mBank CZ Security & Privacy Scorecard
Android
Behavioral and CRM data flows through Synerise SDK to mBank-controlled servers, keeping it within the bank's own infrastructure. Firebase Analytics collection is explicitly disabled. Install and referral data is shared with Google via AdServices and Play Install Referrer. Stored account data remains on-device with strong protections in place.
Best for
mBank customers seeking secure everyday banking
Findings
- 0 critical
- 1 high
- 2 medium
- 4 low
- 3 info
1 issue identified across security and privacy analysis.
Top security issues
- EMaklerProvider insert() Has No Caller Validation — Banking SSO Token Overwrite
- eMaklerProvider Permissions Declared as 'dangerous' Instead of 'signature'
- WebView Popup Allowlist Permits Any HTTPS URL — Open Redirect / Phishing Vector
Top privacy issues
- Synerise CRM SDK Full PII Profile Capability Without Verified Pre-Consent Gate
- Advertising ID Used as Banking Authentication Device Fingerprint Parameter
- AdServices Attribution Permissions Declared with Unrestricted SDK Access
Full analysis
mBank CZ
What This Means for You
Your account and transactions are well-protected by strong authentication and encryption, though the app may send profile information to Synerise, a customer relationship platform used by mBank, before your consent preferences are fully applied.
Recommendation: Trustworthy
mBank CZ is trustworthy for Czech banking, with verified server connections, biometric authentication, and strong encryption protecting your transactions. It's ideal for users seeking full-featured mobile banking with solid security.
Best For: Czech banking customers who want full-featured mobile banking with strong security protections and biometric authentication
Key Findings
Data Security - 0 findings
Network Security - 2 findings (1 medium, 1 low)
Code Safety - 4 findings (1 high, 1 medium, 2 info)
Privacy - 4 findings (3 low, 1 info)
Privacy Concerns
What Data is Collected
- Personal information: name, email address, phone number, and address may be sent to Synerise CRM for customer relationship and personalization purposes
- Device information: device identifier and phone status are accessed on your device and used for secure device binding during authentication setup
- Location data: precise and approximate location is accessed on your device for banking features and may be sent to Google Maps for location-related functionality
- Financial information: account and transaction data is transmitted to mBank's servers to operate the banking service
Third-Party Data Sharing
The following third parties may receive your data:
- Synerise - customer profile data for CRM and personalization
- Firebase (Google) - push notification delivery, remote configuration, and performance metrics
- FaceTec - biometric face data for identity verification during account setup
- eDocument SDK (PWPW) - document data for identity authentication
- Google AdServices - attribution data (permissions are declared in the app, though active use cannot be confirmed from this analysis)
Understanding the Scores
Security: 81/100
Privacy: 95/100
Security Breakdown
- Data Security: 100/100 - Your financial data and login keys are secured with hardware-backed encryption throughout the app.
- Network Security: 93/100 - All banking communications travel over strongly protected connections with server identity verification.
- Code Safety: 93/100 - The app is built with robust tamper detection, secure key management, and protection against modified devices.
Privacy Breakdown
- Data Collection: 96/100 - Data collection is focused on what is needed for banking operations, with analytics tracking explicitly turned off.
- Data Sharing: 99/100 - Third-party data sharing is minimal and primarily limited to mBank's own controlled services.
- User Control: 99/100 - You can request data deletion and disconnect the app remotely if your device is lost or stolen.
Positive Security Features
- All banking communications are protected with server identity verification on top of standard encryption
- Biometric authentication (fingerprint and face recognition) is required for every login and transaction
- Built-in tamper and debugger detection guards your account when the app runs on modified devices
- Google Firebase analytics collection is explicitly disabled in this build
- Hardware-backed secure storage protects your authentication keys
- The CRM integration communicates exclusively with mBank's own controlled server instance
Areas for Improvement
GDPR / CCPA Compliance
The app's privacy practices could be strengthened by:
CRM Consent Gating
The Synerise customer relationship SDK may begin transmitting profile data before consent preferences are fully applied. Ensuring all CRM data flows are explicitly gated on user consent would strengthen GDPR compliance.Advertising Permission Cleanup
Permissions for advertising attribution services are declared in the app but appear to serve no active purpose. Removing unused permissions aligns with the data minimization principle under GDPR and Czech data protection law.
Security Enhancements
Brokerage Integration Access Control
The brokerage feature's session integration allows any app on the device that holds the right permission to overwrite your brokerage login session. Restricting this access to apps signed by mBank would close the gap.Web Redirect Scope Restriction
The embedded browser component allows any trusted mBank page to open any external website. Narrowing this to known mBank domains would reduce the risk of being redirected to a deceptive site from within the banking app.
Technical Context
App Type: Banking and financial services (high-sensitivity personal and financial data)
Classes Analyzed: 12,000
Third-Party Services: 19
Context Tags: financial, sensitive_data, biometric, location, camera
About This Analysis
This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.
App Details
Developer: mBank S.A.
Version: 3.119.0 (Build 94400)
Analysis Date: 2026-06-13
Package: cz.mbank
Analysis Limitations
- Static analysis only (code review without running the app)
- Based on APK version 3.119.0 analyzed on 2026-06-13
- May not reflect server-side security controls
- Cannot detect all runtime behaviors
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 85/100 |