Sari la conținut
Jurnalism fără lesă.

Caută o pagină sau un articol..

  • Investigații
  • The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism

    The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism
    For five months, we tracked over 100,000 ads displayed across 131 websites in Eastern Europe. After decoding the hidden mechanisms behind these ads, we uncovered a network of Russian companies. This investigation reveals what data is harvested from Romanians, who ends up receiving it, and why the ads shown on platforms with conspiratorial and extremist content are among the most valuable to this network.

    Adaugă-ne ca sursă în Google
    • This article is the result of a technical investigation into the code behind the ads running on Romanians’ computers. It builds upon previous investigations published by Snoop regarding the Russia-linked advertising network AdNow, which is used to steal Romanians’ data and promote online scams. The investigation was conducted in collaboration with journalists from across Eastern Europe.
    • We built custom software that allowed us to follow the Russian money flowing into Eastern European websites, including Romanian ones, over the past few months. We also monitored the methods used to harvest our data and route it to Novosibirsk, Russia.
    • Such databases serve purposes far beyond advertising: they can become tools for surveillance and behavioral manipulation when they end up in the hands of authoritarian states, warn international experts consulted by Snoop.
    • The analysis covered ads identified across 1,145 webpages belonging to 131 Eastern European websites. We tracked several online advertising companies with Russian origins, including AdNow, MGID, and AdsKeeper. We will publish our findings on the latter two in the next piece.

    What lies behind the ads you click

    By tracking the ads served on Facebook and Romanian websites such as RTV, Realitatea TV, romaniinostri[.]ro, desteptarea[.]ro, and hundreds of other platforms, we reveal how AdNow’s advertising infrastructure harvests the data of millions of Romanians.

    Screenshot from the website of România TV  

    AdNow ads appear at the bottom of articles and are not served through Google Ads or similar platforms, but via their own infrastructure. Some promise miracle cures, increased sexual potency, or get-rich-quick forex or crypto scams. In reality, once you see them, your data can end up in a network accessible by the Russian state.

    In some cases, the stakes go beyond mere data collection. Once profiled and targeted based on their interests or vulnerabilities, users are redirected to even more complex financial fraud scams. These scams have become increasingly sophisticated and harder to spot, a trend confirmed by both the annual reports of Romania’s National Cyber Security Directorate (DNSC) and international data from Interpol.

    In the case of AdNow, before the actual fraud even takes place, victims unwittingly transmit data to Russia regarding their psychological profiles, political leanings, and interest in conspiracies and astrology. Once a user who consumes conspiracy content clicks on an ad for a „miracle” diabetes cure, for instance, the attacker’s chances of success skyrocket.

    What we know so far

    In 2024 and 2025, we published two investigations on Snoop, The Russian Money Strategy and Tracking the Russian Advertising Money, which were the subject of President Nicușor Dan’s speeches in Copenhagen, Vienna, and in Le Monde. The President promised that he will soon release the report regarding the annulment of the winter 2024 presidential elections. Our investigations appear paraphrased in the indictment charging Călin Georgescu and Horațiu Potra with treason. The pieces were cited by the Financial Times, Bloomberg, Le Monde, and the London Review of Books in the context of national elections, within articles analyzing the risks posed by manipulation and disinformation networks to the democratic process.

    We kept digging into the same Russian actors behind AdNow, so we established a consortium of publications from Ukraine, the Czech Republic, Armenia, and Russia, alongside Finnish researchers specializing in open-source intelligence and online disinformation. Together, we monitored these Russians for five months while they monitored us.

    Through the series The Kremlin’s Digital Pirates, we aim to explain, step by step, the methods and tools we used, so readers can understand how such operations can be identified and documented. 

    Who actually gets your data 

    When you visit the website of the România TV news channel, which we previously revealed took money from AdNow between 2016 and 2020, you are greeted by a GDPR pop-up stating: ”We care about keeping your personal data confidential”. In the European Union, all websites collecting personal data must ask whether you consent to sharing it with their advertising partners – a list that can range from a few dozen to hundreds or even thousands of entities.

