Mobile Banking UniCredit Security & Privacy Scorecard
Android
In-app activity is shared with Adobe Marketing Cloud alongside standard analytics services, meaning banking behavior informs marketing profiles. Users have very limited options to restrict or opt out of this data collection. Multiple third-party services monitor sessions, and the ability to manage what gets shared is among the lowest seen in banking apps.
Best for
UniCredit customers who need everyday mobile banking
Avoid if
You want control over how your data is used for marketing
Findings
- 1 critical
- 2 high
- 6 medium
- 0 low
- 0 info
0 issues identified across security and privacy analysis.
Top security issues
- Catapush API Key Hardcoded in AndroidManifest.xml
- LivePerson Bearer Tokens Stored Unencrypted
- 7 JavaScript Interfaces Exposed in WebView
Top privacy issues
- Invasive Behavioral Tracking Without Explicit Consent
- Adobe Analytics Auto Opt-In GDPR Violation
- Cross-Device Tracking via Adobe Marketing Cloud ID
Full analysis
Mobile Banking UniCredit
com.unicredit | Version 3.68.1 | Scanned 2026-02-08
What This Means for You
In-app activity is shared with Adobe Marketing Cloud alongside standard analytics services, meaning banking behavior informs marketing profiles. Users have very limited options to restrict or opt out of this data collection. Multiple third-party services monitor sessions, and the ability to manage what gets shared is among the lowest seen in banking apps.
Recommendation: Use With Caution
Best For: UniCredit customers who need everyday mobile banking
Avoid If: Control over how data is used for marketing is important
Key Findings
Data Security - 6 findings (1 critical, 1 high, 4 medium)
Network Security - 2 findings (2 medium)
Code Safety - 0 findings
Privacy - 5 findings (2 critical, 2 high, 1 medium)
Privacy Concerns
What Data is Collected
This app collects behavioral and session data during banking activity. Analytics and monitoring services record how users navigate the app, time spent on screens, and patterns in usage. This information is retained by both the bank and third-party services.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Catapush - push notification delivery
- Firebase Cloud Messaging - push notification delivery
- Huawei HMS Push Kit - push notification delivery
- Adobe Marketing Cloud - marketing analytics and behavioral profiling
- Dynatrace APM - application performance monitoring
- LivePerson - in-app customer support
- ThreatMark - fraud and behavioral analysis
- Scanbot SDK - document scanning
- Google Pay - payment processing
- Samsung Pay - payment processing
- Reply Payment SDK - payment processing
Understanding the Scores
| Category | Score |
|---|---|
| Overall Security | 45/100 |
| Overall Privacy | 30/100 |
| Data Security | 50/100 |
| Network Security | 75/100 |
| Code Safety | 55/100 |
| Data Collection | 35/100 |
| Data Sharing | 40/100 |
| User Control | 25/100 |
Positive Security Features
- None identified for this version.
Areas for Improvement
- The app shares user activity data with advertising and marketing platforms, leaving users with little ability to limit what is collected or passed on.
- Multiple third-party services monitor user sessions with no clear opt-out provided within the app.
- The level of control users have over their data is significantly lower than what is typical among comparable apps.
About This Analysis
This scorecard is based on static analysis of the app binary. Scores reflect findings at the time of the scan and may change with app updates.
App Details
| Field | Value |
|---|---|
| App Name | Mobile Banking UniCredit |
| Package ID | com.unicredit |
| Version | 3.68.1 (Build 36801001) |
| Scan Date | 2026-02-08 |
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 38/100 |