mBank CZ Security & Privacy Scorecard

Android

85
Overall trust score
Trustworthy
81
Security
95
Privacy

Behavioral and CRM data flows through Synerise SDK to mBank-controlled servers, keeping it within the bank's own infrastructure. Firebase Analytics collection is explicitly disabled. Install and referral data is shared with Google via AdServices and Play Install Referrer. Stored account data remains on-device with strong protections in place.

Best for

mBank customers seeking secure everyday banking

Findings

  • 0 critical
  • 1 high
  • 2 medium
  • 4 low
  • 3 info

1 issue identified across security and privacy analysis.

Top security issues

  • EMaklerProvider insert() Has No Caller Validation — Banking SSO Token Overwrite
  • eMaklerProvider Permissions Declared as 'dangerous' Instead of 'signature'
  • WebView Popup Allowlist Permits Any HTTPS URL — Open Redirect / Phishing Vector

Top privacy issues

  • Synerise CRM SDK Full PII Profile Capability Without Verified Pre-Consent Gate
  • Advertising ID Used as Banking Authentication Device Fingerprint Parameter
  • AdServices Attribution Permissions Declared with Unrestricted SDK Access

Full analysis

mBank CZ

What This Means for You

Your account and transactions are well-protected by strong authentication and encryption, though the app may send profile information to Synerise, a customer relationship platform used by mBank, before your consent preferences are fully applied.

Recommendation: Trustworthy

mBank CZ is trustworthy for Czech banking, with verified server connections, biometric authentication, and strong encryption protecting your transactions. It's ideal for users seeking full-featured mobile banking with solid security.

Best For: Czech banking customers who want full-featured mobile banking with strong security protections and biometric authentication

Key Findings

Data Security - 0 findings

Network Security - 2 findings (1 medium, 1 low)

Code Safety - 4 findings (1 high, 1 medium, 2 info)

Privacy - 4 findings (3 low, 1 info)

Privacy Concerns

What Data is Collected

  • Personal information: name, email address, phone number, and address may be sent to Synerise CRM for customer relationship and personalization purposes
  • Device information: device identifier and phone status are accessed on your device and used for secure device binding during authentication setup
  • Location data: precise and approximate location is accessed on your device for banking features and may be sent to Google Maps for location-related functionality
  • Financial information: account and transaction data is transmitted to mBank's servers to operate the banking service

Third-Party Data Sharing

The following third parties may receive your data:

  • Synerise - customer profile data for CRM and personalization
  • Firebase (Google) - push notification delivery, remote configuration, and performance metrics
  • FaceTec - biometric face data for identity verification during account setup
  • eDocument SDK (PWPW) - document data for identity authentication
  • Google AdServices - attribution data (permissions are declared in the app, though active use cannot be confirmed from this analysis)

Understanding the Scores

Security: 81/100
Privacy: 95/100

Security Breakdown

  • Data Security: 100/100 - Your financial data and login keys are secured with hardware-backed encryption throughout the app.
  • Network Security: 93/100 - All banking communications travel over strongly protected connections with server identity verification.
  • Code Safety: 93/100 - The app is built with robust tamper detection, secure key management, and protection against modified devices.

Privacy Breakdown

  • Data Collection: 96/100 - Data collection is focused on what is needed for banking operations, with analytics tracking explicitly turned off.
  • Data Sharing: 99/100 - Third-party data sharing is minimal and primarily limited to mBank's own controlled services.
  • User Control: 99/100 - You can request data deletion and disconnect the app remotely if your device is lost or stolen.

Positive Security Features

  • All banking communications are protected with server identity verification on top of standard encryption
  • Biometric authentication (fingerprint and face recognition) is required for every login and transaction
  • Built-in tamper and debugger detection guards your account when the app runs on modified devices
  • Google Firebase analytics collection is explicitly disabled in this build
  • Hardware-backed secure storage protects your authentication keys
  • The CRM integration communicates exclusively with mBank's own controlled server instance

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. CRM Consent Gating
    The Synerise customer relationship SDK may begin transmitting profile data before consent preferences are fully applied. Ensuring all CRM data flows are explicitly gated on user consent would strengthen GDPR compliance.

  2. Advertising Permission Cleanup
    Permissions for advertising attribution services are declared in the app but appear to serve no active purpose. Removing unused permissions aligns with the data minimization principle under GDPR and Czech data protection law.

Security Enhancements

  1. Brokerage Integration Access Control
    The brokerage feature's session integration allows any app on the device that holds the right permission to overwrite your brokerage login session. Restricting this access to apps signed by mBank would close the gap.

  2. Web Redirect Scope Restriction
    The embedded browser component allows any trusted mBank page to open any external website. Narrowing this to known mBank domains would reduce the risk of being redirected to a deceptive site from within the banking app.

Technical Context

App Type: Banking and financial services (high-sensitivity personal and financial data)
Classes Analyzed: 12,000
Third-Party Services: 19
Context Tags: financial, sensitive_data, biometric, location, camera


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

App Details

Developer: mBank S.A.
Version: 3.119.0 (Build 94400)
Analysis Date: 2026-06-13
Package: cz.mbank

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 3.119.0 analyzed on 2026-06-13
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#1 (current) 85/100