    The same notification also states that you can object to the use of your personal data based on the „legitimate interest” claimed by their business partners.

    At the time of our reporting, RTV listed 1,019 such partners. The notification states that you can either consent or decline to share your data. They will know what kind of person you are, which websites you browse, and what you buy online, all to serve you advertising tailored to your interests.

    Under European law, there is no „legitimate interest” (click for details).

    ”Legitimate interest” is one of the legal bases under which the GDPR may allow a company to process certain personal data without asking for the user’s consent.

    However, the company must demonstrate that it has a legitimate purpose, that processing the data is necessary to achieve that purpose, and that it does not override the individual’s rights and freedoms. For example, under certain conditions, legitimate interest may be relied upon for fraud prevention or service security.

    But it cannot be used as a blanket justification for any kind of data collection. 

    For cookies, pixels, fingerprinting, or other technologies that store information on a user’s device or access information from it, the general rule is that prior consent is required, as this is governed by specific legislation (ePrivacy), explains Bogdan Manolea of the Association for Technology and Internet (APTI). The exceptions are limited: the technology must be necessary for transmitting a communication or strictly necessary for providing a service explicitly requested by the user, under European and Romanian law.

    Cookies and other technologies used for advertising, profiling, or tracking users across websites clearly do not fall within these exceptions and require consent.

    There are some limited exceptions. For example, the French data protection authority, CNIL, considers that certain audience measurement tools may be exempt from consent requirements if they meet strict conditions: they are used exclusively for audience measurement, do not allow users to be tracked across websites, and the data is neither combined with other information nor shared with third parties.

    But refusing is pointless. RTV sells your data anyway. And it isn’t the only Romanian website doing so.

    How?

    Individual Profiling and User Vulnerability

    STEP 1. YOU VISIT THE WEBSITE

    Every user who visits sites like FilmeSiSeriale[.]ro, RomaniiNostri[.]ro, BotosaniNews[.]ro, JurnalulDeArges[.]ro, Realitatea TV, ZiarulArgesul[.]ro, or România TV is highly likely to encounter AdNow ads.

    Over the past decade, 79 Romanian publications have run AdNow ads and trackers. The largest platforms include national news networks like Antena3, B1TV, RTV, and Realitatea TV, as well as news portals such as OrangeSport and Puterea.

    Another category consists of local news websites, whose advertising budgets are razor-thin unless fueled by partnerships with politicians and local institutions. Examples include BZI, Lugojeanul, BotosaniNews, VoceaValcii, TVFOltenia, ExclusivGorj, DeBraila, and CarasOnline.

    However, the vast majority of publications that have collaborated or currently collaborate with AdNow are disinformation or clickbait sites, such as Stiri-Extreme[.]ro, Stiai-Ca[.]ro, PoateNuStiai[.]ro, Desteptarea[.]ro, and Efemeride[.]ro.

    These publications have generated daily traffic of millions of unique users, leaving them exposed to these data-harvesting and disinformation systems.

    Romanian websites with AdNow ads

    Users visiting websites that run AdNow ads, which we analyzed using our custom software, transmit data to Russian servers regardless of whether they give their consent.

    This is the list of entities to which the data of users entering the RTV website went or is going. Anyone can check the partners of an active site by adding at the end of the URL: /ads.txt. In some cases, publications may not update their list, and among the listed companies there might be former, not current, advertising partners.

    The RTV website, for example, had, during the period we ran the monitoring software, between 1,000 and 1,600 business partners potentially interested in the internet users visiting it. The list, published in the site’s ads.txt file, changed constantly.

    The presence of a company in RTV’s ads.txt list does not automatically mean that it collected or used our data for profiling, but that it can do so. Even against our will. For example, on February 26 and May 3, in two visits to the RTV site, although we refused data collection from the displayed GDPR notification, it went to 10 and respectively 17 different companies.

