Raiffeisen Bank’s Russian division recently identified and neutralized a sophisticated affiliate marketing fraud scheme that was siphoning marketing budgets through deceptive traffic attribution. Working in collaboration with data analysts from OWOX BI, the financial institution successfully exposed a system where third-party affiliates were using browser extensions to intercept organic and paid traffic, effectively "stealing" commissions for conversions they did not legitimately generate. This case highlights a growing challenge in the digital marketing landscape, where the complexity of attribution models often masks fraudulent activities that can cost large enterprises millions in unnecessary expenditures.
The investigation began when the bank’s marketing department noticed a troubling discrepancy in their performance metrics. While the costs associated with their Cost-Per-Action (CPA) affiliate programs were rising significantly, the overall revenue and customer acquisition numbers remained stagnant. This lack of correlation between spending and growth prompted a deep dive into the bank’s web traffic data. Initial observations suggested that some affiliates were leveraging technical loopholes to overwrite traffic source values at the critical moment of conversion.
The Mechanics of Affiliate Attribution Fraud
The specific type of fraud suspected by Raiffeisen is a variation of "cookie stuffing" or "attribution theft." In this scenario, users who have already navigated to the bank’s website through other channels—such as organic search or paid search (CPC)—are targeted by malicious or grey-hat browser extensions. These extensions, often marketed as discount finders or coupon aggregators, monitor the user’s browsing activity. When the extension detects that a user is on a checkout or application page, it triggers a popup offering a discount or a "special offer."
If the user clicks this popup, the extension redirects them through an affiliate link. This process happens almost instantaneously, often causing a brief session break. To the standard analytics software, it appears as though the user left the site and returned via the affiliate’s link. Because most attribution models operate on a "last-click" basis, the affiliate is credited with the entire conversion, even though the bank had already paid for the initial acquisition through other marketing channels or had earned it through organic brand recognition.
Chronology of the Investigation
The project to identify and eliminate this fraud followed a rigorous three-step analytical process. Raiffeisen Bank, led by Head of Online Sales Dmitriy Berezin, partnered with Victoriia Pashchenko and the OWOX BI team to build a data pipeline capable of detecting these near-instantaneous session switches.
Phase 1: Establishing a Raw Data Pipeline
The primary hurdle was the limitation of standard web analytics tools. Raiffeisen utilized the standard version of Google Analytics, which often relies on sampled data for large traffic volumes and does not provide the hit-level granularity required to see individual session breaks in real-time. To solve this, the team implemented the OWOX BI Pipeline to stream unsampled data directly from the website into Google BigQuery.

Google BigQuery served as the central repository because of its ability to handle massive datasets with high security standards—a prerequisite for any financial institution. By collecting every "hit" (a single action on a website) with a precise timestamp, the analysts could reconstruct the exact sequence of a user’s journey, down to the millisecond.
Phase 2: Defining Fraudulent Indicators
Once the raw data was flowing into BigQuery, the analysts developed a set of criteria to flag suspicious behavior. The logic was centered on identifying "impossible" user journeys. Specifically, they looked for instances where:
- A user was active on a high-intent page, such as a loan application or a credit card checkout.
- The current session ended abruptly.
- A new session started immediately (within less than 60 seconds).
- The user was on the exact same page as before the break.
- The traffic source for the new session had changed to a CPA affiliate.
By filtering the BigQuery data through these parameters, the team could isolate specific User IDs and Affiliate IDs associated with these anomalies. This allowed them to distinguish between legitimate affiliate referrals and those that were being "injected" into an existing session.
Phase 3: Reporting and Confrontation
The final phase involved moving the processed data from BigQuery into a digestible format for the marketing team. Using an automated add-on, the data was exported to Google Sheets, where pivot tables were created to visualize the impact. The reports clearly identified which specific affiliate partners were responsible for the rewritten source values. Furthermore, the data showed exactly which channels were losing credit—primarily organic search and the bank’s own paid search campaigns.
Supporting Data and Statistical Findings
The findings were definitive. The analysis revealed that a significant percentage of transactions attributed to certain CPA partners followed the fraudulent pattern of session-breaking and source-overwriting. In a typical month, the bank discovered that two specific partners were responsible for the vast majority of these "robbed" transactions.
By analyzing the timestamps, Raiffeisen found that the time between the end of a legitimate session and the start of a "new" affiliate session was frequently less than 10 seconds. In a natural browsing environment, it is statistically improbable for a user to leave a site and return via a different marketing channel within such a short window while remaining on the same internal application page.
The financial impact was substantial. By ceasing cooperation with the two identified dishonest partners, Raiffeisen was able to immediately reduce its affiliate payout budget without seeing a corresponding drop in actual customer acquisitions. This move effectively increased the Return on Ad Spend (ROAS) for their organic and CPC channels, which were finally being credited correctly for the conversions they drove.

Broader Implications for the Financial Sector
The Raiffeisen case is a microcosm of a much larger global issue. According to industry reports from firms like Juniper Research, ad fraud is estimated to cost advertisers over $80 billion annually, with a significant portion of that coming from attribution manipulation. For banks and financial institutions, the stakes are particularly high. Not only is the cost per acquisition (CPA) for financial products like mortgages or credit cards among the highest in the digital economy, but the regulatory requirements around data and security make them frequent targets for sophisticated fraudulent schemes.
This investigation highlights several key takeaways for digital marketers in the enterprise space:
- The Limitation of Last-Click Attribution: Relying solely on last-click models creates an incentive for affiliates to "intercept" users at the final stage of the funnel.
- The Necessity of Raw Data: Standard analytics dashboards are often insufficient for fraud detection. Access to hit-level, unsampled data is required to see the technical footprints of browser extensions and automated scripts.
- The Power of Cloud Data Warehousing: Tools like Google BigQuery allow companies to join disparate data sets and run complex queries that would be impossible in traditional spreadsheet software.
Official Response and Strategic Shift
Following the investigation, Dmitriy Berezin, Head of Online Sales at Raiffeisen Bank, emphasized the importance of transparency in the affiliate ecosystem. The bank has since adjusted its contracts with CPA networks to include stricter clauses regarding the use of browser extensions and toolbar-based traffic.
"Raiffeisen got a report that helps monitor statistics on affiliates and bring to light the cases of fraud in CPA networks," the bank noted in its summary of the project. "The company managed to optimize the ad budget by ceasing cooperation with two dishonest partners that rewrote the traffic sources and unreasonably overbilled Raiffeisen."
The bank continues to use the OWOX BI and BigQuery framework to perform ongoing monitoring. This proactive stance serves as a deterrent to other affiliates who might consider using similar tactics. By maintaining a "continuous audit" of their traffic sources, the bank ensures that their marketing budget is being spent on genuine incremental growth rather than being diverted by technical exploitation.
Conclusion
The successful identification of affiliate fraud at Raiffeisen Bank serves as a landmark case for the Russian banking sector and the global digital marketing community. It demonstrates that while fraudsters are becoming more sophisticated in their use of technology, the tools available to brands for data analysis are equally powerful. By moving beyond surface-level metrics and investing in raw data infrastructure, organizations can protect their margins and ensure that their marketing partnerships are built on a foundation of genuine value creation. As digital advertising continues to consume a larger share of corporate budgets, the ability to distinguish between legitimate traffic and technical manipulation will remain a critical competency for marketing leaders.








