EU Financial Institutions Leak Data Through Cookie Trackers

Financial Institutions Expose Customer Data Through Cookie Trackers, Ignorant of the Risk

A disturbing trend has emerged among European banks and other financial institutions, inadvertently transmitting sensitive customer information to third-party advertising platforms via cookie trackers. Researchers at Jscrambler have uncovered a pattern of data leakage through tracking pixels, often without the knowledge or consent of the affected organizations.

The problem lies in the widespread use of cookie tracking technology on financial institution websites. These tracking technologies are designed to gather user data and transmit it to third-party platforms for advertising, analytics, and personalization purposes. However, researchers have found that many financial institutions are not taking adequate steps to protect their customers’ sensitive information. In some cases, this data is transmitted before users even have a chance to make an informed consent choice, while in others it continues to flow despite users explicitly rejecting tracking technologies.

The affected organizations, including several major European banks, may be unaware of the issue due to the complexity and subtlety of cookie tracking technology. Jscrambler’s research has identified 14 cases where financial institution websites fired tracking technologies without a valid consent choice, resulting in sensitive data being transmitted to about a dozen third-party platforms, including Google, Meta, TikTok, LinkedIn, and others.

The situation is particularly concerning when it comes to sensitive pages such as loan applications or account opening forms. Researchers have found that banks are inadvertently transmitting customer data back to the technology firms that run them, often in an unencrypted format. This means that sensitive information could potentially be linked back to specific individuals under the right circumstances.

One example of this issue is a Spanish bank that presented users with the usual cookie choices while going through a mortgage application process. Once the user accepted cookies, TikTok received the user’s hashed email and phone number through a request to its pixel endpoint. However, TikTok does not appear as a vendor on the bank’s cookie policy or privacy policy, meaning customers would have no way of knowing that accepting cookies sent hashed details to TikTok.

This pattern of data leakage is not isolated to European banks. Researchers have also found similar issues with Portuguese and US-based financial institutions. The problem is compounded by the fact that many organizations are unlikely to realize how much of this is happening by default.

The implications of these findings are serious, raising concerns about compliance, security, and privacy. Financial institutions must take immediate action to address this issue and ensure that they are not inadvertently exposing their customers’ sensitive information. This may involve reviewing their cookie policies, implementing more robust tracking technology solutions, and educating customers about the risks associated with cookie tracking.

For individual users, it’s essential to be aware of these issues and take steps to protect your own data. When visiting financial institution websites, be cautious when accepting cookies or configuring tracking technologies. Understand that even if you reject tracking technologies, sensitive information may still be transmitted without your knowledge. Stay vigilant and stay informed – the security of your personal data depends on it.


Source: Dark Reading — 2026-07-22