Startups
Phoebe Gates' Phia Accused of Cookie Stuffing Fraud
Bloomberg says Phia, the shopping app from Bill Gates' daughter Phoebe, claimed commissions it never earned, and that its founders knew for seven months.

Phoebe Gates, the 23-year-old daughter of Bill Gates, has spent two years insisting that her shopping startup would succeed with "no ties to my privilege or my last name." The company is now the subject of a reporting series alleging that a large share of its revenue came from commissions it did not earn, and that its two founders knew about it for months.
What Phia is accused of doing
Phia is a browser extension marketed as a personal shopping assistant: it hunts for better prices on clothes and accessories, and takes an affiliate commission when a user buys through it.
Bloomberg reported on July 9, 2026 that the extension was also claiming commissions on purchases it had nothing to do with. It opened a background tab and dropped its own affiliate tracking cookie at checkout, overriding legitimate referrals from the creators, deal sites and publishers who had actually sent the shopper there.
The practice has a name in the affiliate industry: cookie stuffing.
"The most fundamental requirement in affiliate marketing is that commission is only paid if a user clicks," affiliate marketing researcher Ben Edelman told Bloomberg. "The rules don't allow fake clicks, simulated clicks, imaginary clicks or hypothetical clicks. Only a real click will do."
How much of the business it was
The scale is the part that turns an embarrassment into a business story. In June 2026, more than half of the sales Phia claimed credit for came from cookie stuffing, and after the feature was switched off on July 7 the company's average daily revenue fell from roughly $80,000 to between $10,000 and $28,000.
Phia switched the feature off the same day Bloomberg first contacted it for comment. A spokesperson blamed "technical anomalies" and said the team had "worked overnight to identify, mitigate, and has since resolved the issue."
The Slack messages
A follow-up Bloomberg story on August 11 undercut the accident framing. Internal Slack messages obtained by the publication indicate Gates and co-founder Sophia Kianni pushed for the features and knew about them for at least seven months, despite saying they had learned of the problem within the previous 24 hours.
"can u confirm auto pop for cookie drop is live on ALL sites w a coupon to confirm we are monetizing on all [gross merchandise volume]," Gates wrote on December 18.
In a separate exchange, after an engineer flagged that automatically dropping cookies breached compliance rules, Kianni wrote: "Whatever we can do to keep these cookies dropping will be amazing thank you."
The legal exposure
No charges have been filed against Gates, Kianni or Phia, and no regulator has publicly opened a case. What makes the reporting serious is that cookie stuffing has been prosecuted before as federal wire fraud, which carries a maximum sentence of 20 years.
There is direct precedent. Shawn Hogan, once one of eBay's largest affiliates, was sued by the company in 2008 over a cookie stuffing scheme and sentenced in 2014 to five months in federal prison plus a fine, after being found to have taken roughly $28 million in marketing fees he had not earned. Brian Dunning, prosecuted in the same eBay affiliate case, pleaded guilty and received 15 months.
Corporate attorney Ariel Givner laid out that history in the post that pushed the legal framing into wide circulation:
Again, this is called cookie stuffing! On a simple level, it's automatically injecting affiliate tracking cookies to claim commissions on sales you didn't drive. It's typically treated as federal wire fraud in US courts. There's a possibility of a max penalty of up to 20 years prison + fines/restitution. As a reminder, previous violators were given… - Shawn Hogan (top eBay affiliate): guilty plea → 5 months federal prison + $25k fine. - Brian Dunning: guilty plea → 15 months prison + restitution (millions defrauded).
— Ariel Givner (@GivnerAriel) August 11, 2026
What the replies argued about
Givner's post drew 83,000 views, and the discussion under it split cleanly in two directions, neither of which was really about Phia's browser extension.
The first was industry exasperation. "I wish all cases of cookie stuffing and stolen ecommerce attribution were investigated as seriously as Phia," wrote affiliate marketer Malte Landwehr, in the reply that drew the most agreement from people who work in the channel. It is a fair point and it cuts both ways: attribution theft is endemic in affiliate marketing, prosecuted almost never, and the reason this instance got a Bloomberg investigation is the surname on the founder.
The second was a bet against enforcement. "No chance Phoebe Gates sniffs a minute of prison," ran the most-liked skeptical reply. "Her punishment will be some social shame." That prediction is probably right on the narrow question, and for an unremarkable reason rather than a conspiratorial one: no charges exist, first-time affiliate fraud cases are usually resolved civilly through restitution, and both prison precedents people keep citing involved eight-figure sums taken over years.
Almost nobody in either thread argued that the conduct was fine. The argument was over whether anything happens to it.
Phia says it has removed the features that caused misattribution, is issuing transaction reversals to brand partners, and is hiring a head of compliance.
The verdict
Strip out the surname and this is a familiar startup failure mode: a growth number that only worked because it was counting other people's work as its own, defended internally right up until a reporter asked about it. Every dollar of the missing revenue came out of an affiliate who did drive the sale, which is why the seven months matter more than the sentencing range.
Reporting in this article is drawn from Bloomberg's July 9 and August 11, 2026 investigations, Futurism, KIRO Newsradio and Business Insider.
About the author
Marcus Doyle
Marcus Doyle is a Toronto-based technology writer covering cybersecurity, hardware, and supply-chain risk.