    The only effective safeguard remains the use of an ad blocker (click for details).

    An ad blocker is a browser extension that intercepts and blocks ads before they load. When we visit a publication’s website that has hundreds of advertising partners, we aren’t just exchanging data with the server hosting the article, but with hundreds of adtech companies about which we know absolutely nothing.

    Some advertising firms harvest sensitive data regarding users’ sexual orientation or religion, highly intimate health issues, or precise real-time location, and subsequently sell it to third parties.

    In Germany, the media outlet Interaktiv acquired highly precise adtech location data tracking German intelligence officers commuting to secret headquarters. Recently, several American soldiers were killed by Iranian forces after being identified using advertising data.

    Other times, ads come bundled with malware that can siphon users’ money. For instance, in one of the latest adtech scandals, Adform, a major global advertising player, began serving a malicious script capable of stealing cryptocurrency from users visiting websites hosting their ads.

    Several cybersecurity experts believe that the data generated by the adtech industry constitutes the greatest security vulnerability of our time.

    Any solutions? An ad blocker like uBlock Origin, AdBlock, or NoScript can secure personal data on your laptop. You can use browsers like Brave or DuckDuckGo, which feature built-in protection against malicious ads.

    In addition, you can use apps such as a VPN (virtual private network), which encrypts your internet traffic and can mask the location from which you are using your phone or computer.

    STEP 2. YOU ARE ASSIGNED A CODE

    To AdNow, at this stage of the data harvesting process, on a website hosting their ads, I don’t have a name. I am a code.

    Through this code, I tell them what kind of computer I have, along with dozens of technical details about my processor, browser, display, and more. This data is linked to that same unique code, which we can think of as a digital ID or a digital fingerprint.

    Here is my code: Ssp-9d8f214f-e1ae-d68c-5edf-5edf-cbfb0f915c

    STEP 3. THE CODE IS SENT ONWARD, EVEN IF YOU REFUSE

    The code that AdNow runs in my browser while I visit sites like Realitatea, RTV, or FilmeȘiSeriale[.]ro explicitly shows that, even if I refuse their transmission, my data is still sent to their servers.

    How we analyzed the ads and data transfers – Methodology (click for details)

    The code injected by the Russians into my browser is transferred from their servers in a cloaked format, meaning it is embedded within other visible code that can be captured and decoded.

    Our partners at CheckFirst, working within the Journalism Science Alliance project, captured the HTML code for every analyzed ad. They then Base64-decoded each HTML element, transforming the code from an obscured string of characters into a readable format. This allowed us to examine the Russian ads across multiple parameters.

    Below, you can see a sample of an ad as it enters our computers versus its decoded form:

    photo-slider visualization

    Eventually we analyzed HAR files, which log the network requests and responses between the computer’s browser and the contacted servers whenever a page loads. We were able to observe multiple pixel and click-tracking servers continuously routing data between our computers and the ad servers controlled by AdNow.

    What this means:

    Pixel tracking: tiny 1×1 pixel images, completely invisible to the user. When the browser downloads them (a fact recorded in the .har file), the AdNow server instantly knows that you opened the page, what screen resolution you have, and what device you are browsing from.

    Click tracking: any interaction or click intention sends a quick request to the servers, leaving a digital footprint with your browsing path.

    The observation of .har files can also be extracted and automated from the site har.fyi. These verifications allowed us to document the past presence of AdNow on sites like antena3[.]ro, bzi[.]ro, and publications from all over Europe through publicwww.com.

    The code generates a browser „fingerprint,” which helps identify specific machine parameters even if the user rejects or clears their cookies.

    STEP 4. THE CODE TRACKS YOU EVERYWHERE

    The code that is assigned to me runs on my computer on all the sites where this network displays its ads. It is useful for them to know what I do and when I visit websites on which they do not have ads, but on which AdNow tracking pixels still run.

