Tobias Reithmeier

Blog

CPA Over CPI: Fraud Doesn't Vanish, It Moves Down the Funnel

A warning aimed at finance app marketers is making the rounds on LinkedIn, skewering a widespread belief: "We run CPA campaigns. We're safe from fraud." The warning is justified - and at the same time it is a case study in how to read vendor content. Both angles deserve a closer look, because the mechanics apply to anyone responsible for paid user acquisition.

Why the billing model doesn't stop fraud, it just redirects it

The logic behind the myth sounds plausible at first: if you no longer pay per install (CPI) but per completed action (CPA) - registration, account opening, first purchase - you only pay for "real" users. Fake installs earn nothing.

The problem: fraudsters don't optimize for installs, they optimize for whatever event gets paid. Move the payment threshold deeper into the funnel and the fraud simply moves with it. Install fraud becomes registration fraud; fake downloads become fake account openings. AppsFlyer itself does the math on why this is even more lucrative for the other side: a registration pays out up to around 4.58 dollars, a purchase around 40 dollars, a subscription up to 87 dollars - a multiple of what a simple fake install ever earned. The attack surface didn't shrink. It moved to where the money is.

What fake users look like today

The days when bots gave up after the download are over. Device farms and behavior-mimicking bots now complete entire multi-step onboarding flows: open the app, confirm the e-mail, fill in forms at human speed, pause realistically between steps. Fraud analysts describe how such scripts deliberately replicate genuine user behavior to pass plausibility checks.

In finance there is a second layer on top: synthetic identities. Real and invented personal data are combined into a new, creditworthy-looking identity that can even survive a know-your-customer (KYC) check. The Federal Reserve Bank of Boston puts the damage from synthetic identity fraud in the billions, and the US central bank runs a dedicated initiative including a mitigation toolkit for banks. An important distinction: at its core this is a fraud prevention and compliance problem, not a marketing problem - even though both types of fraud attack the same onboarding funnel.

The quiet fraud: attribution instead of fabrication

Alongside fabricated users there is a second, quieter category that needs no bots at all: attribution fraud. Not a single fake user is created - real, mostly organic users are relabeled as paid conversions.

  • Click flooding: Fraudsters fire massive volumes of fake ad clicks in the background, without the user ever seeing an ad. Purely probabilistically, some of those clicks land on people who would have installed the app anyway - and the attribution system credits the conversion to the "click".
  • Install hijacking: It gets more targeted when malware on the device detects the start of a download and fires a fake click at the last second to claim the attribution.

One way to detect this is the distribution of click-to-install time (CTIT): legitimate campaigns show a natural decay curve, click flooding shows a flat random distribution. But the most useful alarm signal is a different one, and it sits in every dashboard: if non-organic installs climb without a budget increase while organic holds flat or drops, you are very likely buying users you already had.

Why banking is the prime target

That finance apps are the preferred target is not a coincidence but simple economics. First, no other vertical pays premiums this high per conversion - three-digit CPAs for an opened brokerage account are not unusual. As early as the first half of 2020, an AppsFlyer report found that of 1.6 billion dollars in global install fraud exposure, around 630 million fell on finance apps alone.

Second, for banks the damage doesn't end with wasted ad budget. A fraudulently activated account can collect welcome bonuses, serve as a money mule account for laundering, or be used later for credit fraud. Every fake activation has a direct financial and regulatory price - which is what separates banking from a game where a fake user "only" dilutes the metrics.

What actually protects you - and what such warnings tend to omit

The recommendations in circulation are technically sound: validate conversion events server-side instead of trusting the client, check post-install user behavior for plausibility, use incrementality measurement as an early-warning system against attribution fraud. In short: treat every paid conversion with the same scrutiny as a financial transaction.

But the list is incomplete, and the omission is systematic. The LinkedIn post in question links - via a short URL carrying influencer campaign parameters - to a blog article by AppsFlyer, a vendor that sells exactly the measurement tools being recommended. That doesn't make the analysis wrong, but it makes it selective. Everything that isn't a product is missing:

  1. Contractual levers: Payment holds and clawback clauses towards ad networks shift the fraud risk to where it belongs - the supplier of the traffic.
  2. Network curation: A few vetted partners instead of long-tail networks often reduce the attack surface more than any additional tool.
  3. Organization: Marketing and fraud teams need to see the same data. As long as attribution lives with marketing and KYC with compliance, the fraud falls exactly into the gap between them.
  4. Healthy skepticism towards the measurer: Measurement providers have conflicts of interest too - part of the fraud demonstrably slips past standard MMP detection, and they get paid inside an ecosystem that profits from high measured conversions.

So the core thesis of the post holds: CPA is not a shield, just a relocation of the target. Drawing the right conclusion means combining measurement with contracts and organization - and reading warnings that happen to end in the sender's product catalog with the same skepticism you would apply to a campaign that performed a little too well.

Sources