Mobile Banking UniCredit Security & Privacy Scorecard

Android

38
Overall trust score
Unsafe
45
Security
30
Privacy

In-app activity is shared with Adobe Marketing Cloud alongside standard analytics services, meaning banking behavior informs marketing profiles. Users have very limited options to restrict or opt out of this data collection. Multiple third-party services monitor sessions, and the ability to manage what gets shared is among the lowest seen in banking apps.

Best for

UniCredit customers who need everyday mobile banking

Avoid if

You want control over how your data is used for marketing

Findings

  • 1 critical
  • 2 high
  • 6 medium
  • 0 low
  • 0 info

0 issues identified across security and privacy analysis.

Top security issues

  • Catapush API Key Hardcoded in AndroidManifest.xml
  • LivePerson Bearer Tokens Stored Unencrypted
  • 7 JavaScript Interfaces Exposed in WebView

Top privacy issues

  • Invasive Behavioral Tracking Without Explicit Consent
  • Adobe Analytics Auto Opt-In GDPR Violation
  • Cross-Device Tracking via Adobe Marketing Cloud ID

Full analysis

Mobile Banking UniCredit

com.unicredit | Version 3.68.1 | Scanned 2026-02-08

What This Means for You

In-app activity is shared with Adobe Marketing Cloud alongside standard analytics services, meaning banking behavior informs marketing profiles. Users have very limited options to restrict or opt out of this data collection. Multiple third-party services monitor sessions, and the ability to manage what gets shared is among the lowest seen in banking apps.

Recommendation: Use With Caution

Best For: UniCredit customers who need everyday mobile banking
Avoid If: Control over how data is used for marketing is important

Key Findings

Data Security - 6 findings (1 critical, 1 high, 4 medium)

Network Security - 2 findings (2 medium)

Code Safety - 0 findings

Privacy - 5 findings (2 critical, 2 high, 1 medium)

Privacy Concerns

What Data is Collected

This app collects behavioral and session data during banking activity. Analytics and monitoring services record how users navigate the app, time spent on screens, and patterns in usage. This information is retained by both the bank and third-party services.

Third-Party Data Sharing

Data is shared with the following third-party services:

  • Catapush - push notification delivery
  • Firebase Cloud Messaging - push notification delivery
  • Huawei HMS Push Kit - push notification delivery
  • Adobe Marketing Cloud - marketing analytics and behavioral profiling
  • Dynatrace APM - application performance monitoring
  • LivePerson - in-app customer support
  • ThreatMark - fraud and behavioral analysis
  • Scanbot SDK - document scanning
  • Google Pay - payment processing
  • Samsung Pay - payment processing
  • Reply Payment SDK - payment processing

Understanding the Scores

Category Score
Overall Security 45/100
Overall Privacy 30/100
Data Security 50/100
Network Security 75/100
Code Safety 55/100
Data Collection 35/100
Data Sharing 40/100
User Control 25/100

Positive Security Features

  • None identified for this version.

Areas for Improvement

  • The app shares user activity data with advertising and marketing platforms, leaving users with little ability to limit what is collected or passed on.
  • Multiple third-party services monitor user sessions with no clear opt-out provided within the app.
  • The level of control users have over their data is significantly lower than what is typical among comparable apps.

About This Analysis

This scorecard is based on static analysis of the app binary. Scores reflect findings at the time of the scan and may change with app updates.

App Details

Field Value
App Name Mobile Banking UniCredit
Package ID com.unicredit
Version 3.68.1 (Build 36801001)
Scan Date 2026-02-08

Versions & scan history

ScanDateOverall score
#1 (current) 38/100