    If I click on a news story about Bolojan, I tell them that Ssp-9d8f214f-e1ae-d68c-5edf-5edf-cbfb0f915c is interested in local politics. If I click on a news story about the war of Israel and the USA in Iran, I tell them that I am also interested in the international scene.

    The contract between AdNow and the Pravda publication in Serbia shows that partner sites must run tracking pixels that send data to domains registered in Russia, such as micro-sites like xre4xdxrc[.]ru or teotfgbyn[.]ru. The pixels, invisible to the user, load along with the page.

    This happens to anyone who reaches websites with AdNow ads.

    The company can recognize the same computer when it enters different websites, but which use the same advertising system. This is how, gradually, a profile of your interests is built.

    STEP 5. YOUR DATA IS SENT TO RUSSIA

    Your data, harvested during visits to websites hosting AdNow ads, initially lands on servers in Germany and the Netherlands. From there, it is routed straight to Russia.

    These ads generate hundreds of millions of impressions daily across Eastern Europe, according to AdNow’s public market data. They appear on news and sports portals, within mobile apps, but also on far-right or conspiracy-driven websites promoting communist nostalgia and pseudoscience.

    Money from Russia

    AdNow claims that it delivers 500 million impressions monthly in Romania. From the auction data collected by us, the average cost per thousand impressions (CPM) was 0.12 dollars. Applied to the entire declared volume, it would mean approximately 60,000 dollars per month paid to Romanian sites.

    Prices vary considerably, however: half of the analyzed auctions had a CPM below 0.054 dollars. The most expensive ads exceeded the value of 0.490 dollars per thousand impressions. If the majority of the 500 million ads reached the maximum price, then the Russians could pump in almost 250 thousand dollars monthly.

    We cannot establish from the available data how much all the ads displayed monthly in Romania are worth in reality, because we captured only a part of them.

    Most of the money coming from AdNow is wired through financial applications like PayPal or through cryptocurrencies, which makes the actual amounts almost invisible to the Fiscal Authorities. The Romanian state only knows the amounts declared from Renodo Media Eood, the Bulgarian company that operates the Russian brand AdNow. Between August 2022 and December 2025, Romanian companies invoiced AdNow, in total, 1,913,334 RON, meaning 420 thousand Dollars.

    Why Should We Care?

    Harvesting the data of millions of Romanians via far-right, religious, or seemingly harmless websites featuring jokes and recipes is primarily used to manipulate public opinion, deepen social divisions, erode trust in democratic institutions, and even sway elections.

    „If you understand people’s fears, hopes, dreams, and insecurities, you also know what ‘drop of poison’ to slip into their ear. And if you know that, you already wield a certain power over how they will act. That, ultimately, was the story of Cambridge Analytica”, – Dr. Johnny Ryan, expert in data protection and digital advertising, and director of the Enforce program at the Irish Council for Civil Liberties (ICCL).

    The EU has determined that this level of influence should not fall into the hands of obscure companies or actors who might serve the interests of foreign governments, dr. Ryan explains to Snoop.

    If US or EU authorities want user data from Google, they must follow the procedures by law. Nevertheless, both Google and Meta have collected or misused personal data, as demonstrated by numerous lawsuits and sanctions. The difference is that this is not a general obligation imposed on companies by the state.

    In Russia, legislation compels certain services and operators to retain data and facilitate access for authorities. Through the SORM surveillance system, operators are required to install infrastructure that grants the FSB direct technical access to networks.

    A network like AdNow transmits information about European users into a system under the jurisdiction of a state with radically different rules regarding government access to data.

    And to do this, they also leverage Facebook.

    AdNow uses your Facebook data

    When you click on a link from Facebook, a code named fbclid – Facebook Click Identifier is generated. It is an identifier associated with the click, used for measuring and attributing traffic.

    This code is my unique footprint through which Facebook knows who I am, what content I consume and what ads I click on.

