Hidden Trackers On FI Websites Could Be Exposing Sensitive Customer Data, Researchers Warn

NEW YORK-- Credit unions and banks spend billions of dollars protecting customer and member information from cybercriminals, but a new cybersecurity report suggests some financial institutions may be inadvertently exposing sensitive consumer data through the marketing and analytics technologies embedded in their own websites.

According to BankInfoSecurity, cybersecurity firm Jscrambler found that some financial institutions are allowing third-party tracking technologies—including advertising pixels tied to companies such as TikTok, Google, LinkedIn and Salesforce—to collect detailed information about consumers' online banking and loan application activity. The researchers said the information may be transmitted without valid customer consent or with protections that are insufficient to prevent customer identification, potentially raising privacy and regulatory concerns in both Europe and the United States.

99889988888

BankInfoSecurity reported that Jscrambler analyzed the runtime behavior of tracking pixels and personalization scripts on 14 financial services websites in Europe and the United States. Researchers found that tracking was activated without valid customer consent on nine of the sites, with information transmitted to a dozen third parties. The company did not identify any of the financial institutions it examined.

"Organizations may believe they are simply measuring user behavior through standard analytics. In practice, they are exporting a detailed, ongoing view of customer financial intent and product economics to third parties, often with little visibility into the scope or sensitivity of data being shared," the researchers wrote.

Unlike traditional website analytics, many advertising pixels capture information consumers enter into online forms. According to BankInfoSecurity, that can include contact information, requested loan amounts, repayment terms and other financial details entered during mortgage, lending or account-opening processes. Jscrambler found that ad pixels on the websites of at least two Spanish banks transmitted customer contact details to recipients including TikTok and Google using deterministically hashed data that researchers said could allow reidentification. At one Portuguese bank, a customer's email address was reportedly transmitted to Salesforce's marketing platform through a request URL using binary-to-text encoding rather than encryption.

The findings could carry significant regulatory implications. BankInfoSecurity reported that Jscrambler believes some European institutions may be violating the European Union's General Data Protection Regulation (GDPR), the ePrivacy Directive—commonly known as the Cookie Law—and potentially the Digital Operational Resilience Act (DORA). The company also suggested U.S. financial institutions could face scrutiny under the Gramm-Leach-Bliley Act's Safeguards Rule as well as state privacy laws such as the California Consumer Privacy Act and California Privacy Rights Act if customer financial information is shared without appropriate safeguards.

Among the issues identified, researchers said some websites loaded tracking technologies before visitors had the opportunity to accept or reject cookies, while others allegedly continued sending information to third parties even after users denied consent.

"Recording the consent state and then ignoring it in practice is arguably worse than not asking, because it produces a documented record of a choice the implementation did not honor," the researchers wrote.

Illegal Under Article 5(3)

Levan Lobzhanidze, a data protection lawyer at European privacy advocacy group Noyb, told BankInfoSecurity that, "A tracking pixel gathering information without prior consent, or after a rejection of consent, is indeed illegal under Article 5(3) of the ePrivacy Directive."

Jscrambler also questioned the common assumption that responsibility lies solely with financial institutions deploying the tracking code. According to BankInfoSecurity, many advertising platforms automatically enable "advanced matching" capabilities that collect and hash customer contact information without explicit configuration by the website operator.

"A bank that drops in a standard pixel does not intentionally configure it to send a customer's hashed email and phone number from a mortgage page," the researchers wrote. "A policy that prohibits the sharing of sensitive data is difficult to reconcile with a pixel that, left at its defaults, captures and transmits exactly that kind of data from account-opening and lending flows. If the policy genuinely prohibited it, the default would not collect it."

Gareth Bowker, Jscrambler's head of security research, told BankInfoSecurity there is "very little in the way of enforcement right now—some of that is down to a lack of visibility into this."

He added that the company intentionally chose not to identify the affected financial institutions publicly because its immediate goal is to notify the organizations involved and raise awareness of risks associated with third-party tracking technologies rather than assign blame.

For credit unions expanding digital account opening, online lending and personalized marketing, the report underscores that cybersecurity risks increasingly extend beyond network intrusions and ransomware. As institutions rely more heavily on third-party website technologies, understanding exactly what customer information those tools collect—and where that data ultimately travels—may become just as important as protecting against external attacks.

Section: Standard
Word Count: 890
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto.flux5.ccplatform.net/THE-feature/Hidden-Trackers-On-FI-Websites-Could-Be-Exposing-Sensitive-Customer-Data-Researchers-Warn