations.
Rob: You mentioned undisclosed marketing. You wrote a really interesting piece about the "get paid to watch TikTok videos" scheme, which is related — we'll come back to that. I also want to talk about affiliate marketing.
I've been seeing reporting about clipping and undisclosed promotion. I have a friend in ad tech who gets very frustrated because there are a lot of "marketing influencers," even in B2B, posting about how great some ad platform is, and they appear to be undisclosed paid promoters. How widespread is this? It seems like the FTC and others really haven't been enforcing in this area. I remember when people used to get upset and say, okay, you need to label this sponsored. And the amount of disclosure just seems to have gotten less and less over time.
Craig: There's the widespread piece and the enforcement piece, and obviously they're connected — if enforcement is there, it won't be as widespread, because people will be worried.
In terms of how widespread: there are marketplaces now where you as a brand can go in and say, I have a $100,000 budget, or a $2 million budget, and here's my content. If it's clipping, people take it, clip it, put it out, and you pay them based on the views they get. There's almost never disclosure.
X only recently introduced a paid partnership label, which is crazy — it's basically the law, and they didn't do it for a long time. That gives you an indication on enforcement.
The clipping world grew up largely around live streamers. They pioneered this model where they'll stream for hours and hours and then incentivize people to go through the stream, pull out the most potentially viral moments, and get paid to help make them viral. It just lands in people's feeds — oh, look at this crazy clip from some streamer. You think it's a fan, but no, it's part of a marketing campaign. MrBeast has a clipping company. There are several self-serve platforms.
The other model is companies doing what they call UGC or organic marketing. You've got a product, you've got a brand, you hire them, and they either have a roster of existing creators or they go hire people who fit the type of person that's good for your product. Then they do mass-scale, industrialized posting. They come up with a bunch of hooks and frames and test them like crazy. The people hired on these campaigns might be doing one or several posts a day, every day, for a long period.
As soon as something hits and goes viral, if there are 20 creators on that campaign, all 20 will be told to use that exact frame, that slideshow, that whatever, on their accounts — because platforms like TikTok don't punish people for duplicative content. So you have a network of dozens and dozens of paid creators with accounts that don't disclose they're working for a company. They just say, oh, I'm a student, or I'm this. And they crank out variations of the exact same post. In some cases I've edited together videos of them literally reading the same script.
We're talking about billions and billions of views. I did a piece looking at seven or eight of these UGC campaigns, and each had hundreds of millions or billions of views, and they're still ongoing. Almost none of the companies ever respond to me. Some respond and say, oh, these are our rules, this is how we do it — but the rules they describe are not actually what the FTC or the platforms themselves require. They're basically telling me, yeah, we're not in line with either set of rules, but this is what we do for our clients.
At the end of the day, what it means is that the average person on TikTok or Instagram has a feed that's increasingly filled with — or sprinkled with — posts that look like they're from real, relatable people, with no paid label and no disclosure in the content itself. It all looks organic. That's why they call it organic UGC: it's user-generated content, it's organic. But by definition, organic content is not paid. And they're paying people to create organic content. We've manufactured organic content.
I've gone to the FTC every time I've done one of these stories. They typically don't comment in general, but there's been nothing brought that I've seen on clipping or on undisclosed UGC campaigns. They've done nothing to date. And the platforms, when they respond, tell me what their rules are. Sometimes they add a label after the fact when I reach out, or in some cases accounts get removed or deleted, but there's no mass-scale enforcement by the platforms or the FTC. It's open season.
Rob: Not to take the other side, but it is really hard. These are off-platform payments — anything could be happening behind the scenes, and it's difficult to do technical enforcement when you don't know what's going on. That said, on the duplication of content, there are probably timing signals: this looks suspicious, why is this the same. But it's tricky to find automatically, which is why a lot of it ends up reactive. And unless the enforcing agencies here or in other countries get aggressive, this is just going to keep going.
The other thing you touched on indirectly is that feeds pivot so much faster now, across all the platforms. If you show interest in a topic, you get a lot more content on it. I'm in London right now — I ran the London Marathon —
Craig: Yay.