    Facebook is not the only company that uses such identifiers. Many advertising networks generate similar codes, which can travel further in the URL of the accessed page and can be correlated with other data about the same visit.

    The value of these codes increases when they are collected by multiple companies, says Zach Edwards, researcher in cybersecurity and digital advertising, founder of DecryptAds, a research tool for programmatic supply side ecosystem – ad systems, publishers, apps. He explains what advertising companies can do with Facebook’s identifying data:

    „If 20 advertising companies collect data and all receive the same fbclid associated with a user, they share a common identifier through which they can link information about them. Two companies can compare data based on this identifier. Thus, separately held information can be tied back to the same user.”

    Correlated with other identifiers and data collected by AdNow, such a code can contribute to building a more detailed profile of the user.
    How we found out that AdNow sends data to servers in Russia, they don’t tell you about (click for details)

    We explained above the methodology of collecting ads and the decoding in base64.

    We also wanted to see if the AdNow servers overlap their data with that from other servers. After we saved the data traffic from the sites where AdNow ads appear, we analyzed other servers that deliver without consent pixel tracking or click tracking data, which generate behavioral data.

    According to the analyzed .har files, the AdNow ads also send data to servers – like teotfgbyn[.]ru – physically registered in Russia. These servers do not appear in the partner list of publications like Realitatea TV or România TV, although data about us reaches them once the ads are displayed.

    Furthermore, we entered news sites with Russian advertising from the Facebook account to observe if the data transmitted to Russia is different. We found out from the .har files that the Russians automatically export technical identification data of Facebook users, without having had consent, such as the code fbclid=, which falls under GDPR as being personal identification data.

    We found in the data traffic the piece of code below, which makes AdNow recognize us:

    H.get({excludes:{enumerateDevices:!0,pixelRatio:!0,doNotTrack:!0,fontsFlash:!0,deviceMemory:!0,fonts:!
    0,audio:!0}},function(b){b=b.map(function(b){return

    b.value});b=H.x64hash128(b.join(„”),31);b=[„ssp”,b.substr(0,8),b.substr(8,4),b.substr(12,4),b.substr(16,4),b.substr(16,4),b.substr(20,10)].
    join(„-„);a(b)})

    Separately, none of this is a secret. Together, they create a profile sent by a Romanian site to AdNow. It contains identifiers about the same user: the fbclid code and the code created by the site you opened (parameter named uord=).

    Neither contains the user’s name, but together they allow the more precise correlation of the same visit and of the same browser with information coming from different sources. The message leaves twice: once when the ad loads and once again, five seconds later, when it becomes visible on the screen.

    The same data also reaches Western advertising companies. The difference is that they appear in the public partner files and are subject to European rules. AdNow continues to receive data, without permission and without figuring anymore, since May 2026, in the IAB Europe system or in the partner list of some analyzed sites, such as România TV.

    In Moscow or Novosibirsk, no one yet knows the name of the Facebook user who frequents disinformation sites, but they know for sure that a certain Facebook account spends a lot of time on the România TV site and what headlines brought it there.

    It is not just about advertising, but also about financial fraud.

    How a Code Becomes a Name. The Frauds

    On the websites that promote frauds with natural products or investments that promise getting rich overnight, the codes acquire names and phone numbers. Because the ads persuade most of the vulnerable users to give all their data.

    For example, an ad with Călin Georgescu, former president Klaus Iohannis, and prime minister Ilie Bolojan who „sell” a rapid enrichment solution. The messages differ depending on the politician. The materials are favorable to Georgescu, who says that the scheme is „honest” and brought him 1.3 million lei. On the other hand, „Bolojan greedily fills his pockets with money, while the people starve”.

    When you click on such an ad, in Chrome, Firefox, Opera, Safari, Internet Explorer, a lot of sites open, not just one.

