Unmasking Digital Ad Fraud: How Raiffeisen Bank Identified and Eliminated Affiliate Attribution Manipulation

In an increasingly digitized financial landscape, the integrity of marketing data has become as critical as the security of the banking transactions themselves. Raiffeisen Bank’s Russian division recently encountered a sophisticated challenge that highlights the vulnerabilities inherent in the Cost Per Action (CPA) affiliate marketing model. The bank’s marketing department observed a troubling trend: while the expenditure on affiliate traffic was climbing at an abnormal rate, the corresponding revenue remained stagnant. This discrepancy suggested that the bank was not paying for new customers, but rather for "stolen" attributions—a practice where affiliates claim credit for traffic that would have converted through organic or other paid channels regardless of their intervention.

To address this, Raiffeisen Bank partnered with OWOX BI to conduct a deep-dive forensic analysis of their web traffic. The investigation revealed a systematic manipulation of traffic source data, orchestrated through browser extensions that interfered with the user experience at the most critical point of the conversion funnel: the checkout page.

The Mechanics of Attribution Hijacking

The fraudulent scheme suspected by Raiffeisen’s team involved a technique often referred to as "cookie stuffing" or "attribution rewriting." The process typically begins with a consumer installing a seemingly benign browser extension, such as a coupon aggregator or a discount notifier. These extensions remain dormant until the user navigates to a specific URL, such as a bank’s credit card application form.

Once the user begins the checkout or application process, the extension triggers a pop-up window offering a discount or a promotional code. If the user interacts with this pop-up, the extension executes a script that refreshes the session or redirects the user through an affiliate link so rapidly that it often goes unnoticed. This action overwrites the original traffic source—whether it was an organic search, a direct visit, or a paid search ad (CPC)—with the affiliate’s tracking ID. Consequently, when the user completes the application, the bank’s analytics system attributes the high-value conversion to the affiliate, who then receives a commission for a sale they did not actually generate.

For Raiffeisen, this resulted in "session breaks." Customers who were in the middle of filling out sensitive financial forms experienced sudden interruptions, which not only skewed marketing data but also created a friction-filled user experience that threatened to lower overall conversion rates.

Chronology of the Investigation

The investigation was structured into three distinct phases: data infrastructure overhaul, forensic filtering, and stakeholder reporting.

Tackling Fraud in CPA Networks with Analytics - Online Behavior

The initial phase addressed a fundamental limitation in the bank’s existing setup. Raiffeisen was utilizing the standard version of Google Analytics, which, while robust for general reporting, possesses limitations regarding data sampling and hit-level granularity. In the standard version, high-traffic sites often see sampled data, which can obscure the minute-by-minute actions of individual users. To bypass this, the OWOX BI team implemented a data pipeline that streamed raw, unsampled data from the bank’s website directly into Google BigQuery.

This move to Google BigQuery was essential for two reasons. First, it allowed for the collection of actual timestamps for every "hit" (every interaction a user has with the site). Second, it ensured compliance with the high security and privacy standards required by the banking industry. With raw data available in near real-time, analysts could reconstruct the exact sequence of user actions across sessions.

Technical Analysis and Data Processing

Once the raw data was flowing into the cloud warehouse, the analysts began the process of identifying "fraudulent signatures." They focused on a specific behavioral pattern: users who had a session interrupted and a new session started on the same page within a very short timeframe.

The analysts established a set of criteria to filter the data. They looked for instances where:

  1. A user was active on an application page.
  2. The session was terminated abruptly.
  3. A new session was initiated by the same user on the exact same URL.
  4. The time elapsed between the end of the first session and the start of the second was less than 60 seconds.
  5. The traffic source for the second session was an affiliate (CPA) channel, while the first session was attributed to a different source, such as organic search or a paid Google ad.

By writing SQL queries in BigQuery, the team was able to isolate these occurrences. For example, they identified a segment of users who initially arrived via a "promo" page or a CPC campaign but finished their journey as "affiliate" conversions. The data showed that the "theft" of the attribution usually happened within seconds of the user reaching the final stages of the application form.

Quantifying the Impact

The results of the data processing were exported to Google Sheets via an automated add-on to create accessible reports for the marketing team. These reports provided a clear view of which affiliate partners were acting in bad faith.

The findings were stark. The reports identified specific affiliate IDs that were consistently associated with rewritten traffic sources. By comparing the "before" and "after" traffic source values, Raiffeisen could see exactly which channels were being cannibalized. Organic search and CPC (Cost Per Click) campaigns were the most frequent victims. In these cases, Raiffeisen was effectively paying twice: once for the original click and a second time for the fraudulent affiliate commission.

Tackling Fraud in CPA Networks with Analytics - Online Behavior

The data allowed the bank to visualize the scale of the problem. A pivot table demonstrated that a significant percentage of the transactions attributed to certain CPA networks were actually "robbed" from other channels. With this empirical evidence, the bank was no longer operating on suspicion; they had the transaction IDs and timestamps to prove that specific partners were using predatory scripts to claim unearned commissions.