Rob: — and my feed is entirely London, London Marathon, whatever. Completely different than it was a couple of days ago. That makes the impact of questionably sourced information much worse.
Craig: Absolutely. TikTok changed the game in how the algorithm works, and companies like Meta saw it: it doesn't matter if you have a big following. This is one of the things the marketers say — you don't need to be on the platform for months, you don't need lots of followers. You can create an account, warm it up with some regular posts, and get an absolute viral banger, 5 or 10 million views, within your first few weeks, because the algorithm is just trying to find anything it can serve to people that they'll like. Instagram has moved in that direction too.
You do have this weird experience as a user. On X, I'll hover on one post about one topic and suddenly my feed is sprinkled with that topic, and I'm like, I wasn't that interested — please dial it down. It's such a hair trigger. But you can also make it work for you: my For You feed on X is now all skeezy marketers talking about what they're doing. It works for me in that sense, though I don't enjoy it personally.
Craig: You raise the enforcement challenge: what are the reliable signals an internal team could build and scale to detect this? That is a challenge, no question.
But the strategy I'd suggest is this. These companies, the marketers, and the agencies they hire talk about this publicly. They're boasting about it. You can go find companies that have published their own case studies of what they're doing. Pick one that's running at very large scale, pick an agency running at very large scale, take what they've publicly shared, and then trivially — for internal investigators — build a case and take down one company as an example. If people saw that, and you said, we removed them because they were doing X, Y, Z, this violates our policies, and we also have concerns it may violate FTC rules, I think everyone in the industry would go, oh, crap.
So the scaling part is hard, because they're not disclosing, they're not putting the tags on. But the duplicative posts are a real signal — once they find an angle that works, everybody does it and it's all over the feed.
And aside from regulation, the user experience is horrible. When I write these stories, people come to me and say, I see that post and variations of it from ten different creators in my feed all the time. It's driving them crazy. They see this brute-force attack on their timeline, and they didn't know they were ads. They just thought people were copying each other.
On enforcement, I'd say: pick one example and make it public, and I think you'd see people snap into compliance. I sat in on a webinar where the founder of a company talked about how when a post gets above 50,000 views or so, all the creators on the campaign get a message saying, hey, we have a banger — and everybody goes and comments on that post. So it's not just the content, it's engagement farming, which is also against policy. They're hitting these platforms from so many different levels.
I wish they'd make an example of someone, or just put out a communication saying, we're going to remind everybody what our rules are because we're going to step up enforcement in this area. You don't actually have to step up enforcement. I think if you made a public announcement, you'd see people change.
Here's an argument I make to platforms when I get a chance to talk to someone, and I'd like your take. You're potentially cannibalizing your own ad business by allowing this. The reason it works is that it isn't labeled as an ad and doesn't have any of the platform structure of an ad around it. If I'm a marketer, I can spend $500,000 on a paid campaign on TikTok or Instagram, or I can spend $500,000 on a campaign where none of it goes through the auction, none of it is subject to whether the price rises or falls based on performance. If I can just pay people to brute-force the algorithm and have viewers think these aren't ads, that's probably going to perform better — and that's exactly what the marketers selling these campaigns say. So if you're a platform allowing people to run ads without paying you, over time you're cannibalizing your business. I haven't reached enough people inside to know — what do you think, having worked at a platform?
Rob: The first version of this was when organic brand posts got downranked, or essentially disappeared, from platforms like Facebook and Instagram, after companies had spent a bunch of money to get followers and were upset because that reach got crowded out by the combination of friends-and-family content and ads.
What you've seen over the last couple of years is friends-and-family content getting crowded out by content the algorithm thinks will be interesting — unconnected content, to your point about TikTok being first. So now you're in the position you're describing, where unconnected, non-business content is actually business content in some cases, and it's competing with ads. There's also unconnected clout-chasing content: let me explain this thing from 15 years ago in a long series of posts on Threads. Another variant of the same thing.