    An identified piece of code artificially creates 10 browsing sessions. Thus, if you want to return directly to the original page, it is impossible for you. Every time you click on „back”, you are redirected through new automatically created sessions. All these fake sites contain the same tracking pixels.

    On some pages, raffles for the medicines you are looking for also appear. Whichever you click on or whenever you press on the wheel of fortune, the script behind it will always give you the biggest discount and will make you leave your personal data.

    We will never know exactly how many Romanians have been identified and profiled using the surveillance technology of companies like AdNow, but we can get an idea from a presentation by the Russian company RocketProfit. We reported on Snoop back in 2025 that the firm is affiliated with AdNow and holds a personal data management authorization from the FSB, the Russian intelligence service descended from the Soviet Union’s KGB.

    A screenshot taken by a RocketProfit employee shows market data for six so-called miracle drugs, Tensital, Inspicure, Steplex, Ultravix, Viarex, and Paraxan, which offer zero medical benefit to people. Ultravix used the image of Dr. Irinel Popescu in an AI-generated ad where he appeared to recommend the product.

    In total, the ads for these six pseudomedications were viewed 445,836 times. We do not know the timeframe over which they were promoted, but from the Russians’ market data, we know that 1,856 Romanians landed on the sales pages.

    Of those, 843 handed over their name, phone number, and address, as well as their money. From these victims and just six of the hundreds of products they sell, the Russians collected $29,594.

    After the Snoop investigation from 2025, ANCOM blocked access to RocketProfit[.]com. On the same IP behind which the state propaganda sites – Russia Today, RIA Novosti and SputnikNews, under international sanctions – are also blocked.

    Every Piece of Information About You Is Bought and Sold in Real Time

    The system behind AdNow’s ads classifies websites based on the amount of sexual or violent content they can display. Four values appear in the code, establishing both the classification of the ads and the threshold accepted by each partner website:

    • sex_rate and brutal_rate indicate the level of sexual and violent content in an ad, respectively.
    • show_sex_rate and show_brutal_rate determine the maximum content level up to which an ad can be bid on a partner website.

    Consequently, some websites may receive more explicit ads than others.

    These classifications are transmitted to the network’s servers from the very first ad impression. In the analyzed data, we identified no GDPR consent signal, even though the Russians thereby learn not only that the same browser has visited multiple websites, but also whether a user spends more time on sites featuring sexual or violent content.

    AdNow is not an isolated case. “Almost anything is bought and sold,” says Wolfie Christl, an Austrian expert in digital advertising and data protection. The adtech industry collects everything from information about people’s health and financial situation to their political views and religious beliefs.

    “We found a company that had audience segments made up of people with AIDS, and even one segment consisting of 200 survivors of sexual abuse in Ireland. The data can be extremely intimate,” explains Dr. Johnny Ryan.

    Why Big Tech Moved to Ireland (click for details)

    The presence of Russian companies in the European advertising market, and the flow of data into their infrastructure, is also made possible by the way the adtech industry has developed in Europe — a system that major tech companies have spent years lobbying to shape.

    Meta, Google and TikTok did not choose Ireland for their European headquarters by accident. Among other advantages, they benefit from the country’s relatively favourable tax regime within the EU. The concentration of Big Tech companies in Dublin has made Ireland’s data protection authority one of the most important regulators when it comes to enforcing the GDPR across Europe.

    Dr. Johnny Ryan, a privacy rights advocate, has been warning for years about the way the online advertising industry shares user data with a vast number of companies. His findings about the collection and circulation of highly sensitive data have reached regulators in both Dublin and Brussels.

    The Irish authority has opened investigations and imposed billions of euros in fines on tech companies, but it has also faced criticism over the effectiveness of its GDPR enforcement. Accusations that the regulator was too close to the industry intensified in 2025, when a former Meta public policy and lobbying official was appointed as one of the three commissioners leading Ireland’s Data Protection Commission.

