In an era where digital acquisition costs are under constant scrutiny, Raiffeisen Bank, one of Russia’s leading financial institutions, recently undertook a comprehensive forensic analysis of its affiliate marketing ecosystem. The initiative, led by Dmitriy Berezin, Head of Online Sales at Raiffeisen Bank, in collaboration with Victoriia Pashchenko, a senior web analyst at OWOX BI, was prompted by a series of fiscal anomalies within the bank’s Cost Per Action (CPA) channels. Despite a significant surge in affiliate-related expenditures, the bank observed that its bottom-line revenue remained stagnant. This disconnect suggested a systemic inefficiency or, more concerningly, a sophisticated form of attribution fraud known as "cookie stuffing" or "source substitution."
The investigation revealed that certain affiliate partners were utilizing malicious browser extensions to hijack user sessions during the checkout process. By identifying these fraudulent patterns through granular data processing in Google BigQuery, Raiffeisen Bank was able to terminate relationships with dishonest webmasters, safeguard its organic and paid search channels, and reallocate its marketing budget toward more transparent and high-performing avenues.
The Anatomy of Attribution Hijacking in the Banking Sector
The core of the challenge lay in the vulnerability of the "last-click" attribution model, which is a standard metric used by many financial institutions to reward affiliate partners. Under this model, the last source a user clicks on before completing a transaction receives 100% of the commission. Raiffeisen’s marketing team suspected that certain affiliates were exploiting this by using browser-based tools to intercede at the final stage of the customer journey.
The suspected mechanism was as follows: a user would navigate to the Raiffeisen website through an organic search or a paid CPC (Cost Per Click) advertisement. While the user was filling out a loan or credit card application, a browser extension—often marketed to consumers as a "coupon finder" or "discount notifier"—would trigger a pop-up. This pop-up would offer a nominal discount or a special offer. If the user clicked the link within this pop-up, the extension would instantly refresh the session or rewrite the browser’s cookies, substituting the original traffic source (such as Google Organic or a paid search ad) with the affiliate’s own tracking ID.
Consequently, when the user submitted the application seconds later, the bank’s internal systems recorded the affiliate as the source of the lead. This resulted in the bank paying a CPA commission for a customer they had already acquired through other, often expensive, marketing channels.
A Chronological Overview of the Forensic Investigation
The project followed a structured timeline, beginning with the identification of symptoms and culminating in the execution of a new, fraud-resistant marketing strategy.
Phase 1: Detection of Anomalies
In early 2018, Raiffeisen’s internal audits showed a sharp rise in CPA costs. However, the conversion rate from these affiliates did not correlate with a rise in new-to-bank customers. Simultaneously, the technical team noted an unusual number of "session breaks" occurring specifically on high-value application pages.

Phase 2: Technical Integration and Data Collection
To move beyond the limitations of standard web analytics, the bank partnered with OWOX BI. The goal was to bypass the sampling issues inherent in the standard version of Google Analytics. By implementing the OWOX BI Pipeline, the team began streaming raw, unsampled hit-level data from the bank’s website directly into Google BigQuery. This allowed for the collection of precise timestamps for every user interaction, which was critical for proving the "last-minute" source substitution.
Phase 3: Analytical Processing and Hypothesis Testing
Analysts focused on a specific subset of data: users who experienced a session change while remaining on the same URL. By querying the raw data in BigQuery, they looked for instances where a second session started within 60 seconds of a first session on the same page, with the second session carrying an affiliate source tag.
Phase 4: Reporting and Partner Confrontation
The findings were compiled into a pivot table that explicitly named the affiliate IDs responsible for the hijacked sessions. This report also quantified the "stolen" transactions from other channels like Organic and CPC. Armed with this data, the bank’s procurement and marketing departments moved to terminate contracts with the identified parties.
Technical Methodology: Leveraging Google BigQuery for Fraud Detection
The technical complexity of the fraud required a sophisticated response. Standard Google Analytics (GA) often aggregates data, making it difficult to see the exact second a session is terminated and a new one begins. Furthermore, GA’s standard reporting does not easily allow for the cross-referencing of hit-level timestamps across different sessions for a single user in a unified view.
