To receive commission from programs you have to give correct name and details. Either these hackers are running in a group, in which case, they'd have multiple identities they could use, if one account is locked. But I don't think this is a huge group of hackers. I think it's either a lone wolf or at most, two or three people.
Albeit criminals are known to secure fake ID but unless commission is being sent to a bank account or a cheque (check), acquiring web-wallets is no mean feat. Those guys can sniff out fake sh#t with KK's barge pole.
Which brings me back to the affiliate programs. Unless these hackers are spoofing the referring headers/data or send blank referrers, then some form of data is being collected by the aff program. Some programs still veto applications, does Buffalo not do this anymore? If not, why not?
I can grab an aff ID and search Google, which will display all the sites using, the aff tag entered. The above returns nothing. Hence it's a new aff ID.
Not saying this is the case or it's true... But I have entertained the thought that these accounts are not hackers at all...