They were ripping off both their users and anyone using affiliate links (including the content creators who promoted them)
During checkout, when you clicked the “find coupon” button in honey (which it prompted you to do on screen during checkout), it would strip out any affiliate link and add their own. So if you clicked on a product from a review, they would strip out the referral link from the YouTube video or website that sent you and indicate they sent you instead and get the commission.
In addition, they were working with online retailers and basically extorting them. They said that if retailers paid them a fee, they got to pick the discount code that was used during checkout. So if there was a 20% coupon and a 5% coupon, stores could pay them to ignore the 20%.
This, in turn, was basically faking out their users, thinking they were giving them the “best deal” like they claimed to.
If a user is banned on their home instance, that ban is federated out to all instances. If a user is banned on a remote instance, they’re just banned locally on that instance, and their account remains active for all other instances.
They’re likely some remote users who have interacted enough with your instance to be federated over, and then banned on their home instance.