Jscrambler Detects Cookies Exporting Detailed View of Customer Financial Intent

Many European and American bank websites are quietly – and perhaps unwittingly – sending sensitive customer data to third parties such as TikTok without user consent or sufficient anonymization, the cybersecurity firm Jscrambler found.
See Also: Moving Past Legacy AD Bridging With Idira Identity Bridge
Company researchers said the banks and service providers that offer user tracking pixels may be breaking multiple privacy laws – and perhaps even financial services cybersecurity legislation – in Europe. Some U.S. banks may be violating federal and state laws by allowing this sort of tracking. The firm didn’t call out any specific banks in either market by name.
Jscrambler made the claims in a Wednesday blog post. The code integrity security outfit, which recently hit the headlines when hackers published a malicious version of one of its packages, has repeatedly tackled the subject of intrusive marketing tech in recent months.
“Organizations may believe they are simply measuring user behavior through standard analytics,” researchers wrote. “In practice, they are exporting a detailed, ongoing view of customer financial intent and product economics to third parties, often with little visibility into the scope or sensitivity of data being shared.”
The researchers performed a runtime analysis of tracking pixels and personalization scripts – mostly designed by the adtech companies that receive data from them – on 14 financial-services websites. Of those, tracking was activated without valid consent on nine of the sites, with information being sent to a dozen third parties.
The big issue with these tracking tools is that they collect details that customers input into webpages. Apart from contact details, that can also include information such as details of the amounts that customers want to borrow and the repayment terms.
Jscrambler said it found that ad pixels on the websites of at least two Spanish banks were sending out customers’ contact details to recipients such as TikTok and Google in a deterministically hashed form that allows for reidentification. The account open flow on one Portuguese bank’s website went further by transmitting the customer’s email address to Salesforce’s marketing system in the request URL, with mere binary-to-text encoding rather than actual encryption. Salesforce did not respond to a request for comment.
If European bank sites really are treating user data in this way, their operators may be falling foul to the European Union’s General Data Protection Regulation Act. Financial data is covered by the law as personal data, as long as it can be connected with an identifiable person. GDPR violations can incur fines of up to 4% of global annual revenue, though in practice the top of that range has never been reached.
Jscrambler also found many apparent violations of the EU’s ePrivacy Directive, more commonly known as the Cookie Law. One European bank loaded a fingerprinting script before the user was even able to state a tracking preference on the site’s cookie consent form. Others, in Spain and Portugal, allowed third parties such as Google and LinkedIn to capture information even after the user had actively denied consent.
“Recording the consent state and then ignoring it in practice is arguably worse than not asking, because it produces a documented record of a choice the implementation did not honor,” the researchers wrote.
In another case involving the personal credit simulator on a Portuguese bank’s site, even if a user specified only essential cookies, five third parties nonetheless received detailed information about a requested loan.
“A tracking pixel gathering information without prior consent, or after a rejection of consent, is indeed illegal under Article 5(3) of the ePrivacy Directive,” Levan Lobzhanidze, a data protection lawyer at the European privacy advocacy group Noyb, told ISMG on Wednesday.
Apart from potential GDPR and ePrivacy violations, Jscrambler said some European banks could be falling foul of the Digital Operational Resilience Act, which applies to the financial sector. DORA is largely concerned with cyber resilience, and the researchers said it may “arguably treat unmanaged third-party scripts in customer-facing flows as part of the institution’s risk surface.”
“There’s very little in the way of enforcement right now – some of that is down to a lack of visibility into this,” Gareth Bowker, Jscrambler’s head of security research, told ISMG.
The researchers also suggested there may be issues with the Payment Services Directive – the second version of that law, PSD2, applies now and the tighter PSD3 is currently going through the legislative process. This suggestion may be a little more tenuous, as those directives only apply to payment services, rather than more general financial services.
As for the U.S. banks whose behavior was called out in the post, the suggestion there is that they might be contravening the safeguards rule in the Gramm-Leach-Bliley Act by not sufficiently protecting customer financial information – and possibly also state laws like California’s Privacy Rights Act and Consumer Privacy Act.
Adtech vendors tend to try to shift compliance responsibility onto the shoulders of the website operator, but Jscrambler said this framing “only holds if the collection is something the operator deliberately switched on, and much of what we observed is not.”
“Features such as automatic advanced matching are enabled by default and are designed to capture and hash contact details with no explicit action from the site owner. A bank that drops in a standard pixel does not intentionally configure it to send a customer’s hashed email and phone number from a mortgage page,” the researchers wrote. “A policy that prohibits the sharing of sensitive data is difficult to reconcile with a pixel that, left at its defaults, captures and transmits exactly that kind of data from account-opening and lending flows. If the policy genuinely prohibited it, the default would not collect it.”
Bowker said his team felt “quite strongly” that the blame mostly lies with the companies providing the tracking pixels, which is why Jscrambler didn’t name any of the banks it referenced in its research – a necessary step if any enforcement is to follow.
“We are reaching out to them to let them know what we found, and we’ll be seeing what happens after that,” Bowker said. “At the moment it’s really about trying to raise awareness about this, to make sure that the entities understand what’s going on.”
The European Banking Federation, which represents the sector in the EU, did not respond to a request for comment.