To solve this, the OWOX BI team utilized a three-step data processing framework:
1. Raw Data Ingestion
By streaming data to Google BigQuery, the bank gained access to the fullVisitorId, visitNumber, visitStartTime, and the hit.time. This granularity was essential because it allowed the analysts to reconstruct the exact sequence of events. For instance, they could identify a user who landed via an organic search at 10:00:00 AM, reached the application page at 10:02:00 AM, and then suddenly had their source changed to an affiliate at 10:02:45 AM without ever leaving the page.
2. Filtering for Fraudulent Patterns
The analysts established specific criteria to isolate fraudulent behavior. They filtered for:
- Users with more than one session within a single day.
- Sessions where the "Previous Page" and "Current Page" were identical at the moment of a session restart.
- A time delta of less than 60 seconds between the end of the original session and the start of the new affiliate-tagged session.
3. Data Visualization and Export
The results were exported from BigQuery into Google Sheets using the OWOX BI BigQuery Reports Add-on. This created a dynamic environment where marketing managers could see the real-time impact of affiliate fraud. The report highlighted not just the lost revenue, but also the specific channels that were being cannibalized.

Supporting Data and Financial Impact
The investigation yielded startling insights into the scale of the attribution theft. According to the data models generated during the study, a significant percentage of transactions previously attributed to CPA networks were actually the result of organic and paid search efforts.
In the sample data analyzed, the bank found that:
- Source Substitution Frequency: Hundreds of transactions per month were being redirected by just a handful of dishonest affiliates.
- Channel Cannibalization: Approximately 40% of the hijacked transactions originally belonged to the "Organic Search" channel, while 35% were stolen from "Paid Search (CPC)."
- Cost Savings: By terminating the top two most "dishonest" partners, Raiffeisen Bank was able to immediately reduce its CPA budget by a significant margin without experiencing a decrease in actual customer acquisitions.
These findings underscore a broader trend in the digital advertising industry. Research suggests that ad fraud costs the global economy tens of billions of dollars annually. For financial institutions like Raiffeisen, where the "Customer Acquisition Cost" (CAC) is high, the impact of such fraud is particularly damaging to the Return on Ad Spend (ROAS).
Industry Implications and Future Outlook
The Raiffeisen Bank case serves as a landmark example of how data transparency can shift the power balance between advertisers and affiliate networks. Traditionally, CPA networks have operated as "black boxes," providing little transparency into how their webmasters drive traffic. By taking ownership of their raw data, Raiffeisen has set a precedent for other financial institutions to move toward a "Trust but Verify" model.
Industry experts suggest that this type of fraud is not limited to the banking sector but is rampant in e-commerce, travel, and any industry with high commission structures. The use of browser extensions as a vehicle for fraud is particularly difficult to police, as these extensions are installed by the users themselves, often for legitimate purposes like price comparison.
Broader Impact on Marketing Strategy
As a result of this project, Raiffeisen Bank has transitioned to a more robust attribution framework. The bank now monitors affiliate performance in near real-time, looking for "velocity spikes" or unusual session behavior that might indicate new forms of fraud. Furthermore, the bank is exploring multi-touch attribution (MTA) models that distribute credit across all touchpoints in a customer journey, thereby reducing the incentive for affiliates to hijack the "last click."
Final Analysis
The collaboration between Raiffeisen Bank and OWOX BI highlights a critical shift in the digital marketing landscape. As fraud techniques become more sophisticated, the tools used to combat them must be equally advanced. The ability to process "Big Data" in real-time is no longer a luxury for large corporations; it is a fundamental requirement for protecting marketing investments and ensuring the integrity of the digital ecosystem. By identifying and eliminating dishonest partners, Raiffeisen not only saved significant capital but also fostered a healthier, more competitive environment for its honest affiliate partners.