I'd be surprised if data scientists at these companies weren't looking at this and asking how much it's cannibalizing ad revenue and how to reduce it. I have no doubt they're thinking that way. The real question is whether they can find something that reduces the negative behavior without reducing the positive side. That's always the trick — how do you thread that needle, how do you communicate to the different actors that things are changing? And then some of the most sophisticated folks still find ways through.
Someone was just posting content about the incident at the correspondents' dinner this weekend, and if you click through to the page that posted it, the admins are five accounts in Vietnam. So there's still a lot of inauthentic foreign clout-chasing engagement. People still don't realize the tools that exist to fight this.
Craig: They've got to be looking at these signals, because if it's in the business interest, those arguments are always better — and you'd know better than me what resonates internally. If the FTC is doing zero enforcement, is Meta worried the FTC will come after them? Probably not, especially with the current FTC. But if they look at it and say, this is money that could be spent with us, and the scale of these campaigns is quite large, that's a good argument.
And you keyed on duplicative content, which I think is one of the best signals, because that's how they operate. This is in their playbooks and their webinars: when something works, do it a million times. In some cases it's literally word-for-word scripts, or the same series of slideshows with the same hook at the end. That's the opportunity for automated clustering and detection — here's this type of post across dozens or hundreds of accounts within a short timeframe. From there the signals are trivial for a human analyst. They often have the same kinds of words in their bios. Sometimes they do mention the brand in the bio, but that's not what the platform rules or the FTC rules require — you have to disclose it in the content itself. And the FTC says a hashtag isn't good enough, which I know annoys a lot of creators, but those are literally the rules.
So I'm interested to see what might get the platforms to send some kind of signal. The conversation around clipping is reaching more people. A lot of what I end up on seems huge to me because it's being talked about in the communities I monitor — but by definition I'm looking at early adopters. That's what I'm trying to find. It's not part of the larger conversation yet, and I'm often trying to punch these things through to a bigger audience and say, hey, look at this, somebody should do something.
Clipping, just in the last two or three weeks, is starting to get more mainstream. People are starting to understand that this is manufactured virality, that it's part of a marketing strategy. I'll be interested to see whether that triggers anything — whether the FTC decides to talk about clipping. But right now the hands are off the wheel. Nothing is publicly happening. Even when I send platforms lists of dozens of accounts, most of them remain online. Sometimes they retroactively apply the paid partnership label to content that has already gotten millions of views and whose viral moment is gone. That's not the most effective strategy.
I do hope someone inside one or two of these platforms says, let's send out a smoke signal and scare everybody a little. I think that would be effective — say, hey, we're paying more attention here, and everybody on these campaigns goes, oh, okay, what does that mean?
Rob: You bring up labels. The other label I think is really interesting is AI labeling. There's so much AI slop out there, and we know from various studies that when people know something is AI-generated, they view it more negatively than when they're uncertain. I'm curious what you think of how the various AI labeling efforts are going, and about the different levels of slop out there. It seems pretty bad, and I assume it will get worse.
Craig: This is an area where we've done two audits at Indicator.
The broad picture: pretty much every major platform and a lot of the major AI companies — the ChatGPTs and others — have said they understand people would like to know if they're looking at something AI-generated, and that disclosure should be there. They've committed to metadata standards, so that if you generate something in, say, Nano Banana on Gemini and upload it to Facebook, Facebook should recognize it as AI-generated and label it. That's the main industry commitment everyone has made. None of them want to discourage the use of AI, because they're all building models and want people using them on their platforms. But they've all said, yes, we agree it should be labeled.
So we did two audits. We went to several different models, generated images and videos, and checked whether the metadata was in there or not — have they actually implemented the standard? Then we uploaded to different platforms. We had to build a matrix: okay, we generated this image in ChatGPT, now we're putting it on Instagram, LinkedIn, Pinterest, and so on. Then we generated an image with Meta's own model and put it on Instagram, LinkedIn, and so on.
The headline is that everybody is still doing a pretty bad job, and they've all committed to it. There's legislation coming into effect next month in the U.S. that actually requires more of this kind of labeling. They have a lot of work to do.