    Hate Codes: Among the Most Profitable

    Some data can be even more profitable. For example, when you read online materials built on a rhetoric of hate, whether it is homophobia or antisemitism, Russian ads with the code IAB25-5 appear in the code that runs in your browser.

    IAB codes are a convention used in the online advertising industry for classifying ads depending on their content.

    AdNow boasts that they are „part of IAB Europe„, an organization that brings together advertising companies from all over Europe. This gives the company credibility and helps it operate in an ecosystem built on standards and procedures also used by the big tech platforms in the world, such as Google, Microsoft, Meta, and TikTok.

    There are IAB codes for almost every category of products and services. An auto ad is classified in the same category, regardless of whether it promotes Dacia or Rolls Royce. Slot machine ads have their own code, those for natural products – one for each individual condition. The same classification mechanism is also used for sensitive categories, including for hate-based content.

    Hate has the code IAB25-5.

    Here is an example of an ad associated with this IAB25-5 code (photo).

    The ad imitates the title of a news story from local sites like Gorj Online or Ziarul Argeșul and is meant to cause panic: „Scary news: the pension reform will surprise you!”

    A click on this ad takes the elderly who fear that their pensions, already small, are being decreased, directly to the Russian site xre4xdxrc[.]ru.

    In February and March, the pension reform and the cutting of magistrates’ special pensions were intensely debated subjects in the public space.

    In parallel, at the end of the news stories about Călin Georgescu and George Simion, such images built to provoke emotion appeared: elderly people in line or crying into their hands.

    Behind an ad, several companies bid simultaneously, in a fraction of a second, for their ad to appear in front of you, depending on the information they have about you.

    Dr. Johnny Ryan explains the mechanism:

    ”When you visit a website or use an app, the page you load organizes an auction for the advertising space. Every slot where an ad can appear is put up for auction. For this auction to take place, information about what you are reading or doing at that exact moment is broadcast to dozens, perhaps even hundreds, of different companies. They thereby learn more about you and decide whether to bid for the chance to serve you an ad.”

    Among the highest-valued ads in the AdNow network are those placed on sites featuring conspiratorial and extremist content, because this is where readers classified under IAB25-5, the code for hate, are. Visitors land on these pages via Facebook, according to AdNow’s head of publishers.

    Consequently, databases of users interested in conspiracies and hate-based content, linked to tracking codes originating from Facebook, are being stored in Russia.

    Pieced together, this data can provide a highly precise picture of a country’s citizens and their online behavior. Researcher Wolfie Christl warns that the very same infrastructure built for advertising can also be exploited by state actors for surveillance, targeting specific groups, or influencing behaviour.

    But who are the Russians behind the AdNow operation?

    The Russians Behind AdNow

    AdNow is a Russian advertising firm with a controversial past. At the beginning of the pandemic, the company’s employees tried to recruit influencers in France, Germany, and India to spread conspiracy theories about the Pfizer and AstraZeneca vaccines.

    AdNow’s founder is Yulia Serebryanskaya, who previously worked for the PR department of Vladimir Putin’s ruling party, United Russia. She has worked on presidential election campaigns for both Putin and former president Dmitry Medvedev.

    In 2024, we discovered that AdNow’s IT infrastructure was utilized in the election campaign of the governor of the Kaliningrad region, Aleksey Sergeevich Besprozvannykh, who is on international sanctions lists for his contribution to Russia’s war against Ukraine.

    Our previous investigations show how millions were funneled into extremists and conspiracy theorists who support the public rhetoric of former pro-Russian presidential candidate Călin Georgescu or political party AUR’s far-right policies (click for details).

    The money entered Romania through the British firm AdNow LLP. It was controlled by a Russian citizen named Stanislav Fesenko, the son of a high-ranking officer in the Moscow Ministry of Defense and husband to a woman whose ID was registered at a student dormitory of the GRU, the Russian army’s military intelligence service.

