Mobile banking apps are exposing user data to attackers
Positive Technologies’ study finds 13 out of 14 banking apps gave attackers access to user data

Positive Technologies has found that 14 banking apps available on iOS and Android were affected by vulnerabilities.
In 2019, Positive Technologies assessed the security level of a number of banking apps and found vulnerabilities in each one. Per the report, each vulnerability could be traced to faults in the application code, client-server interaction and the implementation of security mechanisms.
On the user-side, Positive Technologies found 13 out of 14 applications unwittingly gave attackers access to user data. For more than a third of the banking apps tests, vulnerabilities could be exploited without administrator rights. Further, 76% of these vulnerabilities could be exploited without the attacker having physical access to the account holder’s device.
On the server-side, researchers found servers contained 54% of all vulnerabilities identified in the study. According to Positive Technologies, each mobile bank had an average of 23 server-side vulnerabilities. Plus, at five out of seven banks, hackers were able to steal user credentials and at one-third of banks, users’ card information is at risk of being stolen.
Though these statistics are staggering enough, the FBI recently revealed a 50% increase in attacks against mobile banking apps since the beginning of 2020. In its announcement, the FBI said it expects threat actors to attempt to exploit mobile banking customers by using a variety of techniques, such as app-based banking Trojans and even fake banking apps.
To protect themselves, users should use two-factor authentication along with a strong password.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
-
Cisco names Oliver Tuszik as global sales chief
News Cisco has announced the appointment of Oliver Tuszik as its new executive vice president of global sales, who replaces Gary Steele.
By Daniel Todd
-
AI will chew through the same amount of energy as Japan by 2030
News The energy demand of AI data centers will top that of Japan by the end of the decade, new research shows – and that’s providing that energy grids can even keep up.
By Nicole Kobie
-
Why the Space Force wants white hats to attack a satellite
Case study Authorities hope the first-of-its-kind competition could bring benefits to the cyber sector
By James O'Malley
-
OpenAI to pay up to $20k in rewards through new bug bounty program
News The move follows a period of unrest over data security concerns
By Ross Kelly
-
New ‘DarkBit’ ransomware gang shuts down Technion, demands $1.7 million ransom
News A politically charged ransom note suggests DarkBit are one of the newest hacktivist gangs to emerge in recent months
By Ross Kelly
-
Research: Luxury cars and emergency services vehicles vulnerable to remote takeover
News A "global API issue" has been highlighted through months-long research into brands such as Ferrari and Mercedes-Benz, leaving owners open to hacking, account takeovers, and more
By Rory Bathgate
-
Podcast transcript: Meet the cyborg hacker
IT Pro Podcast Read the full transcript for this episode of the IT Pro Podcast
By IT Pro
-
The IT Pro Podcast: Meet the cyborg hacker
IT Pro Podcast Resistance is futile - offensive biotech implants are already here
By IT Pro
-
SpaceX bug bounty offers up to $25,000 per Starlink exploit
News The spacecraft manufacturer has offered white hats immunity to exploit a wide range of Starlink systems, with a dedicated report page
By Rory Bathgate
-
Nomad happy to forgive hackers if they return 90% of $190 million that was stolen
News The crypto bridge is offering 'white hat hackers' a 10% bounty following the attack earlier this week
By Zach Marzouk