They have gotten better. The first time we did the audit, the best platform for consistent labeling was Pinterest, at about 55%. So only about half the time, when we'd validated the metadata was there, Pinterest was labeling properly. Other platforms were far, far worse. What we showed was that a bunch of them hadn't properly implemented the metadata standard, so it wasn't being generated and embedded in the files. And the bigger problem was that even when we validated the metadata was there, the label often didn't appear on upload.
Our first audit was pretty disappointing. In the second, some had improved. But the craziest thing in both audits was that we would generate images with Meta's AI model, upload them to Instagram, and they still weren't labeled. You'd expect them to do it best on their own platform. Meta is to this day the most concerning one.
Who's doing it best? Google is the most interesting here. Pinterest and LinkedIn seem better at applying the labels, but in terms of actually doing something new, Google came out with SynthID, their own proprietary watermarking technology. If you generate an image in Gemini, not only is the C2PA and IPTC metadata supposed to be there, but even if someone strips that metadata — which is trivial; there are metadata removal tools that will even remove the little Gemini logo on your images — SynthID watermarks it invisibly. So if you take an image and throw it into Gemini and ask whether it was generated with Google's tools, it often can tell you, even if the metadata's been stripped.
There are ways to defeat that, and increasingly there are tools claiming they can remove SynthID watermarking. I don't know how effective they are; I haven't done a full-scale test. But the state of things is not good.
Unfortunately, if you're a tech industry hater, it fits the narrative: they say they'll do things and they don't really do them. It's not that they've done nothing, but I wish they'd put into fulfilling this promise even a small fraction of what they put into building the models. Google is the only generation company I've seen that said, let's build something new that's actually quite good. So I'll give them props on SynthID. I just wish everybody would put a couple more engineers on it for the next six months so it works properly — don't starve the teams of people who really want to make this work.
I will acknowledge the challenge. If you're on the team at Meta implementing this — and you'd know better than me — that's your team, but then you have to deal with Instagram, Facebook, Messenger, WhatsApp, and find champions within all of those teams. I can't imagine there's much incentive when the priority from on high isn't "get this metadata done," it's generation tools, engagement, ads. So I can see the challenge. But they've got to get their act together.
Rob: The trend for some of these folks seems to be relying on the community to call out deception — in the comments, or with a community note. Threads shipped community notes as the alternative to third-party fact-checking. I don't know how effective that's going to be.
But you could also argue there may be no technical way for this stuff not to be circumvented — the metadata can always be stripped — so eventually you have to have some community-oriented mechanism, and maybe they're betting they'll make it better over time and figure out how to surface notes well. To me, though, it seems like we're always going to be in a state of uncertainty about whether something is true, from here on out.
Craig: That is the reality. When I give workshops or talks to people who aren't journalists or technical, the big thing I try to say is: understand this environment is being manipulated, and yes, there are massive amounts of AI-generated content. You need that awareness. But you don't want them to walk away freaked out, thinking, I don't know what to trust, I can't believe anything anymore.
One of the really basic skills I encourage is patience. You don't have to make up your mind about this video or this image right now. You don't have to take action on it. You don't need to stop scrolling. You don't need to share it. You could send it to somebody and ask if they think it's real. So much of it is meant to trigger us into fight-or-flight, or to trigger our emotions and our own beliefs and biases. If you can train yourself to have a little more patience and not get carried away, that's very good at a basic level.
What often happens then is you move into System 2 thinking, rather than the reactive System 1 mode we mostly operate in to save cognitive effort. Suddenly you're patient, you can shift your brain into a different mode, and you see the thing differently because you've enabled yourself to pull back mentally and physically.
Sure, I teach reverse image search. I teach all these things. But at the end of the day, if you can't get your mind into an approach for navigating a universe where there are many types of manipulation and many deceptive things at any given moment — as well as really good, interesting stuff — if you can't consume and browse in a way that accommodates that and gives you the opportunity to pause, you're going to be in trouble. If you can pause and be patient, and you know you could search and see what else people are saying, or do a reverse image search, then you're winning.
