Bank of Ireland Mobile Banking Security & Privacy Scorecard
Android
Usage patterns and app behavior are tracked by Firebase Analytics and AppDynamics. Push notification data flows through ExtremePush, a third-party service outside the bank. Financial data may not be fully protected during transmission and on the device.
Best for
Bank of Ireland customers who need mobile access
Avoid if
You share your device with others
Findings
- 3 critical
- 5 high
- 8 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Universal File Access Enabled in WebView
- Conditional SSL Error Bypass
- WebView LocalStorage Likely Contains Session Tokens
Top privacy issues
- AppDynamics Screenshot Capture of Banking Data
- ExtremePush Real-Time GPS Location Tracking
- ExtremePush SDK Collects Persistent Device Identifiers
Full analysis
Bank of Ireland Mobile Banking
Version: 3.4.4 | Scan Date: 2026-01-28
What This Means for You
Usage patterns and app behavior are tracked by Firebase Analytics and AppDynamics. Push notification data flows through ExtremePush, a third-party service outside the bank. Financial data may not be fully protected during transmission and on the device.
Recommendation: Use With Caution
Best For: Bank of Ireland customers who need mobile access
Avoid If: The device is shared with others
Key Findings
Data Security - 5 findings (2 high, 3 medium)
Network Security - 3 findings (2 high, 1 medium)
Code Safety - 0 findings
Privacy - 5 findings (4 critical, 1 high)
Privacy Concerns
What Data is Collected
Firebase Analytics and AppDynamics collect behavioral and session data from user interactions with the app. This includes which features are used, how long users spend in the app, and navigation patterns within banking sessions.
Third-Party Data Sharing
Data is shared with the following third-party services:
- ExtremePush - Receives push notification data and device identifiers outside the bank's own infrastructure
- AppDynamics (Cisco) - Receives performance and behavioral telemetry gathered during user sessions
- Firebase Analytics - Receives usage and navigation data from user time in the app
- HID Global ActivCastle SDK - Integrated for identity-related functions within the app
- Google Tink - Used for internal data protection operations
Understanding the Scores
| Category | Score |
|---|---|
| Security | 35/100 |
| Privacy | 25/100 |
| Data Security | 40/100 |
| Network Security | 45/100 |
| Code Safety | 40/100 |
| Data Collection | 20/100 |
| Data Sharing | 30/100 |
| User Control | 25/100 |
Positive Security Features
- No standout security protections were identified in this version of the app.
Areas for Improvement
- Multiple third-party analytics providers receive behavioral data from banking sessions, reducing user control over where financial activity information goes.
- Data transmitted between the device and external services travels with less protection than expected for financial applications.
- The app provides limited options for users to control or restrict data collection, leaving privacy settings largely outside user control.
About This Analysis
Independent automated analysis of the app's code and configuration as of the scan date. Results reflect the state of the app at the version listed below.
App Details
- App Name: Bank of Ireland Mobile Banking
- Package ID: com.bankofireland.mobilebanking
- Version: 3.4.4
- Scan Date: 2026-01-28
- Developer: Bank of Ireland
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 30/100 |