HomeMalware & ThreatsPixels Tracking Every Loan Taken on EU Bank Websites

Pixels Tracking Every Loan Taken on EU Bank Websites

Published on

spot_img

Jscrambler Uncovers Inappropriate Data Sharing by European and American Banks

In a recent revelation, the cybersecurity firm Jscrambler has exposed critical concerns regarding the handling of sensitive customer data by various European and American bank websites. These financial platforms have allegedly been transmitting data to third-party entities, including major tech firms like TikTok and Google, without proper user consent or adequate anonymization. This breach of privacy highlights significant potential violations of privacy laws, raising alarms in the cybersecurity industry and among consumers alike.

In a blog post published on July 22, 2026, Jscrambler’s researchers indicated that the misuse of tracking pixels and scripts for user monitoring could be in direct violation of several privacy regulations in Europe. The researchers emphasized that financial institutions, especially in the U.S., might also be infringing upon federal and state laws by enabling such data usage. Interestingly, no specific banks were identified in their findings, yet the implications carry significant weight.

Through a detailed analysis of tracking technologies employed on 14 financial-service websites, Jscrambler observed that nine out of these twelve sites had tracking activated without obtaining valid user consent. The data collected was sent to a dozen different third-party entities, revealing a troubling trend where customer financial intentions and sensitive information were transmitted without the users’ knowledge.

The crux of the issue lies in the nature of the information being captured. Tracking tools often collect not just basic contact details but also sensitive information such as loan amounts and repayment conditions that customers input while navigating bank websites. This collection poses substantial risks given that such details could be exploited for malicious purposes.

Jscrambler highlighted alarming findings, particularly regarding two Spanish banks that were found to be sharing customer contact information in a hashed format, making re-identification possible for recipients like TikTok and Google. Meanwhile, another incident involved a Portuguese bank’s website, which transmitted customer email addresses to Salesforce’s marketing systems without utilizing proper encryption methods. Despite inquiries, Salesforce did not provide a comment on the situation.

If the allegations are substantiated, these banks could be in breach of the European Union’s General Data Protection Regulation (GDPR), which classifies financial data as personal data when linked to identifiable individuals. Violations of GDPR can lead to heavy penalties, amounting to 4% of a company’s global annual revenue, although enforcement of such penalties has been inconsistent thus far.

Jscrambler’s report also pointed out multiple apparent breaches of the EU’s ePrivacy Directive, commonly referred to as the Cookie Law. In one instance, a European bank loaded a fingerprinting script before users could express their tracking preferences. In Spain and Portugal, users actively denied consent yet still found their information captured by third parties like Google and LinkedIn.

The researchers deemed this practice particularly concerning, stating, “Documenting a user’s consent state while ignoring it is arguably more egregious than not seeking consent at all.” Furthermore, in a case involving a personal credit simulator on a Portuguese bank’s website, multiple third parties still received sensitive data about a requested loan, despite the user selecting only essential cookies.

The implications of tracking pixels capturing information without prior consent are stark; such actions violate Article 5(3) of the ePrivacy Directive, as noted by Levan Lobzhanidze, a data protection lawyer at the European privacy advocacy group Noyb. This flagrant disregard for user privacy may also extend to the Digital Operational Resilience Act (DORA) for financial institutions, which emphasizes the need for cyber resilience. Jscrambler’s findings suggest that unmanaged third-party scripts could be perceived as an intrinsic security risk.

Further complicating matters, there are suggestions that these European banks might also be breaching the Payment Services Directive, particularly in its second iteration, PSD2, which is currently in effect, while a more stringent PSD3 is under legislative review. This assertion, however, is somewhat tenuous, as these regulations primarily focus on payment services rather than broader financial services.

The U.S. banking sector is not immune to such scrutiny. Jscrambler hinted that American banks implicated in this situation might be violating the Gramm-Leach-Bliley Act, which necessitates stringent protection of customer financial information. Moreover, they could be falling short of compliance with state laws, including California’s Privacy Rights Act and Consumer Privacy Act.

Interestingly, Jscrambler pointed out a common trend among adtech vendors attempting to shift compliance responsibilities to website operators. Yet, they argued that this should only hold true if the operators deliberately enabled the collection features, which was not observed in many of Jscrambler’s findings.

“The default configurations capture and transmit sensitive data without explicit action on the part of the site owner,” the researchers wrote, underscoring the implications of default settings in tracking technologies.

Gareth Bowker, Jscrambler’s head of security research, emphasized the necessity of raising awareness among financial institutions regarding these findings. He stated that the goal is to drive home the importance of understanding the ongoing data-sharing practices. In light of this, Jscrambler has reached out to the concerned banks to inform them of the findings, with hopes for subsequent actions.

Despite these critical disclosures, the European Banking Federation, representing the interests of the banking sector in the EU, has not responded to inquiries regarding this pressing matter.

The situation raises critical questions on the ethical use of user data and the responsibilities of financial institutions in safeguarding their customers’ information. With regulatory landscapes becoming increasingly stringent, it remains to be seen how banks will address these issues and whether there will be broader implications for the industry at large as scrutiny intensifies.

Source link

Latest articles

Google Unveils Gemini 3.5 Flash Cyber AI Model

Google Unveils Gemini 3.5 Flash Cyber: A New Era in Cybersecurity AI Google has introduced...

TrickBot Abandons HTTP for DNS Tunneling in Newest Variant

A newly discovered variant of the notorious TrickBot malware has been identified employing a...

Cybercriminals Target World Cup Fans

A Different Kind of Opponent: Cybersecurity Threats Surrounding the FIFA World Cup As the dust...

More like this

Google Unveils Gemini 3.5 Flash Cyber AI Model

Google Unveils Gemini 3.5 Flash Cyber: A New Era in Cybersecurity AI Google has introduced...

TrickBot Abandons HTTP for DNS Tunneling in Newest Variant

A newly discovered variant of the notorious TrickBot malware has been identified employing a...