But it's an extremely difficult information environment for anyone to navigate, and it has nothing to do with education level or intelligence. It's really tough, and we need to develop new skills, no question.
Rob: The best advice I always give when something looks sketchy is to slow down. Take time, don't be in a rush, try to reduce the perceived level of urgency. Ask someone else, come back to it in ten minutes — whatever slows you down.
Craig: And on that level, that's good news — because if that's actually powerful, then you can accept that synthetic media detection tools will never be 100% reliable, which is true. They'll never be as good as the models. They'll never keep up. There will never be perfect metadata, and metadata can be stripped. All the weaknesses, all the evasion and adversarial tactics — given all of that, the best defense is adopting a mode of consuming information that lets you slow down, pause, and engage your thinking.
When I communicate that, what I want people to have is a sense of power, a way not to give up in this environment — which is a very easy thing to do. And in some cases, that's actually the goal of the manipulation: to get people to conclude that they don't know what to trust or believe. You can't have a good functioning society, you can't have a democratic society, in that scenario. So the thinking piece is really key.
Rob: That's a great point. One thing I've enjoyed about your writing over the years is how you look at incentives — why is this information being produced, why am I being encouraged to click on it? A few months ago you wrote about people being told they'd get paid to watch TikTok videos, and you did a lot of investigation into the entities behind it and the affiliate networks. Maybe walk us through that story at a high level, and then let's talk about affiliates.
Craig: Oh, affiliates. It's funny — you spoke to Asaf recently, and I shared some of my findings with him, and he did some work on it too. When I shared my initial findings, he said something like, it's affiliate marketing, the worst people on earth.
Rob: It always comes back to affiliates.
Craig: That's it. If you encounter something sensationalist or manipulative online, there's a good chance — not always, but a good chance.
In this case, what I saw on TikTok was a lot of posts, some of them very viral, with a video telling people there's a setting in TikTok that gets you into a program where they pay you to watch videos. The video showed people turning on the toggle. That caught people's attention, because there are many very heavy TikTok users who believe they could earn a lot of money if they were paid to watch.
One of the reasons this worked, aside from it being an easy money scheme — and we said scams have always been around; easy money is the oldest one there is — is that everybody knows TikTok does pay creators. People know that once you have a certain number of followers you can get into a creator program and get paid based on engagement and views. Because TikTok pioneered that, this scam works.
So there'd be the video, and then a URL in the account bio, or shared in the comments, because people were commenting "how, how, how" and they'd reply. One thing these folks did to resist TikTok recognizing what was going on was to share the URL as an image in a comment, so TikTok couldn't automatically scan it against a list of known malicious domains.
You'd type in or click the domain and land on a page saying yes, there's a program, you can earn money, here's how it works, click here to get started. From there you'd go through a series of redirects and end up on a page that in some cases was a similar rewards program but not about TikTok — you're going to get a gift card if you do this. Or it was a page asking you to download a web browser or install an application.
At the end of the day, it's affiliate marketing. One, you could inspect the URLs and see the telltale parameters around affiliate IDs. Two, they're trying to get you to take an action so that the affiliate marketer who ran that deceptive TikTok post and got you to click earns a commission when you install the app or sign up for the program. That's the core of affiliate marketing: drive people to an offer, get them to accept it — purchase, download, sign up — and earn a commission.
So the core of the scheme was that you thought you were getting paid to watch TikTok, and at the end you installed or did something that had nothing to do with TikTok, but got somebody paid and tricked you into doing something you otherwise wouldn't have.
Rob: At various points people have said to me, oh, there's this global conspiracy, all these different offers running everywhere, it's all one big mega entity. But often it's a bunch of disconnected actors copying each other, copying tactics they see working.
There was one recently — a very similar scam, three different versions of it, all different actors. One was essentially just a web page. The second was an HTTrack copy of that page or a prior website, essentially identical. And the third was designed very well, everything obfuscated across different files. Someone had said, let's use the same creative approach, but let's design it so we hide where it's going. So there are lots of versions of affiliates, and they all copy each other and try to find what the others are doing and replicate it, but they're often disconnected.