Strategic Response and Industry Implications

Armed with this data, Raiffeisen Bank took immediate corrective action. The bank terminated its relationship with two major affiliate partners who were identified as the primary offenders. By removing these dishonest actors from their marketing ecosystem, the bank was able to immediately stabilize its acquisition costs and reallocate that budget toward more transparent and effective channels.

Beyond the immediate cost savings, the project provided Raiffeisen with a permanent monitoring tool. The bank now has an automated system that flags suspicious session breaks in real-time, allowing them to audit affiliate performance continuously.

This case serves as a significant benchmark for the broader digital marketing industry, particularly in high-stakes sectors like banking and insurance. Ad fraud is a multi-billion dollar global issue. According to industry estimates, digital ad fraud costs advertisers over $80 billion annually, with a substantial portion of that attributed to sophisticated attribution manipulation.

Broader Implications for Digital Marketing

The Raiffeisen case highlights a growing need for "Marketing Provenance"—the ability to verify the entire lifecycle of a customer’s journey without gaps in data. As browser privacy settings become stricter and third-party cookies are phased out, the opportunity for malicious actors to exploit gaps in attribution logic may actually increase.

For Chief Marketing Officers (CMOs), the takeaways are clear:

  1. Raw Data is Non-Negotiable: Relying on the aggregated, sampled data provided by standard analytics platforms is no longer sufficient for high-spend environments. Access to hit-level data (raw logs) is necessary for forensic auditing.
  2. The "Last-Click" Vulnerability: The traditional "last-click" attribution model is particularly susceptible to this type of fraud. Moving toward multi-touch attribution (MTA) or data-driven attribution models can help mitigate the incentive for affiliates to hijack the final step of the funnel.
  3. Vendor Accountability: Affiliate contracts should include clauses that allow for audits based on session-integrity data. The ability to prove that a session was forced to refresh can be used as a legal and financial basis for withholding payment to fraudulent partners.

Conclusion

The collaboration between Dmitriy Berezin of Raiffeisen Bank and Victoriia Pashchenko of OWOX BI demonstrates that while ad fraud is becoming more sophisticated, the tools to combat it are also evolving. By leveraging cloud-based big data tools and rigorous analytical filtering, Raiffeisen transitioned from a position of vulnerability to one of informed control. The bank not only protected its marketing budget but also ensured a smoother, more secure application process for its customers. In the competitive world of online banking, where customer acquisition costs are high and margins are scrutinized, the ability to distinguish between genuine growth and fraudulent inflation is a critical competitive advantage.

Related Posts

OpenAI Launches GPT-6 Astra as Frontier Model Redefining Autonomous Computer Use and Cybersecurity

OpenAI has officially announced the release of GPT-6 Astra, its latest and most sophisticated frontier model, marking a significant escalation in the ongoing artificial intelligence arms race. The launch comes…

Data-Driven Progress in Global Health Analyzing the 2017 Goalkeepers Report and Trends in Maternal Mortality

The Bill and Melinda Gates Foundation released its inaugural Goalkeepers report in 2017, marking a significant milestone in the global effort to track and accelerate progress toward the United Nations…

You Missed

Unmasking Digital Ad Fraud: How Raiffeisen Bank Identified and Eliminated Affiliate Attribution Manipulation

  • By
  • September 5, 2026
  • 1 views
Unmasking Digital Ad Fraud: How Raiffeisen Bank Identified and Eliminated Affiliate Attribution Manipulation

The Power of Performance: Unpacking the Nuances of Affiliate Marketing for Business Growth

  • By
  • September 5, 2026
  • 1 views
The Power of Performance: Unpacking the Nuances of Affiliate Marketing for Business Growth

Google Ads Tests Serving Search Ads With Restrictive Match Types In AI Mode

  • By
  • September 5, 2026
  • 1 views
Google Ads Tests Serving Search Ads With Restrictive Match Types In AI Mode

The Platypus Effect: How Reddit’s Unique Blend of Search and Social is Redefining Digital Advertising

  • By
  • September 5, 2026
  • 1 views
The Platypus Effect: How Reddit’s Unique Blend of Search and Social is Redefining Digital Advertising

HubSpot AEO and Scrunch Emerge as Key Players in Evolving AI Search Landscape

  • By
  • September 5, 2026
  • 1 views
HubSpot AEO and Scrunch Emerge as Key Players in Evolving AI Search Landscape

The Nuanced Approach to Content Pruning: Experts Urge Contextual Strategy and Rigorous Testing in Evolving SEO Landscape.

  • By
  • September 5, 2026
  • 1 views
The Nuanced Approach to Content Pruning: Experts Urge Contextual Strategy and Rigorous Testing in Evolving SEO Landscape.