In an era where digital transformation dictates the competitive landscape of the banking sector, the integrity of marketing data has become as critical as the security of financial transactions. Raiffeisen Bank, one of Russia’s leading financial institutions, recently faced a sophisticated challenge that threatened both its marketing efficiency and its customer experience. By partnering with the data analytics firm OWOX BI, the bank successfully identified and dismantled a fraudulent scheme perpetrated by bad actors within its Cost Per Action (CPA) affiliate network. This investigation not only saved the institution significant marketing expenditure but also highlighted a growing vulnerability in the digital advertising ecosystem: the manipulation of traffic attribution through browser-based exploits.
The Genesis of the Investigation: Identifying Anomalies in Acquisition Costs
The project began when the internal marketing team at Raiffeisen Bank noticed a troubling divergence in their performance metrics. Despite a steady or stagnant revenue stream from online acquisitions, the costs associated with affiliate traffic were rising at an abnormal rate. In the high-stakes world of digital banking, where the Cost Per Acquisition (CPA) for a new credit card or loan application is meticulously calculated, such a discrepancy is a red flag for systemic inefficiency or foul play.
Simultaneously, the bank’s user experience (UX) researchers identified a technical glitch occurring during the customer journey. A significant number of users were experiencing "session breaks" while filling out application forms on the bank’s website. These breaks occurred when a user’s active session would abruptly end and a new one would begin, often resulting in the loss of progress or the need to re-authenticate. Initial assessments suggested a technical bug, but the marketing team suspected a more calculated cause: traffic source substitution.
The hypothesis formulated by Raiffeisen’s Head of Online Sales, Dmitriy Berezin, suggested that certain CPA affiliates were using deceptive software to hijack the attribution of successful conversions. The suspicion centered on browser extensions—tools often downloaded by consumers to find discounts or coupons. These extensions were allegedly programmed to detect when a user navigated to a bank’s checkout or application page. At that moment, the extension would trigger a popup window offering a nominal discount. If a user interacted with this popup, the extension would execute a script to overwrite the original traffic source data in the user’s cookies, replacing it with the affiliate’s own tracking ID. Consequently, when the user completed the application, the bank’s analytics system would credit the affiliate for a "new" lead that had actually originated from organic search or paid search (CPC) campaigns.
The Technical Infrastructure: Moving Beyond Standard Analytics
To validate this hypothesis, Raiffeisen Bank required a level of data granularity that standard web analytics tools often struggle to provide. At the time, the bank utilized the standard version of Google Analytics. While robust for general reporting, the standard version carries inherent limitations for forensic data analysis, including data sampling and a lack of access to raw, hit-level data with precise timestamps.
To overcome these hurdles, the bank engaged OWOX BI. The primary objective was to move away from sampled data and establish a "Single Source of Truth" within a high-security environment. The chosen solution involved the implementation of the OWOX BI Pipeline to stream raw, unsampled data from the bank’s website directly into Google BigQuery.
Google BigQuery was selected not only for its computational power but also because it adheres to the stringent security and compliance standards required by the Russian financial sector. By using the OWOX BI Pipeline, the analysts were able to collect data in near real-time, capturing the exact timestamp of every "hit" (interaction). This capability was vital; it allowed the team to reconstruct the exact sequence of user actions across sessions, providing a "forensic timeline" of how and when a traffic source was altered.

Chronology of the Data Analysis Process
The investigation was structured into three distinct phases: data collection, filtering, and reporting. Each step was designed to isolate the specific behavior of fraudulent browser extensions.
Phase 1: Raw Data Collection and Integration
The initial phase focused on establishing the data flow. By bypassing the limitations of Google Analytics Standard, the team collected raw data that included unique Client IDs, session IDs, and the specific UTM parameters (source, medium, campaign) associated with each interaction. This allowed the team to track a user who might have arrived via a Google search (Organic) but ended their journey being attributed to an affiliate (CPA).
Phase 2: Filtering for Fraudulent Patterns
The analysts defined a specific set of criteria to identify "source overwriting." They looked for instances where a user had two distinct sessions recorded on the same page within a very narrow timeframe—specifically, less than 60 seconds.
