In an era where digital acquisition costs are under constant scrutiny, Raiffeisen Bank, one of Russia’s leading financial institutions, has successfully identified and mitigated a sophisticated form of affiliate marketing fraud that was siphoning marketing budgets and distorting performance metrics. The investigation, conducted in collaboration with the data analytics firm OWOX BI, revealed that certain Cost Per Action (CPA) affiliates were utilizing deceptive browser extensions to hijack attribution and claim credit for organic and paid search conversions. By implementing a high-granularity data pipeline and transitioning to cloud-based processing, the bank was able to isolate fraudulent patterns, terminate relationships with dishonest partners, and reallocate its marketing spend toward more effective channels.
The Genesis of the Investigation: Anomaly Detection in Affiliate Performance
The initiative began when the marketing department at Raiffeisen Bank noticed a troubling discrepancy in their performance reports. Despite a significant increase in the costs associated with affiliate traffic, the overall revenue generated from online applications remained stagnant. In a healthy marketing ecosystem, an increase in CPA expenditure typically correlates with a rise in customer acquisition; however, the bank’s data suggested that they were paying more for the same volume of business.
Further investigation into user behavior on the bank’s website revealed a secondary, more technical anomaly. Analysts observed that a subset of customers experienced abrupt "session breaks" while in the middle of filling out application forms for credit cards and loans. Under normal circumstances, a user session should remain continuous as they navigate the checkout or application process. The presence of these breaks suggested that the session was being artificially terminated and restarted, often with a different traffic source value assigned to the second session.
Raiffeisen’s marketing specialists hypothesized that some affiliates were using "cookie stuffing" or "attribution hijacking" techniques. The suspicion was centered on malicious browser extensions that users might have installed for legitimate purposes, such as finding discounts or managing loyalty points. These extensions were suspected of monitoring the user’s URL and, upon detecting that the user was on a Raiffeisen checkout page, triggering a pop-up window with a generic discount offer. If the user interacted with this pop-up, the extension would overwrite the existing traffic source data—such as "Organic Search" or "Paid Search (CPC)"—with the affiliate’s own tracking ID, effectively "stealing" the commission for a sale that was already in progress.
Chronology of the Technical Response
To prove this hypothesis, the bank required a level of data granularity that surpassed the capabilities of standard web analytics tools. The project unfolded in several distinct phases, moving from data collection to advanced cloud processing.
Phase 1: Identifying the Limitations of Standard Analytics
Raiffeisen Bank utilized the standard version of Google Analytics (GA), which, while powerful, presented two significant hurdles for this specific investigation. First, the standard version often employs data sampling for high-traffic sites, which can obscure the minute-by-minute actions of individual users. Second, GA does not natively provide the precise, hit-level timestamps required to track the sequence of actions across session breaks in real-time.

Phase 2: Implementing the OWOX BI Pipeline
The bank partnered with OWOX BI to bypass these limitations. They established a data pipeline that streamed raw, unsampled data directly from the Raiffeisen website into Google BigQuery. This move was critical for security and compliance, as BigQuery meets the rigorous international standards required by financial institutions. This streaming solution allowed the bank to capture every user "hit" (page view or event) with an actual timestamp, enabling the reconstruction of the exact user journey.
Phase 3: Data Processing and Hypothesis Testing
With the raw data residing in a cloud warehouse, the analysts could now perform complex SQL queries to identify fraudulent patterns. They focused on isolating instances where a user’s session ended and a new one began on the same page within a window of less than 60 seconds. By comparing the traffic source of the first session with that of the second, they could see exactly which affiliates were overriding original sources like "Google Organic" or "Brand CPC."
Analyzing the Mechanics of Attribution Hijacking
The fraudulent mechanism uncovered by the bank is a growing concern in the digital advertising industry. It relies on the "Last-Click" attribution model, which is still the default for many CPA networks. In this model, the last touchpoint the user interacts with before a conversion receives 100% of the credit.
