US and European Banks Sharing Financial Intent, Loan Details, and Customer Data With Third-Party Platforms, According to Jscrambler Research

Analysis Shows Financial Institutions Are Sending Sensitive Customer Data to Google, Meta, TikTok, LinkedIn, and Salesforce Without Valid Consent PORTO, Portugal, July 22, 2026 /PRNewswire/ — New research fromย Jscramblerย reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms. The analysis…


US and European Banks Sharing Financial Intent, Loan Details, and Customer Data With Third-Party Platforms, According to Jscrambler Research

Analysis Shows Financial Institutions Are Sending Sensitive Customer Data to Google, Meta, TikTok, LinkedIn, and Salesforce Without Valid Consent

PORTO, Portugal, July 22, 2026 /PRNewswire/ — New research fromย Jscramblerย reveals that banking websites are transmitting sensitive customer information, including hashed identifiers, loan details, and financial intent signals, to third-party advertising, analytics, and personalization platforms. The analysis of 14 financial institutions, spanning retail and investment banks, payment providers, and consumer credit platforms, found that this data routinely leaves the site before a cookie consent choice is made and, in some cases, even after users explicitly reject tracking.

Key Highlights:

  • Across 14 financial services websites in Europe and the US, tracking technologies fired without valid user consent on 9 sites, sending data to at least a dozen third parties, including Google, Meta, TikTok, LinkedIn, Pinterest, Adobe, and Salesforce.

  • Hashed and unhashed emails, phone numbers, and government tax IDs sent from account-opening and mortgage flows, plus precise loan details โ€” including a โ‚ฌ27,000 loan simulation with full repayment terms โ€” from credit and loan-simulator flows.

  • Tracking often continued after users rejected cookies, and consent choices frequently didn’t carry over into iframes and subdomains handling the same transaction.

As financial institutions accelerate digital banking, personalization, and embedded financial services, more critical customer interactions are moving into the browser, creating new exposure points beyond traditional application security controls.

While banks present themselves as among the most careful custodians of personal and financial data, Jscrambler’s research shows that the public-facing reality often does not match this. The report found that some of the most regulated and sensitive pages on the webโ€”mortgage applications, account openings, credit simulatorsโ€”have tracking and personalization scripts that collect and transmit data far beyond what ordinary financial customer-journey measurement requires.

Incidents identified by the research include:

  • A Spanish bank’s mortgage process sent a customer’s hashed email and phone number to TikTok’s pixel endpoint immediately after cookie acceptance, despite TikTok appearing in neither the bank’s cookie policy nor its privacy policy.

  • In a Portuguese bank’s account-opening flow, a customer’s email address was sent to a Salesforce marketing platform alongside the customer’s name, age, and national tax number (NIF), without valid consent.

  • A credit and loan simulator at two other Portuguese institutions shared the full details of a customer’s loan request, including exact amounts, terms, interest rates, and total cost of credit, with Google Analytics. This created a continuous stream of borrowing-intent signals that flowed into a third-party advertising ecosystem used across industries.

  • The analysis uncovered examples of leading U.S. banking and investment websites sending analytics requests to third parties before visitors had the opportunity to provide consent, highlighting how browser-side technologies can bypass intended privacy controls.

Source link