The logic was as follows:
- A user enters the application form via a legitimate source (e.g., Organic Search).
- The browser extension triggers a popup.
- The user clicks the popup, causing the page to refresh or a tracking link to fire.
- A new session is instantly created with the affiliate’s source data.
- The time elapsed between the end of the first session and the start of the second is negligible (often 1–5 seconds).
By querying the BigQuery database for these specific conditions, the team could filter out legitimate multi-session users and isolate those whose sessions were artificially interrupted by third-party scripts.
Phase 3: Attribution Theft Visualization
Once the data was filtered, it was exported to Google Sheets via an OWOX BI add-on to create digestible reports for the marketing department. These reports visualized the "robbery" of transactions. The data clearly showed which channels were losing credit—primarily organic search and the bank’s own paid search (CPC) efforts—and which specific affiliate IDs were the recipients of this stolen credit.
Findings and Financial Impact
The results of the analysis were definitive. The data revealed that a substantial percentage of transactions attributed to certain CPA partners were, in fact, "stolen" from other channels. These partners were not generating new demand; they were simply inserting themselves into the final stage of an existing customer journey to claim a commission.
For Raiffeisen Bank, the implications were both operational and financial. The "session breaks" that had been frustrating customers were confirmed to be side effects of the fraudulent scripts running in the background. More importantly, the bank identified two specific affiliate partners who were consistently acting in bad faith.

By terminating the contracts with these dishonest webmasters, Raiffeisen Bank achieved an immediate optimization of its marketing budget. The funds that were previously being siphoned away in fraudulent commissions were reallocated to high-performing, legitimate channels. This correction led to a measurable increase in the Return on Ad Spend (ROAS) and restored the integrity of the bank’s performance metrics.
Broader Implications for the Digital Banking Sector
The Raiffeisen case serves as a cautionary tale for the broader financial services industry. As banks increasingly rely on affiliate networks to drive customer acquisition, the risk of "attribution fraud" or "cookie stuffing" grows. This type of fraud is particularly insidious because it does not appear as a typical cyberattack; rather, it looks like successful marketing performance on the surface.
Industry experts suggest that this case highlights three critical takeaways for digital marketers:
- The Limitations of Last-Click Attribution: Relying solely on the "last click" to attribute a sale makes a company vulnerable to source overwriting. Fraudulent extensions are designed specifically to exploit last-click logic by ensuring they are the final touchpoint before a conversion.
- The Necessity of Raw Data: Without hit-level data and precise timestamps, it is nearly impossible to detect the sub-60-second session swaps that characterize this type of fraud. Standard analytics platforms often "smooth out" these anomalies, hiding the evidence of manipulation.
- The Role of Security in Marketing: Digital marketing is no longer just about creative and placement; it is about technical security. Banks must view their tracking scripts and cookie data with the same level of scrutiny they apply to their transaction ledgers.
Official Responses and Strategic Shifts
Dmitriy Berezin, Head of Online Sales at Raiffeisen Bank, emphasized that the project was about more than just saving money; it was about data-driven transparency. "By gaining access to unsampled data, we were able to see the true path our customers take," Berezin noted in his review of the project. "This allowed us to stop cooperating with partners who were not adding value but were instead inflating our costs through deceptive practices."
Victoriia Pashchenko, a Web Analyst at OWOX BI who worked closely on the project, highlighted the technical necessity of the collaboration. "In the current digital climate, being able to track the sequence of user actions across sessions in a single, unsampled report is the only way to stay ahead of sophisticated fraud," she stated.
Conclusion
The successful identification of affiliate fraud at Raiffeisen Bank marks a significant victory for data integrity in the Russian banking sector. By utilizing the OWOX BI Pipeline and Google BigQuery, the bank moved beyond superficial metrics to uncover a hidden layer of technical manipulation. As affiliate marketing continues to evolve, the ability to conduct deep-dive forensic analysis of traffic sources will remain a vital tool for institutions looking to protect their budgets and their customers’ digital journeys. This case study stands as a blueprint for other organizations facing the dual challenge of rising acquisition costs and unexplained technical anomalies in their conversion funnels.