The other thing that was interesting in your article, and is also true generally: it's always worth asking whether the end advertiser, or the company paying the affiliates, or the network, knows what the affiliates are doing to generate those leads or sales. Because often it's, oh, I have no idea — but come on.
Craig: I'm shocked to discover there's gambling going on in this establishment.
Rob: Yes. I'm sure you've seen all the variants of that.
Craig: That's the beauty of the model — plausible deniability is built in. If you're the company whose product is getting sold through these ads, you work with an affiliate network, and the network has relationships with all the individual affiliate marketers. The network says, we'll pay $60 if you get somebody to sign up for this, and pushes that out to their affiliates, maybe with some suggested creative. Then the affiliates are off and running.
They often do have rules — you can go on the affiliate marketplaces and see them: no deception, no celebrity ads, all the rules they're not supposed to break. But the affiliates go out, break all the rules, run the crazy deceptive ads, and drive huge volume and conversions. Oftentimes nobody says anything, because it's working. And if there is an issue and somebody discovers the ads, the ads for that affiliate get removed, but nobody goes up the chain. Platforms don't typically go up the chain and say, this affiliate network we found has been a hotbed of millions of deceptive ads, and we're sending them a cease and desist. That basically never happens.
So the system is set up so the affiliate network can say, well, we published the rules, they're not allowed to run celebrity bait ads, this person broke the rules, and we're very disappointed in them. And then they probably work with them again. Even if people complain to the network, or the client is mad, the network says, some people broke the rules, I'm really sorry. And if the FTC goes after the network, or after the individual affiliates, the client says, we set rules for this campaign and they broke them. Part of the design is that everybody establishes rules to keep it legal, but in a lot of cases — not always — everyone is willfully blind, knowing the affiliates won't follow them.
This is the central thing in everything we're talking about — undisclosed ads, clipping, affiliate stuff. The problem with the environment right now is that cheating works best. Why would you run legitimate ads when you can do undisclosed ads with a UGC campaign and get a better return? Why would you run traditional ads when you can launder it through an affiliate network running tons of violative, illegal celebrity ads that convert like crazy?
As long as the incentives are that cheating wins, you're going to have lots of people cheating — because the auction nature of the ad world means the ad that performs better typically costs less. If the stuff that breaks the rules performs better, then unless enforcement is really good and those violative ads don't get time to perform and earn, cheating is completely incentivized.
Affiliate marketing is the most perfect example. The most successful affiliates are usually doing sketchy stuff, usually cheating, usually breaking the rules — and everybody knows that's how you win.
The last thing I'll add: I did a story about this happening with Obamacare marketplace ads on Meta and Google. I talked to people who run compliant ads in that space, and some of them said they'd given up on that business line, because everybody is cheating and they're winning. Their compliant ads will never compete with an ad that says the government is going to give you $500 a month for free. It's impossible. So it really skews the market. The affiliates know it, and they've set up this beautiful plausible deniability system where there's not much accountability at all.
Rob: The one piece of optimism I have — to your point about cheating being celebrated — is that there's a real culture of, as they say in *The Big Short*, why are they confessing? They're not confessing, they're bragging. There's a lot of bragging happening on places like X. So if the government entities ever wanted to enforce, I don't think they'd have a hard time finding leads, because some of these "marketers," in quotes, are going to be talking about the shady stuff they're doing.
Craig: And they sell courses in some cases.
Rob: They do. So I'm hopeful that'll happen at some point.
Rob: I think we're coming to the end of our time, at least for this one. Craig, this was, as always, illuminating. Where can people find you online?
Craig: Thank you. Our site is indicator.media. We're active on Bluesky and LinkedIn, and we have a free newsletter people can sign up for. Every Friday we do a rundown of news in the world of digital deception, plus a section on new and updated tools, and we try to cover academic research in the area as well. So go to indicator.media and sign up for free for our Friday newsletter. That's where all of our work is now.
Rob: That's awesome. I've been enjoying what you and Alexios have been doing for some time, and I'd encourage everyone to go check it out.