The fraudulent affiliates exploited this by injecting themselves into the very end of the funnel. When a user was already committed to a purchase, the browser extension would trigger a "synthetic" click. To the bank’s analytics system, it appeared as if the user had left the site and returned via an affiliate link, when in reality, the user had never intended to leave the application process. This not only resulted in the bank paying unnecessary commissions but also created a poor user experience, as the session break could occasionally lead to data loss in the application form, causing user frustration.
Supporting Data and Findings
The data gathered through Google BigQuery provided the "smoking gun" needed to take action. The reports generated by the OWOX BI team highlighted several key metrics:
- Transaction Robbery Rate: The analysts identified specific affiliates who had a disproportionately high number of transactions where the source changed from "Organic" or "CPC" to "Affiliate" within a one-minute window.
- Channel Displacement: The data revealed that organic search and paid search were the primary "victims" of this fraud. These were channels the bank had already paid for or earned through SEO, yet the affiliate was claiming the final commission.
- Time-to-Conversion Anomaly: In legitimate affiliate marketing, there is usually a reasonable gap between the initial click and the final conversion. The fraudulent sessions showed a "time-to-conversion" from the new source of mere seconds, a physical impossibility for a human navigating a complex banking form.
By importing this data into pivot tables and visualizations, Raiffeisen’s marketing team could clearly see which partners were acting in bad faith. The analysis showed that two specific affiliate partners were responsible for a significant portion of the suspicious activity.
Official Responses and Strategic Implications
Following the discovery, Raiffeisen Bank took immediate steps to protect its marketing budget. The bank terminated its contracts with the two identified dishonest partners. This decision was not merely about recovering lost funds but about ensuring the integrity of their entire marketing ecosystem.

Dmitriy Berezin, Head of Online Sales at Raiffeisen Bank, emphasized the importance of transparency in digital partnerships. He noted that the ability to track the full sequence of user actions allowed the bank to move from suspicion to evidence-based decision-making. By eliminating these fraudulent actors, the bank was able to optimize its advertising budget, ensuring that commissions were only paid to partners who actually contributed to the growth of the customer base.
Victoriia Pashchenko, a Web Analyst at OWOX BI who worked closely on the project, highlighted that this case underscores the necessity of owning one’s raw data. Without the transition to a BigQuery-based environment, the bank would have remained blind to the subtle session-level manipulations occurring at the browser level.
Broader Impact on the Financial Services Sector
The Raiffeisen case serves as a warning for the broader financial services industry, where high customer lifetime value (CLV) often leads to high CPA payouts, making the sector an attractive target for sophisticated fraudsters. As banks continue to shift their acquisition strategies online, the "AdTech Tax"—the portion of the budget lost to fraud, middlemen, and technical inefficiencies—becomes a critical metric for CFOs and CMOs alike.
Industry experts suggest that this incident will likely accelerate the adoption of more robust attribution models. Moving away from "Last-Click" to "Data-Driven" or "Multi-Touch" attribution makes it much harder for a single fraudulent event at the end of the funnel to claim the entirety of the commission. Furthermore, it highlights the need for banks to implement server-side tracking and more secure cookie handling to prevent third-party extensions from tampering with session data.
Conclusion: The Future of Data-Driven Integrity
The successful resolution of this challenge at Raiffeisen Bank demonstrates that the battle against digital fraud is increasingly a battle of data sophistication. By leveraging tools like Google BigQuery and OWOX BI, the bank transformed its analytics from a simple reporting tool into a powerful investigative asset.
The project concluded with the development of an automated monitoring report. This system now continuously audits affiliate traffic, flagging any recurring patterns of session breaks or source substitutions in real-time. This proactive approach ensures that Raiffeisen Bank can maintain a clean marketing funnel, ensuring that every ruble of their marketing budget is spent on genuine customer engagement rather than rewarding deceptive technical maneuvers. As digital fraud continues to evolve, the lessons learned by Raiffeisen provide a blueprint for other institutions looking to safeguard their digital investments through transparency and advanced analytics.