    In the investigation „The Russian Money Strategy,” we showed you how this business operates and its activity in Romania, and in the episode „Tracing the Money Behind Russian Ads,” we revealed who is behind the operation.

    The Russians are not hiding. Some of the ads contain comments in Russian, left in the code by programmers in Novosibirsk. They leave each other instructions on how to use the code to target some of the most vulnerable people online.

    After the first few months of documenting the investigation, we requested an interview with a specialist from Prebid.org, a global programmatic advertising industry organization.

    We provided them with several technical data points for context. Without our consent, the specialist forwarded this information to IAB Europe on May 5 to verify questions regarding AdNow and MGID.

    On May 25, IAB Europe revoked AdNow’s right to deliver ads through the centralized real-time bidding system.

    From that moment on, AdNow stopped delivering ads in Romania and the rest of the EU. However, we identified other undeclared servers through which ads continue to be distributed, such as nnowa.com.

    Although AdNow is openly operated by a Bulgarian company, Renodo Media EOOD, and the owner claims to no longer have any ties to Russia, an employment contract obtained by Snoop shows that AdNow employees were subject to Russian labor legislation for many years.

    The Bulgarian owner is named Gyorgy Abuladze and is originally from Georgia. He established 53 IT companies in Bulgaria in 2020, some of them alongside Russian citizens. All of his firms work with the same accounting company, owned by Emil Haralambev. In 2017, the latter also provided services for Siberika, a company belonging to the Russian national Dmitry Alexandrovich Panin.

    Panin appeared on the Kherson front as an employee of the Russian Ministry of Interior. He is part of the GROM special forces, and Ukrainian authorities accuse him of crimes against civilians, while Russia has decorated him for his military activity.

    These people have spent years building databases of internet users in Romania.

    What the Romanian state does not do

    In March 2026, we asked DNSC if it received complaints from people defrauded through the ads promoted by AdNow and by the other companies investigated by us. The institution sent us data from its reports, which show a continuous increase in online frauds, in general.

    Sources from the institution say, however, that DNSC had asked ANCOM since 2025 to block neotex[.]pro, one of the sites to which the investment fraud ads led. The site was, however, blocked only after Snoop’s request for public information, from March this year.

    ANCOM is the digital services coordinator in Romania. The institution claims that it does not have the competence to investigate the processing or transfer of personal data and that DNSC asked it to block a single site.

    But it knows the AdNow problem. In May 2025, before the presidential elections, ANCOM publicly warned about the disinformation distributed through the AdNow, MGID and AdsKeeper ads. It did nothing else after issuing the press release.

    Asked what other requests it received from state institutions in connection with these networks, it answered that the information is classified.

    Snoop also asked SRI, the Romanian Police and the Supervisory Authority for Personal Data Processing if they investigated AdNow or the data collection through this infrastructure. SRI transmitted that the requested information is classified, and the Police and the Data Protection Authority did not respond until the publication of the material.


    This investigation was supported by a grant from the Journalism Science Alliance.

    Editing: Iulia Roșu, Ada Constanda, Răzvan Luțac

    Graphics and Data Visualization: Adriana Diaconu

    Image Sources: Unsplash (Davide Ragusa, Vicky Hladynets, Imad Alassiry, Ryoji Iwata)

    Contributions: CheckFirst (FIN), Timur Olevsky și Lisa Werner, The Insider (RU), Josef Šlerka, Investigace (CZ), Sorin Tamaș (RO)

    Despre autor
    Victor Ilie este jurnalist de investigație din 2012 și a publicat în mai multe publicații independente ca Inclusiv, Casa Jurnalistului, RISE Project sau Recorder. A publicat materiale despre corupția din presă și de la stat, industria farmaceutică și trafic de persoane, a participat la proiecte transfrontaliere ca Panama Papers și documentări undercover ca Marele Alb sau Jagten. Din 2024 este freelancer și coordonează mai multe documentări pe propagandă și efectele ei. / Foto: Andrei Pungovschi